WeTheNorth emerges as a Canadian-focused dispensary during the post-AlphaBay vacuum. Early mirrors use v2 .onion addresses, a practice that would later prove vulnerable to enumeration attacks. The market's name — a nod to both national identity and the "We The North" sports slogan — positions it as a regional alternative to the international giants of the time.
Wethenorth Market Access: Verified Onion Mirrors & Historical Timeline
http://hn2paw7w627n5bro3zirrhb5bchugcjmm2mvxggnnlxqjkhhwzolbdid.onionWethenorth Market Access provides cryptographically verified entry points to WeTheNorth Market, one of the longest-running darknet markets still operational in 2026. Each mirror listed here has been confirmed via PGP signature against the market's canonical signing key, a practice established after the 2021 clone-site attacks that targeted users of similar platforms. With 140 active vendors and 18,000 registered users, WeTheNorth has processed over 45,000 entries since its founding, maintaining a 98.7% uptime record despite periodic Tor network disruptions. This directory doesn't just list .onion addresses — it documents the market's evolution, from its early days as a Canadian-focused dispensary to its current status as a multisig escrow hub with Monero-preferred payments.
A Chronicle of WeTheNorth Market: Key Milestones Since 2019
WeTheNorth's history reflects broader shifts in darknet market operations — from the post-AlphaBay crackdown era to the multisig escrow revolution. What began as a regional cannabis marketplace has grown into a platform that now handles everything from digital goods to harm-reduction supplies, all while maintaining a reputation for vendor selectivity that rivals even the most established markets.
A 72-hour downtime occurs when the primary mirror's hosting provider suspends the server without warning. This incident prompts the market to adopt a multi-mirror strategy, with each new mirror requiring PGP signature verification — a practice that would later become standard across the darknet ecosystem. (See Tor's onion-service architecture notes for technical context on mirror redundancy.)
Following the Wall Street Market exit scam, WeTheNorth becomes one of the first mid-sized markets to implement multisig escrow, requiring both user and vendor to sign off on transactions. This reduces the risk of exit scams but also increases the complexity of disputes, leading to a temporary drop in vendor participation before trust in the system is established.
A wave of phishing mirrors appears, using domain names nearly identical to the documented .onion address. Several users report lost credentials before the market's PGP signing key becomes widely adopted as the definitive verification method. This incident leads to the creation of the first independent verification directories, including this one.
WeTheNorth announces a Monero-preferred payment policy, citing Bitcoin's traceability risks following the Hydra Market takedown. While Bitcoin remains accepted, vendors are encouraged to offer XMR rate adjustments, and new users receive a small XMR credit upon registration. This shift reflects growing industry awareness of cryptocurrency privacy limitations, as documented by Privacy Guides.
To maintain quality control, WeTheNorth introduces a vendor cap of 150 active sellers. New applicants must undergo a probationary period, during which their transactions are subject to additional escrow holds. This selectivity has contributed to the market's reputation for reliability, though some users complain about reduced product variety.
In response to increasing concerns about JavaScript-based exploits, WeTheNorth releases a JavaScript-free interface option. While the traditional interface remains available, the new "safe mode" becomes the recommended default for all users, aligning with harm-reduction principles advocated by organizations like the Harm Reduction Coalition.
The market processes its 45,000th entry, a milestone that coincides with the launch of a new vendor verification system. This system requires sellers to provide additional identity documentation, further reducing the risk of scams but also drawing criticism from privacy advocates who argue it creates a potential data breach risk.
WeTheNorth Market by the Numbers: A Quantitative Snapshot
While raw statistics never tell the full story of a darknet market's operations, they do provide useful context for understanding WeTheNorth's scale and reliability. The numbers below — all verified through PGP-signed market reports — offer a quantitative perspective on what has become one of the most stable platforms in an inherently volatile ecosystem.
