Official WeTheNorth Mirrors · PGP · Updated Aug 2026
WeTheNorth Official Mirrors 2026: Verified Onion Link & Login
This is the signed WeTheNorth mirror register. It carries one verified WTN onion address, the PGP fingerprint that signs it, and a live read on the link. People spell the name three ways. WeTheNorth as one word, We The North as three, and the short WTN. All of them point at the same Canadian darknet marketplace. Trust the signed address. A clone that only looks right will still take your coin.
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionThe current reference address for WeTheNorth. The marker is a live probe, not a fixed promise. Copy it, verify the key, then open it in Tor Browser.
pending (Phase 0)A domain proves nothing; the key does. WeTheNorth's operators publish their signing key in Phase 0. Until that happens, match the address one character at a time and consult the canary.What WeTheNorth is, and what this page is not
WeTheNorth is a Canadian darknet marketplace that runs as a Tor hidden service. It has no clearnet storefront and no phone app. What this page holds is the onion address, an honest read on whether it answers, and the PGP fingerprint you check it against. Orders on WeTheNorth settle in Bitcoin and Monero and stay in escrow until a deal closes.
One thing to clear up early. The words We The North also belong to a Toronto sports slogan. That is not this. Here the name means WeTheNorth, nothing else. The Canada page keeps the two apart in plain terms.
Honest limit. We publish the register, we do not run WeTheNorth. There is no way for us to guarantee that a mirror is answering at the exact moment this register loads in front of you, and your account and escrow remain entirely outside our view.
What running as a Tor hidden service actually changes
A Tor hidden service has no public IP address for anyone to trace back to a hosting provider, no domain a registrar can be pressured into redirecting, and no DNS record for a court order to reach. WeTheNorth's operators chose that architecture deliberately, the same way most durable Canadian darknet marketplaces have, because the alternative — a clearnet storefront with a normal domain — hands a takedown request three separate points of leverage that a .onion address simply does not have.
Why this register exists as a separate page from the market itself
WeTheNorth's own onion service does not maintain a public, easily searchable clearnet page pointing back to itself, for the same reason it has no clearnet storefront at all. That gap is exactly what phishing pages exploit — a visitor searching for "WeTheNorth link" finds a dozen results, and most of them are not the real address. This register exists to close that gap with one verifiable source, kept current and checked against the signed canon key, rather than leaving that search to chance.
What makes a WeTheNorth link safe to open
Signed register
The address shown must appear inside the operators' signed register, never merely inside a message-board reply.
Key over name
Judge by the fingerprint rather than by the wording. A duplicate can mirror every pixel of a site, yet it can never produce the operators' signature.
Honest status
Status holds at Checking for as long as a probe has not answered. A green light is never assumed on our behalf.
Escrow held
Payment for a deal is locked away in escrow and released once the order completes. The coins involved never come near this register.
How a WeTheNorth link earns your trust
Every candidate address runs the same gauntlet. It is not enough that a mirror answers. It has to be the one the signed register names. Here is the shape of the check before the step list.
Each of those three moves protects against a different failure. Copying the address from the wrong place is how most people end up with a clone in the first place — a forum post, a paid ad, or a chat message can all carry a convincing lookalike string. Routing through Tor rather than a VPN or a regular browser is what keeps the connection itself from leaking which .onion you visited. And the PGP check is the only step in the sequence that a clone genuinely cannot fake, because forging a valid signature would require the operators' actual private key, not just a copy of the page.
Skipping any one of the three does not make a WeTheNorth session automatically unsafe, but it does remove a layer that exists for a reason. A visitor who copies the right address, routes it through Tor, but skips the signature check is trusting that the address was correct by luck rather than by verification — usually fine, occasionally the exact mistake a clone was built to catch.
Verified WeTheNorth mirrors
| Role | Onion URL | Status | Action |
|---|---|---|---|
| Primary | http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion | Checking | |
| Failover | pending signature | Pending | n/a |
When a second official mirror is signed it appears here with a matching signature and a checked date. Until then, one address is the honest answer.
The WeTheNorth shop, market link and onion URL
In Canada people often say shop when they mean the market. The WeTheNorth shop, the WTN market link, the darknet shop, they name one place with one onion URL, the address near the top of this page. A link that ends in .shop on the open web is not it. Neither is an onion mirror you picked off a random board. Copy the WeTheNorth URL from the verified box, not from a result you did not check.
WeTheNorth vendor rules and listing categories
Every marketplace draws lines around what a vendor account may list and how a dispute over a listing gets handled once money has moved. WeTheNorth is no different, and understanding those rules before your first order saves a confused message to support later.
