Inside a Dark Web Counterfeit Currency Operation

bs-single-container

Executive Summary

  • UK counterfeit detections doubled in 2025, to roughly 200,000 notes worth ÂŁ3.97m. Euro counterfeits fell 20% over the same period. The divergence raises an obvious question about where supply actually originates.
  • Bolster AI’s Threat Intelligence Lab examined ShadowMarket, a Tor-hosted market whose “Money Counterfeits” category is dominated by three vendors advertising five currencies and claiming 57,803 combined orders.
  • We monitored all three profiles for nine days across 123 captures, mapped the payment infrastructure, and read the client-side code the market serves to every visitor.
  • The market’s own systems contradict its storefronts. The order counters are a daily display value, the escrow contains no escrow, and the three vendors share one payment pool. We reported an exposed endpoint and briefed authorities ahead of publication.

Key Findings

1. The order counters are a publication schedule, not a transaction feed. All 27 changes we recorded landed inside the 00:00 to 06:00 UTC window, exactly once per vendor per day. Across 92 observed daytime intervals, nothing moved at all. Treating these numbers as live trade volume measures a cron job.

2. The market’s own records put lifetime order volume below 2,400, against 57,803 claimed. Checkout pulls its Bitcoin address from an internal endpoint that needs no login and ends in a sequential order number. The counter had reached 2,306, with 2,231 slots returning an address.

3. Those orders funnel through a fixed pool of roughly 600 reused Bitcoin addresses. The 2,231 populated slots mapped to 602 wallets, one of them issued 22 separate times. Real escrow keeps every deal separate, because pooling unrelated buyers onto one address tangles their payments together on a public ledger.

4. The “Multisig Escrow System” contains no multisig, and the “secure” messaging is plain text. No script the market serves contains cryptography of any kind. Genuine multisig requires the buyer to hold a key, and nothing on the platform generates one. Messages post to the server unencrypted, readable by whoever runs it.

5. The three “independent” vendors are one operation. Two publish word-for-word identical product descriptions, all three draw from the same wallet pool, and all three move to the same overnight beat. Franklin Company also specifies paper substrate for GBP, CAD, and AUD notes, all three polymer currencies.

The Numbers Behind the Storefront

Counterfeit currency is having a moment, and the dark web is where the industry claims to live.

The Bank of England’s 2025 figures got attention for good reason. Roughly 200,000 counterfeit notes came out of circulation, more than double the year before, with a face value of £3.97m against £2.1m. Counterfeits remain vanishingly rare, under 0.0041% of notes in circulation, but the direction of travel prompted a public response. Chief Cashier Victoria Cleland said the Bank is now working with online marketplaces and law enforcement to stop counterfeit notes reaching the UK at source, and to have listings removed.

The trend isn’t uniform. The European Central Bank recorded 444,000 counterfeit euro notes withdrawn over the same period, a 20% decrease year on year, with €20 and €50 notes making up around 80% of the total. Detections up sharply in one major economy and down in another raises an obvious question about where supply originates.

That was the backdrop when Bolster AI’s Threat Intelligence Lab set out to look at the supply side. We identified ShadowMarket, a Tor-hosted marketplace carrying a dedicated “Money Counterfeits” category alongside carding, hacking, and money-transfer listings. Three vendors dominate it: Franklin Company (“The highest quality Counterfeit money”), Dead Presidents (“We sell real money”), and EuroCash (“Fake Euros with the fastest and safest delivery”). Between them they claim tenures dating to 2016 and tens of thousands of completed orders.

How We Monitored

Every vendor profile in the counterfeit-currency category displays a running Orders total. It sits above the star rating and the “Customer protection: Yes” badge, and it is the most prominent number on the page, the figure that communicates scale and track record. So we measured it.

Between 3 and 12 August 2026 we captured each of the three vendor profiles four times per day at roughly six-hour intervals, recording the displayed order total, the online status, and the claimed “Member Since” date. Across the 8.8-day window that produced 123 captures. We did not transact with any vendor, and every finding below is drawn from what the marketplace serves publicly.