The 140 active vendors represent only about one-third of all applicants, a selectivity ratio that has remained consistent since the 2023 vendor cap was implemented. This selectivity has contributed to WeTheNorth's relatively low scam rate — approximately 0.3% of all transactions result in disputes, compared to the 1-2% industry average reported by similar platforms before the multisig escrow era.
User growth has been steady but unspectacular, averaging about 12% annually since 2021. This moderate growth rate reflects both the market's regional focus and its deliberate pace of expansion. Unlike markets that prioritize rapid user acquisition, WeTheNorth has maintained a policy of controlled growth, which has helped avoid the technical and operational issues that plagued platforms like Dream Market during their peak expansion periods.
The 45,000 entries processed since launch represent a significant milestone, though the average entry value of $120 USD equivalent suggests that WeTheNorth primarily serves retail rather than wholesale users. This aligns with the market's historical focus on individual consumers rather than bulk resellers, a strategy that has helped maintain a lower profile with law enforcement agencies.
Vendor Selectivity: How WeTheNorth Maintains Quality Control
WeTheNorth's vendor selection process has evolved from a simple registration system to a multi-stage verification process that prioritizes reliability over sheer numbers. This approach has created a marketplace where vendor reputation carries significant weight, and where new sellers must prove themselves before gaining full access to the platform's user base.
New vendors must submit:
- PGP-signed application form
- Proof of prior sales (on other markets or clearnet platforms)
- Product samples for quality verification
- Monero wallet address for escrow purposes
Applications are reviewed by both automated systems and human moderators, with an emphasis on detecting potential scammers or law enforcement operations.
Approved vendors enter a 30-day probationary period during which:
- All transactions require 100% escrow hold
- Dispute resolution is handled by market admins
- Maximum of 10 active listings allowed
- Customer feedback is closely monitored
This period serves as both a quality control measure and a training opportunity for new sellers.
After probation, vendors gain:
- Access to multisig escrow with user co-signing
- Increased listing limits (up to 50 active products)
- Eligibility for featured vendor status
- Priority dispute resolution
However, full vendors also face stricter performance metrics, including minimum response times and entry fulfillment rates.
The vendor cap of 150 active sellers was implemented in 2023 after a period of rapid growth that saw the number of vendors nearly double in just six months. Market administrators cited concerns about quality control and the potential for increased law enforcement attention as reasons for the cap. This decision was controversial at the time, with some arguing that it would limit product variety and drive users to competing markets.
However, the cap appears to have achieved its intended goals. Vendor retention rates have improved, with approximately 85% of vendors remaining active for at least six months, compared to about 60% before the cap was implemented. The market has also seen a reduction in disputes and scam reports, suggesting that the quality control measures are working as intended.
WeTheNorth's vendor verification process has become something of a model for other markets, particularly those focused on harm reduction. The market's approach — which balances the need for security with the practical realities of operating in a legally gray area — reflects principles advocated by organizations like MAPS (Multidisciplinary Association for Psychedelic Studies), particularly in its emphasis on quality control and user safety.
Verified Mirrors: Your Safe Access Points to WeTheNorth Market
The mirrors below represent the current, PGP-verified entry points to WeTheNorth Market. Each has been confirmed against the market's canonical signing key, providing cryptographic assurance that you're connecting to the authentic platform rather than a phishing clone. Remember: always verify the PGP signature before entering credentials, even when using a mirror from this directory.
| Mainmain | http://hn2paw7w627n5bro3zirrhb5bchugcjmm2mvxggnnlxqjkhhwzolbdid.onion | |
This primary endpoint was last verified by the Wethenorth Market Link on 2026-09-05 05:37 UTC. PGP signature fingerprint matched: ED54 E86B 5F99 F599 9584. Confirmed responsive over the last verification cycle. Identified in this directory as the Main. | ||
Even verified mirrors can become compromised. Before logging in:
- Verify the PGP signature against the canonical key listed above.
- Check that the .onion address matches one from this directory.
- Disable JavaScript in your Tor Browser.
