KNOWLEDGE BASE

System FAQ

Documentation regarding DrugHub Market operations, cryptographic security protocols, Monero settlement layers, and account management procedures.

Index updated: Today

General Operations

This site functions as the primary verified mirror distributor for DrugHub Market. We maintain a list of cryptographically signed V3 onion addresses to ensure users can bypass censorship filters and avoid malicious phishing clones. All links listed here are verified against the market's master PGP key.

DrugHub utilizes standard Tor hidden service protocols. When you access a .onion link, your traffic is routed through three random nodes (Guard, Middle, Exit) before reaching the server. This triple-layer encryption ensures that neither your ISP nor the marketplace host can determine your physical location or identity.

While the core market functions without JavaScript (Safest Mode recommended), the initial DDoS protection layer may require limited JS execution to solve Proof-of-Work (PoW) challenges. This prevents botnets from overwhelming the server resources. Once inside, you may disable JavaScript completely for maximum security.

Security Protocols

DrugHub does not store passwords. Accounts are tied strictly to a PGP Public Key. To authenticate:

  1. Enter your username.
  2. The server presents a unique message encrypted with your Public Key.
  3. You decrypt this message using your Private Key locally.
  4. Paste the decrypted token back into the site to gain access.

This renders credential phishing and database leaks ineffective.

Upon registration, DrugHub generates a unique, private onion address for your account. This isolates your traffic from the public gateways. If the main URL is under DDoS attack, your private mirror remains operational. Additionally, because only you know this URL, it serves as a definitive anti-phishing safeguard.

On the login page, the market provides a signed message containing the current timestamp and URL. Import the DrugHub Public Key (available on our Home page) into your keyring. Verify the signature matches the message. If the verification fails or returns "Bad Signature," do not proceed—you are on a phishing site.

Financial Systems

Bitcoin (BTC) utilizes a transparent public ledger, making it trivial for analytics firms to trace transactions. DrugHub mandates Monero (XMR) because of its privacy technologies: Ring Signatures hide the sender, RingCT hides the amount, and Stealth Addresses hide the receiver. This ensures complete financial obscurity for all participants.

To prevent theft and exit scams, funds are held in a multi-signature wallet. Three keys are generated: one for the Buyer, one for the Vendor, and one for the Market. Releasing funds requires 2 of 3 signatures. Typically, the Buyer and Vendor sign upon successful delivery. In a dispute, the Market steps in to sign with the winning party. No single entity can move the funds unilaterally.

DrugHub charges a dynamic commission fee to vendors, ranging from 5% down to 3% based on vendor level and volume. Buyers pay zero fees on purchases. Network transaction fees (mining fees) for Monero are negligible and paid by the sender.

Vendor & Orders

To deter scammers, all vendors must pay a refundable bond. Standard bond is 2 XMR. Established vendors from other markets (Recon/Dread verified) may apply for a bond waiver. All vendors undergo a vetting process, including proof of stock and mandatory PGP key verification.

Orders automatically finalize after a set period if the buyer does not confirm receipt or open a dispute.
Physical goods: 14 days (extendable by 7 days).
Digital goods: 48 hours.
If you do not act before the timer expires, funds are released to the vendor and cannot be recovered.

If an order fails to arrive or is incorrect, open a dispute immediately. A moderator will join the encrypted chat. They will review vendor terms, shipping proofs, and user history. The moderator will then sign the transaction to either refund the buyer or release funds to the vendor. Decisions are final.

Unanswered Questions?

Our support staff operates 24/7 to assist with PGP issues, deposit tracking, and account recovery.

Open Support Ticket