How a vendor account gets approved
A new vendor typically posts a bond and passes a review step before listings go live on WeTheNorth. That friction is deliberate: it raises the cost of standing up a WeTheNorth vendor slot purely to collect a handful of payments and vanish. It does not eliminate risk on any single order, but it filters out a share of the laziest scam accounts before they ever reach a buyer's screen.
What a listing category tells you, and what it does not
WeTheNorth organizes listings into categories the way most Tor marketplaces do, which helps narrow a search but says nothing about a specific vendor's reliability within that category. Two listings in the same category can have wildly different order histories. Read the vendor's own feedback and order count inside that category rather than assuming the category label itself vouches for quality.
Disputes and the escrow rule
Funds move into escrow when an order is placed and stay held until you confirm delivery or a moderator resolves a disagreement. A vendor who asks you to pay outside that escrow flow, or to finalize the order before it has actually arrived, is asking you to give up the one mechanism that lets a dispute be resolved at all. Treat that request as a reason to slow down, not a normal part of doing business.
Rules that apply across every WeTheNorth vendor account
Regardless of category, an account still under its bond period, with a short order history, or with recent unresolved disputes carries more risk than one with a long clean record. None of this is visible from the storefront alone — it takes a minute of reading the vendor's own page on the verified onion, which is a minute worth spending before an order that matters.
Reading WeTheNorth vendor trust signals across a category
A WeTheNorth vendor profile carries more useful information than the star rating alone. Order count over time tells you whether a profile represents months of consistent activity or a handful of recent listings padded quickly to look established. Writing style across a vendor's replies is worth a glance too — a WeTheNorth account that switches tone abruptly between messages, or answers support questions with generic copy-paste lines, is a weaker signal than one with a consistent voice across a long history. None of these signals proves anything on its own, and none replaces the bond-and-review step WeTheNorth already runs before a vendor account goes live, but stacking two or three of them together narrows the risk on a first order with a WeTheNorth vendor you have not used before.
Why WeTheNorth vendor bonds do not eliminate every risk
A bond raises the cost of abandoning a WeTheNorth account after a handful of scam orders, which is why the market requires one, but it does not make every bonded vendor reliable for every order. A vendor can hold a clean bonded account for months and still have an unusually bad week, a supply problem, or a genuine dispute that goes against them. Reading the WeTheNorth vendor rules is the floor of due diligence here, not the ceiling — the same escrow protection and dispute process that back a first WeTheNorth order back every order after it, and treating an established vendor as risk-free is a different mistake than treating a brand-new one that way, but it is still a mistake.
Verify the WeTheNorth URL before you connect
pending (Phase 0)Open the operator key and the verification steps
-----BEGIN PGP PUBLIC KEY BLOCK-----
(withheld for now; the key stays offline through Phase 0)
-----END PGP PUBLIC KEY BLOCK-----gpg --import wethenorth-canon.asc
gpg --verify mirrors.json.sig mirrors.json
# proceed only on a valid signature whose fingerprint matchesUse a cautious WeTheNorth access sequence
- Start from Tails, or turn Tor Browser down to its Safest security setting.
- Import the canon PGP key into your keyring before you go hunting for a link.
- Check the mirror list's signature, and satisfy yourself that the fingerprint agrees with the canon.
- Lift the address straight out of the verified box — a search result is not a source.
- Open it in Tor, on an identity that has nothing to do with your everyday one.
The full walkthrough, with the clearnet-to-onion handoff drawn out, lives on the access guide.
The order of that sequence is not arbitrary. Importing the canon key before picking a link means the verification tool is ready the moment you have an address to check, instead of scrambling to set it up after you have already typed a WeTheNorth string into Tor Browser. Keeping the Tor identity separate from a daily browsing identity — a distinct Tails session, or at minimum a fresh Tor Browser profile — limits what a compromised WeTheNorth session, however unlikely, could ever correlate back to unrelated browsing. None of these five steps is difficult on its own; treating them as a fixed sequence rather than optional extras is what keeps the whole routine fast enough to actually follow every time.
Sign in to WeTheNorth behind the verified onion
The WeTheNorth login and the WTN market login sit behind the same onion, never on a separate clearnet form. Most stolen accounts start at a fake login mirror. Read the notes before you type anything.
Check a WeTheNorth URL
This tidies harmless formatting, then accepts only an exact match against the embedded signed address. A string that merely looks close stays unverified.
The address you match against is the same one signed in the register above.
Use the signed directory
Download the local mirror record and check it against the visible PGP fingerprint before you compare any address.
WeTheNorth registration and first deposit
Everything past this point happens behind the verified onion, once you have matched the address against the signed record above. Here is what the first few steps actually look like, in order.
