onion links v3

V3 Onion Links: Understanding the Upgrade to Tor's Addressing System

If you've noticed .onion addresses getting longer and more complex, you're seeing Tor's shift to v3 onion links. In 2021, the Tor Project deprecated v2 addresses in favor of v3, a more secure addressing scheme with stronger cryptography and built-in protection against certain attacks. This change affects how you verify legitimate dark web sites and spot phishing clones.

Onion Links V3: What Changed and How to Verify

What V3 Onion Links Are

V3 onion links are 56-character .onion addresses that replaced the older 16-character v2 format. Each v3 address is derived from a 32-byte public key using the SHA3-256 hash function, making it cryptographically bound to the site's identity in a way v2 addresses were not. The longer format is not arbitrary; it encodes the site's actual encryption key, so the address itself proves ownership.

When you visit a v3 onion site through Tor Browser, the browser verifies that the site's key matches the address you typed. This verification happens silently in the background. If someone tries to serve you a different site under a v3 address you didn't request, Tor Browser will reject the connection. This is a fundamental security improvement over v2, where the address and the key were not cryptographically linked.

V2 vs V3: Why the Upgrade Mattered

V2 onion addresses were 16 characters long and used RSA-1024 encryption, which was considered adequate when Tor introduced them but became a liability as computing power grew. A determined attacker with enough resources could theoretically generate a v2 address matching a legitimate site's key, creating a perfect phishing clone. V3 addresses use elliptic curve cryptography (ed25519) and are 56 characters, making brute-force address collision attacks computationally infeasible.

The Tor Project announced the deprecation of v2 in 2020 and disabled support for v2 addresses in Tor Browser by October 2021. This means older .onion links you find in archived databases or on Reddit are likely no longer accessible. If a site you're looking for only has a v2 address listed, it has either migrated to v3 or gone offline. Checking the site's official PGP-signed announcement or the Tor Project's list of known onion services is the only safe way to confirm a current address.

How to Verify a V3 Onion Address

Verification begins with the source, not the address itself. Legitimate dark web sites publish their v3 onion links on official channels: a PGP-signed statement on their clearnet domain, a pinned post in their official forum, or a link from the Tor Project's directory of known services. Never rely on a single mention you find on Reddit, a forum post, or a third-party link aggregator.

When you have a candidate address, follow these steps:

  1. Copy the v3 address exactly as written, character by character.
  2. Open Tor Browser and paste it into the address bar.
  3. Wait for the connection to establish; Tor Browser will show a green onion icon if the site's key matches the address.
  4. Check the site's certificate information by clicking the padlock icon; it should show the .onion domain.
  5. Look for the site's official announcement or PGP signature confirming this is the current address.

If the connection fails or Tor Browser shows a certificate mismatch warning, stop immediately. Do not proceed.

The Reality of Phishing and Clones

Even with v3's cryptographic protections, phishing remains the primary attack vector. An attacker cannot forge a v3 address, but they can register a visually similar one: swapping a 1 for an l, or a 0 for an O. They can also compromise a site's infrastructure and serve malicious content from the legitimate address. The v3 system prevents address spoofing, not social engineering or malware.

According to Tor Project documentation on onion service security, the most common attack is still the typo: a user misreads or miscopies an address and lands on a lookalike site. A second common scenario is a user bookmarking a phishing clone early on and returning to it repeatedly, never realizing it is fake. The third is a legitimate site being hacked and serving malware to visitors. V3 addresses do not protect against any of these; they only guarantee that the address you visit belongs to the operator you think it does. Verification through official channels remains your responsibility.

Finding and Using V3 Onion Links Safely

The most reliable source for current v3 onion links is the Tor Project's own directory of known services, which lists projects and organizations that have published their addresses. Many news organizations, privacy advocates, and whistleblowing platforms now operate v3 onion mirrors. These are typically linked from their clearnet homepages or announced via official social media accounts.

When searching for a specific onion site, start with the organization's official website or social media. If you are looking for a dark web marketplace, forum, or service that does not have a clearnet presence, use a Tor-based search engine like Ahmia or Not Evil, which index v3 sites. Be aware that search results can be outdated or malicious. Cross-reference any address you find with multiple independent sources before visiting. If you are using Tor Browser on Android or iPhone, the same verification steps apply; the address bar and certificate information are accessible the same way.

Common Mistakes When Using V3 Links

One frequent error is trusting a v3 address found in a database or link aggregator without verifying its source. Databases of onion links, even well-maintained ones, can contain outdated, abandoned, or malicious entries. A v3 address that was legitimate two years ago may now be a phishing clone or a seized site. Always trace the link back to an official announcement.

Another mistake is assuming that a working connection means a safe site. A v3 address proves the site's identity, not its legality or trustworthiness. You can connect to a v3 address and still encounter scams, malware, law-enforcement honeypots, or content you did not expect. Tor Browser's security is about anonymity and encryption, not content filtering. Use the same caution you would on the clearnet: do not download files unless you trust the source, do not enable plugins or extensions, and do not maximize your browser window (which can aid fingerprinting).

What You Should Do Now

If you have a list of old v2 onion links, discard them. They no longer work and any attempt to visit them will fail. If you are looking for a specific dark web service or resource, start by searching for its official website or social media account, then look for a link to its current v3 onion address. Bookmark only addresses you have verified through multiple independent official sources.

Install or update Tor Browser to the latest version, which supports v3 addresses and includes the latest security patches. If you are accessing onion sites on a mobile device, use Tor Browser for Android or Onion Browser for iOS, both of which handle v3 addresses correctly. Take a moment to review the Tor Project's guide to onion service security on their official website; it covers phishing prevention and best practices in detail. Your next step is to verify the address of any onion site you plan to visit regularly by checking its official announcement or PGP signature.

Common Questions

What is the difference between v2 and v3 onion links

V2 onion addresses were 16 characters and used RSA-1024 encryption; v3 addresses are 56 characters and use ed25519 elliptic curve cryptography. V3 is more secure because the address is cryptographically bound to the site's key, preventing address forgery. The Tor Project disabled v2 support in October 2021, so v2 addresses no longer work.

How do I know if an onion link is real or a phishing clone

Verify the address through official channels: the site's clearnet homepage, a PGP-signed announcement, or the Tor Project's directory. V3 addresses prevent spoofing, but not typos or social engineering. Always copy the address exactly, and check the certificate in Tor Browser by clicking the padlock icon. If the connection fails or shows a mismatch warning, stop immediately.

Can I use v3 onion links on my phone

Yes. Tor Browser for Android and Onion Browser for iOS both support v3 addresses. The verification process is the same: connect through Tor, check the certificate, and verify the address through official sources. Mobile browsers handle v3 links identically to desktop Tor Browser.

Where can I find a list of current v3 onion links

The Tor Project maintains a directory of known onion services on their official website. Many organizations publish their v3 addresses on their clearnet sites or official social media. Tor-based search engines like Ahmia index v3 sites, but results can be outdated. Always verify any address you find against multiple independent official sources.

Why are v3 onion addresses so long

The 56-character length encodes the site's 32-byte ed25519 public key using base32 encoding. This length makes the address cryptographically bound to the site's identity, preventing attackers from forging addresses. The longer format is a security feature, not a limitation.