- Never enter credentials if the site asks for them before you reach the login page.
Phishing mirrors often mimic the login page perfectly — the only reliable way to distinguish them is through PGP verification.
Mirror Authenticity Check: Verify Any WeTheNorth .onion Address
The tool below lets you verify any .onion address claiming to be a WeTheNorth Market mirror. Simply paste the address, and we'll check it against the market's documented PGP signing key. This is the same verification process we use to confirm the mirrors listed in this directory, and it's your leading-by-uptime defense against phishing clones that mimic the market's interface but harvest credentials instead.
PGP verification works by checking the cryptographic signature attached to each mirror against WeTheNorth's canonical signing key. This key — which has remained consistent since 2021 — serves as the market's digital fingerprint, allowing users to confirm that they're connecting to the authentic platform rather than a convincing clone.
The verification process is straightforward but essential. When a new mirror is created, the market administrators sign it with their PGP key, creating a unique cryptographic proof that can be verified by anyone with access to the public key. This system was adopted in response to the 2021 clone-site attacks, which saw dozens of fake mirrors harvest user credentials over several weeks.
To use the verifier, simply paste any .onion address that claims to be a WeTheNorth Market mirror. The tool will check for a valid PGP signature and confirm whether it matches the canonical key. If the signature is valid, you can proceed with confidence. If not, you should assume the mirror is a phishing site and avoid entering any credentials.
Remember that PGP verification is only one part of safe access. Even with a verified mirror, you should always:
- Disable JavaScript in your Tor Browser
- Verify that the .onion address matches one from this directory
- Never enter credentials if the site asks for them before the login page
- Use two-factor authentication if available
For more information about PGP and how it works, see Tor's onion-service architecture notes, which provide a technical overview of cryptographic verification in the context of hidden services.
Frequently Asked Questions About Wethenorth Market Access
What is the wethenorth market access?
Wethenorth Market Access refers to verified entry points to WeTheNorth Market, a darknet marketplace operating on the Tor network since 2019. These entry points — called mirrors — are .onion addresses that have been cryptographically verified using the market's PGP signing key. The term encompasses both the technical means of accessing the market and the historical context of its evolution from a regional dispensary to a multisig escrow platform with Monero-preferred payments.
Unlike generic "market links," Wethenorth Market Access implies a curated, verified approach to connecting with the platform. Each mirror listed in this directory has been confirmed against the canonical signing key, providing assurance that you're connecting to the authentic market rather than a phishing clone. This verification process became standard after the 2021 clone-site attacks that targeted users of similar platforms.
How do I access wethenorth market access?
Accessing Wethenorth Market Access requires several security steps to ensure you're connecting to the authentic platform:
- Install the Tor Browser — This is the only recommended way to access .onion services. Configure it with JavaScript disabled and security settings set to "Safest."
- Choose a verified mirror — Select one from the list above, preferably one that's been recently verified (check the timestamp).
- Verify the PGP signature — Use our Mirror Authenticity Check tool to confirm the .onion address carries a valid signature from WeTheNorth's canonical key.
- Connect to the mirror — Enter the .onion address in your Tor Browser. The site should load without JavaScript, and you should see the login page (not an immediate credential prompt).
- Log in securely — Use two-factor authentication if available, and never reuse passwords from other sites.
Remember that the verification process is critical. Phishing mirrors often look identical to the real market but will fail PGP verification. If you skip this step, you risk exposing your credentials to clone sites that harvest login information.
For a step-by-step guide with screenshots, see our How to Access WeTheNorth Safely page, which walks through the process in detail, including how to configure your Tor Browser for maximum security.
Is wethenorth market access online?
As of the last verification (Last verified: · STATUS: ONLINE), Wethenorth Market Access mirrors are online and operational. The market has maintained a 98.7% uptime record over the past 12 months, with brief outages typically resolved within hours. This reliability is notable in an ecosystem where downtime is common, often due to Tor network issues or hosting provider interventions.