What the Vendors Claim

At the close of the observation window, the three vendors displayed the following:

VendorClaimed “Member Since”Claimed tenureClaimed ordersCurrencies advertised
Dead PresidentsJul 2016~10.1 years21,347USD
Franklin CompanyJan 2016~10.6 years20,047USD, GBP, EUR, AUD, CAD
EuroCashMay 2017~9.2 years16,409EUR
Combined57,803

Taken at face value, that is 57,803 transactions and close to thirty years of vendor operation in a single category on a single marketplace. All three carry five-star or near-five-star ratings and the “Customer protection” badge. These figures are published by the vendors and should be read throughout as claims.

What We Observed

VendorTotal at first captureTotal at last captureMovementAverage per day
Dead Presidents21,31221,347+353.98
Franklin Company20,01820,047+293.29
EuroCash16,38516,409+242.72
Combined57,71557,803+88~10.0

Across the three vendors, the displayed totals advanced by 88 over 8.8 days, an average of roughly ten per day, or about 3.3 per vendor per day.

The Totals Update Once Per Day, Overnight

Monitoring four times daily surfaced a pattern that a single before-and-after comparison would have missed entirely: the displayed totals do not move during the day.

Across the observation window we recorded 27 changes to the order totals, and every one occurred during the 00:00 to 06:00 UTC interval. Across 92 daytime intervals the totals were identical at the start and the end of every single one. Each vendor’s total changed exactly once per day, without exception, by amounts ranging from 1 to 7 and averaging 3.3.

These are published figures on a daily refresh, not a live transaction feed. A visitor checking a vendor profile at any point during the day is reading a number that was set the previous night.

Vendor Availability: Online, Offline, and Back Again

Alongside the order totals, we recorded each vendor’s Status indicator at every capture. None of the three remained continuously available, and all moved between “Online” and “Offline” repeatedly across the monitoring window. Across 123 captures, a vendor was shown as offline 21 times, an overall rate of 17%.

VendorCapturesShown offlineOffline rate
Dead Presidents411024%
EuroCash42614%
Franklin Company40512%
All vendors1232117%

These offline states did not fall into a single block of hours. They appeared across every one of the four daily capture slots.

More striking is what they did not do: they did not go offline together. Of 40 runs covering all three profiles at once, 25 showed all three online and only one showed all three offline, closely matching what unrelated behavior would predict. Each indicator changes on its own schedule.

The Status indicator is presented as a signal of live vendor presence, an implicit suggestion that a person is at the other end right now. What we observed flips at different times for each vendor, without ever settling into the rhythm a single human operator in any one time zone would produce.

What These Numbers Can and Cannot Tell You

The +88 we recorded is 88 units of increase in a published value across nine daily updates, not evidence that 88 transactions occurred. The claimed lifetime figures deserve the same caution: the tenure dates imply 4.9 to 5.8 orders per day sustained for close to a decade, self-reported on a platform with an obvious interest in appearing established. Metrics of this kind should be corroborated against seizure data, enforcement actions, and currency-authority reporting before being used to characterize counterfeit supply in any jurisdiction.

Three Storefronts, Three Sales Narratives

The three counterfeit-currency vendors on ShadowMarket do not present themselves as a single operation. Each maintains a distinct storefront, a distinct sales narrative, and a distinct specialization: one focused on US dollars, one on euros, and one advertising five currencies simultaneously.

Dead Presidents: “We Do Not Sell Fake Money!”

Of the three vendors, Dead Presidents is the most unusual, because it explicitly denies selling counterfeit currency at all.

The profile carries the tagline “We sell real money,” and the About Vendor section opens with a highlighted “We do not sell fake money!” The claim that follows is that the notes are genuine central bank currency, withdrawn from circulation and marked for destruction, intercepted before it was destroyed. That is a materially different proposition from the other two, and worth taking seriously as social engineering.