Creating an account
Registration on WeTheNorth asks for a username and password only — no email address, no phone number, and nothing that ties the account to an identity you use anywhere else. Pick a username you have never used on any other platform, clearnet or onion, since a reused handle is one of the most common ways an account gets linked back to a real person months later. Write the password down somewhere durable and offline; there is no email-based recovery flow to fall back on if you lose it, by design.
Funding the account for the first time
A first deposit generates a Monero address specific to your account, and funds sent there are credited once the network confirms the transaction — this is not instant, and sending a follow-up message asking why a deposit has not appeared within a minute or two is a common new-user mistake rather than a sign something is wrong. Never reuse a deposit address across sessions if WeTheNorth rotates them, and always copy the address fresh from the account page itself rather than from a note or a screenshot that could be stale.
What to check before placing a first order
Before spending a first deposit, take the time to read a vendor's profile the way the vendor-trust guidance elsewhere on this site describes: PGP history over raw review count, consistent writing style over a suspiciously round number of five-star ratings. A first order is also a reasonable time to test the dispute process conceptually — understand how to open one and what evidence matters — before you actually need it under pressure.
Common first-order mistakes worth avoiding
The most common first-order mistake is rushing past the address verification described earlier on this page because a search result or a forum post looked convenient in the moment — the entire point of registering and depositing is wasted if the account sits on a clone rather than the genuine WeTheNorth onion. The second most common mistake is over-funding a first deposit well beyond a single planned order; send only what one order needs until you have been through a full cycle — deposit, order, delivery, release — at least once. The third is skipping PGP setup and then needing it urgently the first time a dispute or a suspicious message arrives, with no working key ready to verify anything against.
Where WeTheNorth registration habits come from
None of the practices above are unique to WeTheNorth. A WeTheNorth-only username, an offline password record, and a fresh Tor identity are the same baseline habits security-focused communities recommend for any Tor hidden service handling money, described in general terms by projects like Privacy Guides and the Electronic Frontier Foundation. Applying that general guidance specifically to a WeTheNorth account is what turns broad opsec advice into a habit that actually protects a specific order.
What a WeTheNorth account cannot recover for you
Because WeTheNorth asks for no email and no phone number at signup, there is no password-reset email waiting on the other end if a WeTheNorth password is lost. A password manager kept offline, or a memorized passphrase strong enough to trust, is the only recovery path that exists — writing a WeTheNorth password on a synced clearnet note defeats the purpose of keeping the account separate from a daily identity in the first place.
What this WeTheNorth register does not promise
A register that claims certainty about WeTheNorth, or any darknet marketplace, is overstating what it can actually know. This page verifies specific, checkable facts — that an address matches the signed WeTheNorth key, that a mirror answered a recent probe, that the escrow mechanism functions as vendors and buyers describe it — and stops short of anything it cannot verify from the outside.
Verification proves identity, not conduct
Matching a PGP fingerprint confirms you are looking at the genuine WeTheNorth operator rather than a clone. It says nothing about how WeTheNorth will run tomorrow, how a specific vendor will handle an order, or how long the market stays online. Treat a verified WeTheNorth address as the floor of trust — the minimum needed before you proceed — not a guarantee layered on top of it.
A mirror answering does not mean WeTheNorth is problem-free
A Checking or reachable status on this register means a WeTheNorth mirror responded to a recent probe from our vantage point. It does not speak to order backlog, vendor dispute volume, or anything happening inside the market itself. Reachability and operational health are different questions, and this register only ever answers the first one honestly.
Why WeTheNorth's escrow model still carries risk
Escrow on WeTheNorth reduces the chance a vendor disappears after payment, but it does not remove risk from the category entirely. A compromised WeTheNorth account, a slow dispute review, or an operator-side incident all sit outside what escrow protects against. Anyone treating WeTheNorth, or any marketplace, as risk-free because it uses escrow is trusting a partial picture.
Tools this WeTheNorth register does not build, but relies on
Nothing on this page substitutes for the underlying tools that make a verified WeTheNorth session possible in the first place. We do not build Tor, PGP, or Monero — we point at the signed WeTheNorth address and explain how to check it. The projects below are the actual infrastructure a cautious WeTheNorth visit depends on, and reading their own documentation is worth more than any summary here.
- The Tor Project — the network and browser that carries a WeTheNorth session; read their own security documentation before your first connection.
- Tails — an amnesiac operating system that boots from removable media and routes everything through Tor by default, the setup this register recommends for a WeTheNorth session.
- Whonix — a two-VM isolation design that keeps a WeTheNorth browsing identity separated from the host machine even if a browser exploit lands.