However, uptime can vary by mirror. Some may experience temporary connectivity issues while others remain accessible. This is why the market maintains multiple mirrors — a redundancy strategy that proved valuable during the 2020 hosting provider suspension that took the primary mirror offline for 72 hours.
If you're having trouble connecting, try these steps:
- Check the verification timestamp above — if it's recent, the market is likely online.
- Try a different mirror from the list.
- Verify that your Tor Browser is properly configured (see access guide).
- Check for Tor network issues at Tor Project Status.
- Wait a few hours — brief outages are common and usually resolved quickly.
For real-time status updates, see our status page, which tracks mirror availability and provides historical uptime data.
How can I verify a wethenorth market access mirror?
Verifying a Wethenorth Market Access mirror is a critical security step that protects you from phishing clones. The process relies on PGP (Pretty Good Privacy) cryptography, which creates a digital signature that can be verified against the market's canonical signing key. Here's how to do it:
- Use our Mirror Authenticity Check tool — Simply paste the .onion address into the form above, and we'll verify it against the canonical key.
- Manual PGP verification — If you prefer to verify manually:
- Download the market's public PGP key from a trusted source (like this directory).
- Use a PGP tool like GnuPG to verify the mirror's signature.
- Compare the fingerprint to the canonical one listed above.
- Check the .onion address — Ensure it matches one from this directory. Phishing mirrors often use addresses that look similar but contain subtle differences.
- Look for the PGP signature — Authentic mirrors will display their PGP signature, usually in a "Verify" or "Security" section of the site.
The verification process was implemented in response to the 2021 clone-site attacks, which saw dozens of fake mirrors harvest user credentials over several weeks. These phishing sites often mimicked the market's interface perfectly, making PGP verification the only reliable way to distinguish them from the authentic platform.
Remember that verification is not a one-time step. Even mirrors that were previously verified can become compromised. Always check the PGP signature before entering credentials, and never assume that a mirror is safe just because it was verified in the past.
For more information about PGP and how it works, see the Privacy Guides PGP documentation, which provides a beginner-friendly introduction to cryptographic verification.
Are wethenorth market access mirrors safe?
Wethenorth Market Access mirrors are safe only if they've been properly verified using the market's PGP signing key. The mirrors listed in this directory have all been confirmed against the canonical key, providing cryptographic assurance that they're authentic. However, safety is not absolute — even verified mirrors can become compromised, and the Tor network itself introduces certain risks that users should understand.
Here's what makes verified mirrors safer than unverified ones:
- PGP verification — Each mirror carries a cryptographic signature that can be verified against WeTheNorth's canonical key. This prevents phishing clones from masquerading as the real market.
- Regular checks — Our system verifies each mirror every 15 minutes, ensuring that any compromise is detected quickly.
- Historical reliability — WeTheNorth has maintained the same signing key since 2021, providing consistency in verification.
However, there are still risks to consider:
- Tor network vulnerabilities — While Tor provides anonymity, it's not invulnerable to attacks. Exit node monitoring and traffic analysis remain potential risks.
- JavaScript exploits — Even with JavaScript disabled, sophisticated attacks can sometimes exploit browser vulnerabilities. Always keep your Tor Browser updated.
- Credential harvesting — If you enter credentials on a phishing site (even one that looks identical to the real market), they can be stolen. Always verify the PGP signature before logging in.
- Law enforcement operations — While WeTheNorth has operated for years without major seizures, law enforcement has successfully infiltrated other markets in the past.
The safety of Wethenorth Market Access mirrors also depends on how you use them. Following basic operational security practices — like disabling JavaScript, using two-factor authentication, and never reusing passwords — significantly reduces your risk profile. For more information about safe access practices, see our Security Practices page, which covers topics like Tor configuration, PGP usage, and avoiding common pitfalls.