The pitch is structured as a sequence of short, confident sections that read like an explanation rather than a sales page:

  • “Used Cash Is Shredded.” Central banks routinely destroy worn banknotes, citing the ECB and a technical criterion: notes with holes totalling more than 19 square millimetres are unfit.
  • “We Acquire Cash before Its Shredded,” “We Have a Problem,” “We Cant Spend It,” and “We Need Help.” Four steps of one story. The team claims “access” to an “almost limitless supply of cash marked for disposal,” can remove only small quantities, cannot spend the notes itself without attracting attention, and therefore offers them for Bitcoin.
  • “No Risk for You.” No records are kept, serial numbers are unknown, and “buying cash is not illegal.”

Three things undercut it.

The technical framing is real, but one load-bearing figure is not. Central banks do destroy unfit banknotes at scale, and the reference to sensor sorting and hole-area criteria reflects genuine practice. But the claim that “In 2015 9 Billion EURO was destroyed by the ECB” conflates two units. Published figures of that magnitude count banknotes processed and replaced, not a euro value.

The legal claim is false. Receiving, possessing, or handling banknotes known or suspected to be stolen is a criminal offence across all relevant jurisdictions. If the vendor’s own account were true, a purchaser would be knowingly acquiring stolen currency. “No one knows their serial numbers” addresses only the buyer’s fear of detection, not the offence.

The page contradicts itself. The Category field, three lines above the “We do not sell fake money!” banner, reads Money counterfeits. The marketplace lists the vendor in the counterfeit category while the vendor asserts it sells no counterfeits, both shown to the visitor simultaneously, with no way to determine which is correct.

Franklin Company: The Industrial Pitch

Franklin Company does the opposite. Its tagline is “The highest quality Counterfeit money,” and it makes no attempt at a cover story. It is the only vendor advertising a full multi-currency catalogue, and presents itself as a manufacturer rather than an intermediary. It claims tenure from Jan 2016, displayed 20,047 orders, and carries a five-star rating.

Franklin Company operates a conventional product grid, ten listings across five currencies at two order sizes each. With EuroCash’s eight euro listings, it gives the clearest picture the marketplace offers of how counterfeit currency is packaged and priced.

VendorListingFace valueFace value in USD*Price% of face
Franklin CompanyUS dollar bundle$3,000$3,000$1505.00%
Franklin CompanyUS dollar bundle$6,000$6,000$2804.67%
Franklin CompanyEuro bundle€3,000$3,454$1755.07%
Franklin CompanyEuro bundle€6,000$6,909$3254.70%
Franklin CompanyGBP bundleÂŁ3,000$4,046$1904.70%
Franklin CompanyGBP bundleÂŁ6,000$8,092$3554.39%
Franklin CompanyCanadian dollar bundleC$3,000$2,149$1105.12%
Franklin CompanyCanadian dollar bundleC$6,000$4,297$2104.89%
Franklin CompanyAustralian dollar bundleA$3,000$2,118$1105.19%
Franklin CompanyAustralian dollar bundleA$6,000$4,236$2104.96%
EuroCash40 × €50€2,000$2,303$1004.34%
EuroCash20 × €100€2,000$2,303$1004.34%
EuroCash10 × €200€2,000$2,303$1004.34%
EuroCash80 × €50€4,000$4,606$1904.13%
EuroCash40 × €100€4,000$4,606$1904.13%
EuroCash20 × €200€4,000$4,606$1904.13%
EuroCash60 × €100€6,000$6,909$3004.34%
EuroCash30 × €200€6,000$6,909$1902.75%

*Converted at market rates for August 2026 (EUR/USD 1.1515, GBP/USD 1.3486, CAD/USD 0.7162, AUD/USD 0.7060).

Pricing sits in a narrow band, 4.39% to 5.19% of face value across all ten listings, mean 4.9%, with a modest volume discount at the larger tier. The vendor asserts its notes defeat common point-of-sale authentication checks and can be used in retail, banking, casino, ATM, and money-changer settings, and lists banknote security features it claims to reproduce.

The substrate claim doesn’t survive contact with the catalogue. Franklin Company specifies a cotton and wood fibre paper substrate across its full currency range. Three of those currencies, GBP, CAD, and AUD, are polymer. A vendor genuinely producing notes in five currencies would know which are printed on plastic, because it is the first constraint of the job. The specification reads as copy attached to a catalogue, not a description of anything manufactured.

