BlackOps working links
Home / Verify a link

Proving a link is real

A link from anywhere, this page included, is only worth using once you can prove it. The good news is that proving it is quick and does not rely on trusting us. Two checks together make a fake link almost impossible to slip past you.

Check one, the signed list

BlackOps signs its current links with the market PGP key, the same key on its Dread profile. You import that key once, then you can check any address list they sign, any time you have a doubt.

gpg --import blackops.asc
gpg --verify links.txt.asc links.txt

If GnuPG prints Good signature, the list came from whoever holds the market key and nobody changed it on the way to you. If the address you are about to open is not inside that signed list, stop there and do not type your password. The first time you import the key, check its fingerprint against a second source such as the Dread post, so you know you have the right key. After that first check, every future one is automatic.

Check two, the login screen

Every real BlackOps login shows the address it is being served from, both in the page header and inside the anti-phishing image. Read that address and match it, character by character, against the one in your browser bar, before you type your password. A copy can fake the look of the page, but it cannot show the correct address in both spots while quietly running on a different one. That is the trap a fake cannot get out of.

Where to get links in the first place

Only copy links from a place you trust. This directory over its onion, or the signed list. Not a search ad, not a random forum post, not a message from a stranger who is being very helpful. Most people who lose an account started by trusting a link from somewhere they should not have.

Watch out
No real login ever asks for your recovery words to sign in. The recovery words get an account back if you lose the password. A page that asks for them at login is a fake, full stop.

Updated 2026-07-22 · Home