The vendor channel
Vendor communication runs separately from buyer communication, and the split has consequences for both sides.
Announcements reaching vendors are not the same announcements reaching buyers, and readers who assume one channel get confused when a vendor references something they have never seen. The split is deliberate.
Why separate
The two audiences need different things. A buyer needs to know whether the platform is reachable and whether an order is progressing. A vendor needs settlement timing, dispute policy, fee structure, listing rules, and warning of changes far enough ahead to adjust. Merging them means every buyer reads operational detail that does not apply to them, and every vendor digs through reachability notices for the paragraph that does.
The second reason is timing. Vendors generally need advance notice of a change that buyers only need to know about once it lands. A fee change or a settlement timing change that arrives without warning strands a vendor mid transaction, so the vendor channel runs ahead of the buyer one on the same event.
What it carries
- Settlement mechanics and timing, including anything affecting when funds become available.
- Dispute policy changes, weighting adjustments, and evidence requirements.
- Listing rules and enforcement, particularly categories being restricted.
- Advance notice of platform changes affecting order flow.
- Security notices specific to vendor accounts, which are attacked differently and more persistently than buyer accounts.
Why vendor accounts get attacked harder
Worth stating plainly. A compromised buyer account holds a balance. A compromised vendor account holds a reputation built over years, an order flow that can be redirected, and the ability to talk to a large number of buyers as a trusted party. The last one is why it is worth more, since a vendor account is a phishing platform with the credibility already built in.
Which means vendor side verification habits need to be stricter than buyer side ones, not equal to them. The same check, run more consistently, on a channel that is targeted more often.
How it gets impersonated
The vendor channel is a favoured impersonation target for a specific reason. Vendors expect to receive operational messages, which buyers largely do not, so an unexpected message to a vendor is less unusual than an unexpected message to a buyer and clears the initial suspicion threshold more easily.
The forgeries follow the beat. A fee change requiring immediate action. A dispute policy update with a deadline. A settlement problem that needs a wallet address confirmed. All plausible, all urgent, and all asking for something a genuine notice would never ask for.
The rule is the same one that governs everything else here, applied more strictly. A vendor notice is the signature or it is nothing. Not the plausibility, not the formatting, not the fact that it arrived where vendor notices usually arrive. If it is not signed by the pinned key it is not from the platform, and the more reasonable and urgent it sounds the more that matters.
Verified working Nexus Market mirrors
Three v3 onion addresses currently serving the production market, signed under PGP fingerprint 0x7F2A0A9D. Use the Copy buttons.