Franklin Company also invites buyers who “want to learn how to produce quality bills like us” to make contact. That is an offer of knowledge transfer rather than product, and whether or not the vendor can deliver, advertising instruction in counterfeit production is a different category of harm from selling finished notes: it proposes to multiply producers rather than volume. Enforcement bodies may consider it separately.

The vendor states that orders ship in envelopes with X-ray-resistant packaging via national postal services, which places these listings within the remit of postal inspection and customs authorities as well as financial crime agencies.

AttributeObservation
TenureJan 2016 (~10.6 years)
Orders20,047
Rating5 stars
CurrenciesUSD, EUR, GBP, CAD, AUD; 10 listings, two tiers
PositioningOpenly advertises counterfeit production
Pricing4.39% to 5.19% of face, mean 4.9%
Volume discount4.5% to 7.1% at the 6,000 tier
SubstrateCotton and wood fibre paper; GBP, CAD, and AUD are polymer
Additional offerInstruction in production, on request
ShippingNational postal, X-ray-resistant packaging
PaymentBitcoin, per-order address, 3 confirmations

EuroCash: The Same Test, A Different Storefront

EuroCash is the smallest by claimed volume and the only one without five stars. Its tagline is “Fake Euros with the fastest and safest delivery,” it claims tenure from May 2017, and it displayed 16,409 orders against a four-star rating.

Its About Vendor section opens with “Hello! We are EuroCash” and a claim that the operation uses “the new 2024 technology.” That is two years stale, a small thing, but the kind that indicates copy written once and left untouched. The larger issue is what the rest of the section contains.

The product description is shared with Franklin Company. The two profiles carry substantially identical technical descriptions: the same substrate specifications, fibre percentages, and chemical additives including a duplicated entry, the same claims about bypassing two authentication checks, the same five commercial settings, and the same six security features in identical order. Only the framing language differs.

The marketplace presents them as independent vendors, with different names, logos, tenure dates, currency ranges, ratings, and order histories. Matching descriptions indicate a common source of copy. The text alone can’t establish whether they share an operator or simply a template, but the profiles are not independently authored, and buyers are given no indication of that.

EuroCash sells euros only, despite a description claiming notes “of all currencies all over the world.” Its listings are expressed as a note count multiplied by a denomination rather than face-value bundles, as the catalogue table above shows.

Denomination mix is one of the few variables that genuinely matters in counterfeit currency. The ECB has consistently found €20 and €50 notes to make up around 80% of counterfeits withdrawn from circulation, because low denominations attract less scrutiny at the point of sale. A pricing model indifferent to denomination treats notes as interchangeable units of face value rather than products with different risk profiles and production requirements.

AttributeObservation
TenureMay 2017 (~9.2 years)
Orders16,409
Rating4 stars, the only vendor not showing 5
CurrenciesEuro only, despite claiming “all currencies”
Catalogue8 listings, note count × denomination, €50 to €200
Pricing2.75% to 4.34% of face, indifferent to denomination
Catalogue error€6,000 face offered at both $300 and $190
Order pageItem listed at $100 charged at $120
DescriptionSubstantively identical to Franklin Company’s
PaymentBitcoin, per-order address, 3 confirmations

The Payment Flow and a Third-Party Dependency

For all three vendors, the payment page presents a native SegWit (bech32) Bitcoin address, an exact amount, and a QR code, with instructions that the full amount must be transferred and that the order proceeds after three blockchain confirmations.

The significant finding here is not the address but how the QR code is produced. It is not generated by the marketplace. It is requested from api.qrserver.com, a third-party service on the public internet, via a URL carrying the payment details in the query string:

GET https://api.qrserver.com/v1/create-qr-code/

     ?size=200×200

     &data=bitcoin:bc1q3ahgv7zh3e4lq93zg4c3wmxv5cslmhemsvn7z5?amount=0.0034035

Three consequences follow.

Payment data leaves the hidden service. Every Bitcoin address and amount the marketplace issues is transmitted to a commercial third party in the clear. That company operates under an identifiable jurisdiction, and its server logs would contain a record of payment addresses and amounts associated with this marketplace’s orders.