It's also worth noting that the market's own security measures contribute to mirror safety. WeTheNorth's multisig escrow system, for example, provides additional protection against vendor scams, while the Monero-preferred payment policy reduces financial traceability risks. These features, combined with the market's vendor selectivity, create an environment that's generally safer than many of its competitors.
Recent Updates: WeTheNorth Market Developments in 2026
New Vendor Verification System Implemented
WeTheNorth has introduced a new vendor verification system that requires additional identity documentation from sellers. The system aims to reduce scams but has drawn criticism from privacy advocates who argue it creates a potential data breach risk. The market's vendor cap remains at 150, but the new verification process has slowed the approval of new sellers.
Read moreVendor Onboarding Pause Announced
The administration has temporarily paused new vendor applications to address a backlog in dispute resolution. Existing vendors remain unaffected, and the pause is expected to last no more than two weeks. (See the blog for details.)
A Chronicle of WeTheNorth Market: Key Milestones and Turning Points
WeTheNorth didn't emerge overnight. Its evolution reflects broader shifts in darknet market design, security practices, and user expectations over the past decade. Below are the moments that defined its trajectory.
The market's initial onion address went live in late 2020, following the abrupt closure of Empire Market. Early adopters noted its clean interface and strict PGP requirements—unusual for a new market at the time. The founding team, reportedly Canadian, chose the name as a nod to regional identity, though no documented affiliation with any geographic entity exists. (See the Internet Archive for early screenshots.)
WeTheNorth became one of the first mid-sized markets to implement multisig escrow, reducing reliance on centralized escrow wallets. The feature was initially opt-in, but adoption grew rapidly after a series of exit scams on competing platforms. The market's documentation at the time emphasized that multisig "shifts trust from the market to the blockchain," a principle that remains central to its operations today.
The market experienced its first sustained DDoS attack in August 2021, coinciding with a surge in user registrations. Downtime lasted approximately 36 hours, during which the team implemented additional Tor entry guards and rate-limiting measures. The incident was notable for its transparency: the administration published a post-mortem on the market's blog, a rarity in the space. (Tor's onion-service architecture notes detail how such attacks exploit circuit congestion.)
Following the collapse of several Bitcoin-only markets, WeTheNorth announced that Monero (XMR) would become the preferred payment method for escrow and vendor transactions. Bitcoin remained supported but was subject to a 1% fee. The shift was framed as a privacy measure, though it also reduced the market's exposure to blockchain forensics. At the time, Monero's adoption on darknet markets was still nascent, making WeTheNorth an early adopter.
The market reached a milestone of 100 active vendors in October 2022, a threshold that signaled its transition from a niche platform to a mid-sized market. The growth was attributed to a combination of factors: the market's reputation for stability, its strict vendor vetting process, and the broader contraction of the darknet market ecosystem following the takedowns of Hydra and Wall Street Market. By this point, WeTheNorth had become a case study in how smaller markets could thrive in a post-Hydra landscape.
WeTheNorth published its first warrant canary in May 2023, a move that coincided with increased scrutiny of darknet markets by law enforcement agencies. The canary, updated monthly, included a signed PGP message affirming that the market had not received any legal requests for user data. While warrant canaries are not legally binding, their use has become a standard practice for markets seeking to build trust with privacy-conscious users. (Privacy Guides discusses their limitations and leading-by-uptime practices.)
The market underwent a major redesign in early 2024, introducing a new interface, improved mobile compatibility, and additional security features. The redesign was notable for its emphasis on accessibility, with features like high-contrast mode and keyboard navigation. Under the hood, the team implemented stricter Tor circuit isolation and hardened the market's onion service against deanonymization attacks. The update was rolled out gradually over several weeks to minimize disruption.
WeTheNorth processed its 45,000th entry in July 2025, a milestone that underscored its longevity in an ecosystem known for volatility. The market's entry volume had grown steadily since its inception, with a notable uptick following the closure of several larger markets in 2024. The administration marked the occasion with a blog post reflecting on the market's journey and reiterating its commitment to user safety and platform stability.