Skip to main content

Market PGP Keys — Fingerprint & Canary Archive

PGP verification is standard advice before connecting to any market — but the advice rarely includes what the key looks like, how old it is, or how often operators should post a canary. Below: current fingerprint, key age, canary cadence, and address rotation history for every major active market.

Why Key Age and Cadence Matter More Than the Fingerprint Alone

A fingerprint by itself proves nothing except that a message was signed by whoever holds the matching private key. What it doesn't tell you is whether that key has been stable over time, or whether the team behind it posts canaries on a schedule you can actually audit. A key that's been publicly circulating for four years without a disputed rotation is a fundamentally different trust signal than one that appeared two months ago — even if both produce a mathematically valid signature today.

That's why a useful key reference tracks four things per market rather than just the fingerprint: when the key was first observed in circulation, how frequently the team is expected to post a signed canary, the date of the most recent confirmed canary, and how many times the address set has rotated in the trailing twelve months. Rotation frequency isn't a red flag on its own — DDoS pressure and routine operational security both cause rotations — but a market that rotates constantly with no announced reason is worth watching more closely than one that hasn't moved in a year.

Current Key and Canary Data — September 2026

PGP Key Fingerprints & Canary Cadence — Verified September 2026
Market Key First Observed Fingerprint (last block) Canary Cadence Last Verified Canary Rotations (12mo)
DarkMatter Feb 2022 ...33C5 7E29 B804 91FA Monthly 2026-09-18 0
DrugHub Jan 2024 ...A417 D2C9 6B08 5EFA Weekly 2026-09-24 3 (entry point)
TorZon Sep 2022 ...9C41 F730 A8D2 116B Bi-weekly 2026-09-20 2
Nexus Nov 2023 ...5B90 E246 C1A7 3F08 Weekly 2026-09-25 4
WeTheNorth Jun 2021 ...7D14 B689 22FE C053 Monthly 2026-09-12 1
Black Ops Sep 2024 ...E802 4F1A D935 6C77 Weekly 2026-09-26 3
Catharsis Mar 2025 ...C398 71B0 4AD6 2E15 Weekly 2026-09-22 5
Bazaar Nov 2019 (forum key) ...61FB 3D9A 08C4 E752 Monthly 2026-09-19 1

Fingerprints are truncated to the final block for display. Cross-reference the full 40-character fingerprint against the market's own subdread or canary page before trusting it — never rely on a partial match from this or any other directory.

Bazaar's Key Predates Every Market Here — Including DarkMatter

The most useful data point in this table might be the one that's easiest to miss: Bazaar's PGP key wasn't generated when the market launched in 2025. It was generated in November 2019, when BreakingBad was still a discussion forum with no transactional layer at all. That's nearly three years before DarkMatter's key — the next-oldest among active markets — even entered circulation.

This is the practical upside of a forum-to-market evolution, covered in more depth in the market history timeline: the cryptographic identity of the operators predates the marketplace by years, which means there's a longer independent record to cross-reference the key against. A brand-new market key has no such history — which is exactly why Catharsis, at five rotations in the trailing twelve months, is the most volatile entry in this table. New markets get phished harder and rotate more, which is precisely why key age deserves as much attention as the fingerprint itself.

How to Cross-Check a Fingerprint Yourself

  1. Pull the key from two sources that don't share an operator. The market's own canary page and an archived Dread post are usually independent enough. A Telegram channel and a paste site usually aren't — both are common phishing distribution points and can be run by the same person.
  2. Compare the full 40-character fingerprint, not the short key ID. Short IDs (the last 8 hex characters) can be intentionally collided with enough compute time. It's a known technique and it defeats short-ID verification specifically.
  3. Check the key's first-observed date against what you already have saved. If a market's key suddenly shows a different creation date with no announcement, that's a signal the identity changed — not just the address.
  4. Verify the signature, not just the presence of a canary. A canary statement existing on a page proves nothing. Run it through GPG or Kleopatra and confirm the signature actually validates against the fingerprint you're checking.
  5. Re-check after any gap in visits. If you haven't connected to a market in a month or more, treat your saved fingerprint as unverified until you've re-confirmed it against a current canary.

For a breakdown of how phishing clones actually operate once you skip one of these steps, see the phishing analysis.