It creates exposure for buyers. The request originates from the buyer’s own browser at the moment of payment, so a buyer with an imperfect configuration makes a direct clearnet request at precisely the moment they are transacting.

It indicates an incomplete threat model. A marketplace built on anonymity guarantees is routing its most sensitive per-order data through an external clearnet API rather than rendering a QR code locally, which is trivial to do. This behavior was identical on all three vendors’ payment pages, which indicates it is a property of the marketplace platform rather than of any individual vendor.

Escrow: The Trust Mechanism That Turns Browsers Into Buyers

Of everything ShadowMarket publishes about itself, one word does more work than any other. Not the ratings, and not the order counts. Escrow.

A buyer sending cryptocurrency to an anonymous seller for an illegal product has no recourse. No chargeback, no regulator, no court. If the seller disappears, that is the end of it. Against that, “escrow” is the most valuable thing a market can put on its front page, because it is what makes a first purchase feel survivable.

ShadowMarket puts it everywhere. Every vendor profile carries a “Customer protection: Yes” row and a Buyer Protection panel promising a full refund if an order does not arrive. The policy page describes a Money Back Guarantee, disputes within 15 days, refunds in 2 to 5 business days, and a Multisig Escrow System holding funds until the buyer acknowledges receipt.

What Multisig Escrow Actually Means

Multi-signature escrow is a real cryptographic arrangement. Funds are locked to an address requiring m of n keys to move, typically 2-of-3, with one key each held by buyer, seller, and marketplace.

Its value lies in one property: no single party can move the funds alone, including the marketplace. If the operator vanishes, buyer and seller together hold two of three keys and recover the funds without it. Multisig is not a promise that the operator will behave well. It is an arrangement that makes the operator’s good behavior unnecessary.

That requires one thing without exception. The buyer must hold a key. A buyer who never generates a key pair is not a signatory, and the arrangement is not multisig from their side, whatever it is called.

The Door That Was Left Open

If ShadowMarket really holds buyers’ money in escrow, the money has to sit somewhere. So we went looking for the market’s own wallets, the addresses where funds land after a buyer pays. We found more than we expected.

When a buyer reaches the payment page, the marketplace shows them a Bitcoin address. Watching how that page was built, we noticed it pulled the address from an internal endpoint of its own, ending in a number:

/cart/payment/btc-address/2290

Two things stood out. The endpoint needed no login: anyone who knew the address could ask for it and get an answer, with no account, no session, no check of any kind. And it ended in a plain, predictable number. Our order was 2290, which raised an obvious question. What happens at 2289? At 1?

The endpoint answered every time. Each number returned the Bitcoin address tied to that order slot, no questions asked. The market had left a window open onto its own payment records, and the window was numbered.

(We reported this exposure through the appropriate channel ahead of publication. We are not publishing the endpoint itself.)

Counting the Doors

Working through the range, we mapped how many order slots existed. The numbering reached 2,306, of which 2,231 returned a Bitcoin address. The lowest slots, below 70, returned nothing, which suggests the counter had been running for some time before our visit and its earliest records were gone.

That is an independent count of how many orders the platform has processed, taken from its own internal numbering rather than the vendor counters we showed to be cosmetic. And it is far smaller. The vendor profiles claim tens of thousands of orders each. The payment system had issued fewer than 2,400 in total.

The Addresses Repeat

Then we looked at the addresses themselves, and the real surprise appeared.

Those 2,231 slots did not map to 2,231 wallets. They mapped to 602, an average of nearly four buyers per address. Some were reused far more: one address was issued to 22 separate slots, another to 21, with a long tail appearing ten to seventeen times each.

The three checkout addresses we captured earlier, one per vendor, were all in here and all reused. The EuroCash address alone turned up seven times, spread from early orders to the most recent. These were not fresh per-transaction wallets but a fixed pool of about 600, dealt out to whoever happened to be paying.

A recycled pool of addresses tells us two things.

It does not look like escrow. A real escrow system keeps each deal separate. It would never route dozens of unrelated buyers to the same deposit address, because that tangles everyone’s payments together on the public blockchain and you can no longer tell whose money is whose. This is how an ordinary payment collector behaves, not a neutral arbiter holding money in trust.