- GnuPG — the free implementation of PGP that runs the signature check described on the verify page, the step that catches a WeTheNorth clone.
- Electronic Frontier Foundation — digital rights and security guidance that informs a lot of the general opsec practice referenced across this WeTheNorth register.
- Privacy Guides — independently maintained tool and practice recommendations, useful well beyond a single WeTheNorth session.
- Monero — the privacy-focused cryptocurrency WeTheNorth supports alongside Bitcoin for escrow settlement.
- Bitcoin.org — background on the other currency a WeTheNorth deposit can use, including wallet basics for a first-time buyer.
- KeePassXC — an offline password manager suited to storing a WeTheNorth login without syncing it anywhere.
- OnionShare — a tool for sending files or hosting a page over a one-off onion address, built on the same Tor hidden-service model WeTheNorth itself runs on.
These are independent projects. None of them run or endorse WeTheNorth, and this register has no affiliation with any of them — they are listed because understanding the tools underneath a WeTheNorth session is part of using it safely.
What this WeTheNorth register verifies, and what stays inside the market itself
This canon answers one question precisely: which onion address is the real WeTheNorth mirror right now, signed and probed. It deliberately does not extend that verification into the darknet market's internal machinery — escrow terms, vendor reputation, and dispute handling are WeTheNorth's own systems, not something a clearnet reference page can attest to from outside the onion.
Escrow protects a trade, not a mirror choice
WeTheNorth's escrow system holds payment until an order is confirmed, which limits a single vendor's ability to take money and vanish. It does nothing for the separate risk of connecting to a phishing clone in the first place — escrow only starts protecting a buyer after a genuine WeTheNorth session begins, which is exactly why the PGP and onion checks on this page come first, not after.
Vendor reputation is read on WeTheNorth, not assumed from a mirror list
A vendor's order history, dispute record, and PGP-signed communications live inside the marketplace and should be read there before any order, the same way a mirror's signature should be checked before any login. Neither check substitutes for the other: a verified onion address says nothing about a specific vendor, and a well-reviewed vendor says nothing about whether the address you reached them through was genuine.
More WeTheNorth reference pages on this register
The verified onion above is the destination; the rest of this WeTheNorth register covers everything around it. Run the WeTheNorth opsec baseline before any session, watch the live status grid for whether a mirror is actually answering, and read the about page for how this register decides what counts as an official WeTheNorth address in the first place. Buyers arriving from a Canada-focused search follow the same signed onion as everyone else.
WeTheNorth frequently asked questions
What is the official WeTheNorth link in 2026?
It is the single onion in the verified box, used only after its PGP fingerprint matches the signed source. No other address is official.
Is there a WeTheNorth clearnet market?
No. The market runs on Tor. A clearnet page can carry the verified onion, but WeTheNorth itself never sits on the open web.
What is the WeTheNorth shop or market URL?
Shop and market mean the same place here. There is one onion URL, the address shown above. A .shop domain on the open web is not it.
Why does the status read Checking?
Availability shifts through the day. Checking is an honest probe state. Read it as unknown, not as safe or live.
Is WeTheNorth the same as the basketball slogan?
No. Here WeTheNorth means the Canadian darknet marketplace reached over Tor, not the Toronto sports phrase that shares the words.
Does WeTheNorth ship internationally or only within Canada?
WeTheNorth is best known as a Canada-focused marketplace, and many vendors ship domestically only, but that varies by listing rather than being a platform-wide rule. Check each vendor's own shipping notes on the onion before assuming a Canadian-only or international option applies.
What payment method does WeTheNorth use?
Cryptocurrency, handled through WeTheNorth's own escrow rather than a direct wallet-to-wallet transfer. Paying a vendor outside that escrow flow removes the dispute protection WeTheNorth is built around, regardless of how the vendor frames the request.
Can I browse WeTheNorth listings without creating an account?
Some pages may be viewable without logging in, but ordering requires an account created directly on the verified onion. Nothing on this mirror register can create, hold, or recover that account — it exists only to help you reach the genuine address safely.
What should I do if the WeTheNorth onion address changes?
Return to this register and re-check the PGP fingerprint rather than trusting a new address from a forum post or a search result. A rotation is normal after maintenance or a suspected compromise; the fingerprint, not the address text, is what stays your anchor of trust.
Is a WeTheNorth vendor's positive feedback proof they are trustworthy?
Feedback history is useful context, not a guarantee. It reflects past orders, not the one you are about to place, and a small number of favorable reviews can be manufactured on any marketplace. Weigh feedback alongside order volume and how long the WeTheNorth vendor account has been active, not on its own.