Login across mirrors
What happens to your session when you move between addresses, and the login screen habits worth having.
A recurring support question is whether logging in through a different address creates a different account, or loses an order, or requires anything at all. The short answer is no to all of it, and the reason is worth a page because it changes how people behave during an outage.
Why switching costs nothing
The addresses are routes to one backend. Account, balance, orders, and messages live behind that backend rather than being attached to whichever address you arrived through. Switching mirrors is closer to walking through a different door of the same building than to visiting a different building.
Session state is shared for the same reason. A session established at one address is recognised at another, so a mirror going unreachable mid session does not throw away what you were doing. Move, carry on. This is the single most useful thing to know during an incident, and the thing people most often do not know, which is why they sit reloading a dead address instead.
The login screen is where attacks land
Everything an attacker wants is entered on that one screen, which makes it the highest value thing to clone and the place to be most deliberate. The habits that matter are few.
- Verify before typing, not after. Verification after you have entered credentials tells you what happened rather than preventing it.
- Never paste credentials into a page you arrived at from a link someone sent. Navigate there yourself from an address you established independently.
- Treat an unexpected re login prompt as suspicious. Being asked to log in again mid session, particularly during an incident, is a pattern worth stopping over.
- Never enter a wallet seed anywhere. No legitimate flow asks for one. There is no exception, no migration, no verification step that needs it.
- Do not let a password manager fill on an onion you have not verified. Convenience here removes the pause where you would have noticed.
The incident pattern
Attacks cluster during outages, and the reason is structural rather than coincidental. During an incident people are anxious, the real addresses are unreachable so the usual comparison is unavailable, and a helpful new address appearing in a forum thread looks like a solution rather than an approach. Verification matters most exactly when it feels most like an obstacle.
So the rule for incidents is the inverse of what instinct suggests. When things are working normally, a skipped check usually costs nothing. When things are broken and somebody is offering you a way in, that is the check that was worth having.
If you think credentials leaked
Change the password from a session you established through an address you verified yourself, not through whatever you were using when it went wrong. Check the message log and open orders for anything you did not do. If a session was compromised, the account is the immediate concern and the wallet is the one after that, in that order, because the account is what an attacker can act through right now.
Verified working Nexus Market mirrors
Three v3 onion addresses currently serving the production market, signed under PGP fingerprint 0x7F2A0A9D. Use the Copy buttons.