The addresses do not belong to the vendors. The same wallet is shared across orders that would belong to different sellers, and each vendor’s “own” address reappears at slots far apart in the sequence. The payment system sits above the vendors, feeding them all from one bucket, which points the same way as the synchronized overnight counters.

None of this proves what happens to the money after it lands, since we can see the addresses but not the flows between them. But it answers the question we started with. The escrow story asks buyers to believe their money sits apart until they confirm the order. The wallet pool shows it funnelled through a small, shared set of addresses the buyer never controls.

What the Market’s Own Code Reveals

A marketplace can write anything in its policies. Its code is harder to fake, because the code is what actually runs. We recovered and read ShadowMarket’s client-side JavaScript. We have withheld internal paths and the marketplace’s address, and kept code to the minimum needed to make each point.

“Secure” Messaging That Isn’t

Every vendor page has a “Send Message” button, and the market advertises anonymity and security. The script behind it does something very simple. It posts the message straight to the server in plain text:

$.post(“/messenger/send-message/” + dialogId, { _token: token, content: content });

There is no encryption before the message leaves the browser, and incoming messages are polled from the server every few seconds. Every buyer to seller conversation on ShadowMarket is readable by whoever runs it, including negotiations, delivery addresses, and order details, and recoverable from the server through lawful process.

Where the Payment Address Comes From

The payment script accounts for the wallet behavior mapped above. It reads the order number, fetches the address from the same unauthenticated endpoint, and hands the QR code off to the third-party service:

fetch(‘/cart/payment/btc-address/’ + orderId)

    .then(res => res.json())

    .then(data => {

        qrImg.src = ‘https://api.qrserver.com/v1/create-qr-code/?…&data=’

                    + encodeURIComponent(btcUri);

    });

What Is Missing

Across every script, the main bundle, the messenger, and the payment page, there is no cryptography of any kind: no PGP, no key generation, no wallet logic, no redeem scripts, no multisig. That breaks two of the market’s central claims.

No PGP means no verifiable vendor identity. Buyers cannot confirm that a vendor is a consistent, real seller, or that a payment address wasn’t swapped, which is exactly why two “separate” vendors sharing a word-for-word product description matters.

No cryptography means no real escrow. Genuine multisig needs the buyer to hold a key, and no code lets them. The “Multisig Escrow System” contains no multisig.

A Forensic Note

The scripts shipped with developer comments still attached, a sloppy non-production build, and those comments are in Russian. That identifies no one on its own. Stacked with the shared code, the single reused wallet pool, and the synchronized counters, it points one way: a single Russian-speaking operator or team behind a conventional web application, dressed as three vendors.

Conclusion: The Storefront Is Real, The Trust Is Not

UK detections doubled in a year, and central banks are now saying openly that they are working with online platforms to cut supply off at source. That was the backdrop when we set out to look at where that supply claims to live.

What we found on ShadowMarket was not an industrial counterfeiting operation quietly serving five economies. We found something more revealing: a marketplace engineered, top to bottom, to look like one.

Three vendors advertise counterfeit pounds, dollars, euros, Canadian notes, and Australian notes, wrapped in five-star ratings, tens of thousands of claimed orders, buyer-protection badges, and a “Multisig Escrow System.” Piece by piece, the market’s own evidence took those signals apart:

  • The order count moved once a night and never during business hours. It is a display value on a daily cycle.
  • The “independent” vendors share one script. Two publish word-for-word identical descriptions, and all three draw payments from the same wallet pool.
  • The escrow has no escrow in it. Multisig requires the buyer to hold a key, and the code never lets them. What it calls escrow is a custodial deposit the operator controls outright.
  • The “secure, anonymous” messaging is plain text, readable by whoever runs the market and by anyone who lawfully obtains the server.
  • The payments run through roughly 600 reused addresses, fed by an unauthenticated endpoint that exposed the market’s entire order-to-address mapping.
  • The developer left Russian comments in the code, in a sloppy build that shipped its own internals to every visitor.

The notes on sale may be paper, polymer, or nothing at all. From outside, that can’t be proven either way. But the trust the market sells is manufactured, and manufactured is a finding we can stand behind completely. On ShadowMarket, the credibility is the product, and it is counterfeit. That is the real lesson for anyone tracking this threat.

A Note for Law Enforcement

Bolster AI reported the exposed endpoint through the appropriate channel and shared its findings with relevant authorities ahead of publication. For investigating agencies, this market offers several concrete threads that require no undercover purchase and no breach, all of it drawn from what the marketplace serves publicly:

  • A third-party QR-code service (api.qrserver.com) holds logs tying payment addresses and amounts to this market’s orders, obtainable by legal process in an identifiable jurisdiction.
  • Buyer to seller messaging is not end-to-end encrypted and is recoverable from the server on seizure.
  • Payments concentrate in roughly 600 heavily reused addresses, making blockchain tracing unusually tractable.
  • An unauthenticated, sequentially numbered payment endpoint exposes the order-to-address mapping.
  • The absence of PGP and any real multisig points to central, single-operator control.

We hold the complete, unredacted evidence set, and will make it available to verified law enforcement on request.

Indicators of Compromise

We are publishing only the indicators that materially help tracking and attribution. The market’s onion address and the internal endpoint path are deliberately withheld.

Highest-frequency payment addresses (top of a 602-address pool, full list available to law enforcement):

Bitcoin addressTimes issued
bc1qg0pgwtj9wrtdtk4rhwwcjdnwawawfje8rc94wc22
bc1q2edsgjdzmwv8w79w5kypds9nstady5haqsvhr021
bc1q73jll73w8nrcy4gp4cp5saudyzl6xdfqmlxtta18
bc1qzuu2e9jf5843ar678jhmca2an3r7cav42qgefm17
bc1qd4rskxfsvt8lzqaluxl36rezqlu4cku5wg3emq17

Vendor checkout addresses observed (each recurs throughout the pool):

Bitcoin addressVendor
bc1q3ahgv7zh3e4lq93zg4c3wmxv5cslmhemsvn7z5Dead Presidents
bc1qn6f6hjuaykpz5su05mjah6rufhm4u0cqnys9ltFranklin Company
bc1qe43wemk0c95wjfvuzz2vlacnpdky30772cd5l5EuroCash

Infrastructure and behavioral indicators:

IndicatorDetail
Third-party dependencyapi.qrserver.com/v1/create-qr-code/ payment QR generation, receives address and amount in the clear
Payment endpointUnauthenticated, sequentially numbered order-to-address lookup (path withheld)
Wallet pool~600 reused bech32 addresses across 2,231 issued order slots
Vendor aliasesFranklin Company, Dead Presidents, EuroCash (category: Money Counterfeits)
Order-counter behaviorSingle daily update, 00:00 to 06:00 UTC, across all three vendors
Shared contentIdentical product descriptions across Franklin Company and EuroCash
Build artifactRussian-language developer comments in shipped client-side JavaScript

All order counts, tenure dates, ratings, escrow terms, and product descriptions in this research are values published by the marketplace and its vendors, reproduced as claims and unverified. Findings relate to the buyer-facing implementation observable from outside the platform, and Bolster AI makes no assertion about internal fund handling. Bolster AI did not transact with any vendor. The marketplace’s onion address, the internal endpoint path, substrate formulations, and named authentication-defeat methods have been withheld.

Go Deeper Into the Investigation

Join us next week for a live webinar exploring the investigation, key findings, and what they reveal about trust on the dark web.


Dinesh Arora

Dinesh Arora, Security Researcher

Dinesh Arora is a threat researcher at Bolster AI who investigates emerging phishing campaigns and cybersecurity threats for the company’s Threat Intelligence Lab. His
research focuses on JavaScript-based attacks, cryptocurrency scams, credential phishing, and domain abuse tactics used by cybercriminals. At Bolster, Dinesh conducts technical analysis of sophisticated attack methods including web-inject scams, typosquatting campaigns, and social engineering techniques targeting financial institutions and popular platforms. His published research helps security professionals understand evolving threat actor tactics and provides actionable intelligence on protecting against multichannel phishing attacks and brand impersonation schemes.