The Ledger

Everything the market says, decoded and dated. Onion addresses are never guesses. Independent — no affiliation, no accounts, no affiliate links.

Verified master onion:  http://drughuberjxfrxtlk2cystdz4jvogmc3lsnk5drvwx2nfi63ou2r2kid.onion/
Front page / The wire

The wire — complete announcement archive

Every entry below is a decode of a PGP-signed staff announcement or the published market JSON. Tag means: red threat, amber operational, green vendor-facing, teal product, gray policy. The eight most recent also headline the front page.

2026-10-05mirror health

Mirror health dashboard now visible after login

Logged-in users see current public mirror latency, latest PoW difficulty and queue estimates before hitting a mirror.

2026-10-03buyer protection

High-value orders get a 12-hour review window

Orders above 0.8 XMR offer an optional 2-of-3 style review window for the first 12 hours after an order is marked shipped.

2026-10-01fees

Withdrawal network-fee policy updated

The market keeps covering standard Monero network fees for withdrawals under 0.05 XMR; larger ones show a disclosed deduction at request time.

2026-09-29impersonators

Fake “DrugHub support” accounts on Session

Impersonators DM users claiming to be support or mirror admins. Staff never initiate contact on Session, Telegram or Dread.

2026-09-27tools

Encryption helper 1.4 released (Go + Python)

Transparent E2EE reverse-proxy tools updated: better Tails 6.x support, faster key import, loud failure modes. Signed releases in the market files section.

2026-09-24phishing

Phishing wave — verify your sign-in message every login

A significant increase in cloned login pages. After decrypting the PGP challenge, your personal sign-in message must appear in the top navigation bar.

2026-09-21mirrors

Private mirror capacity expanded

New private nodes. Buyers with 8+ completed orders in 60 days, clean history and an active PGP key can request one via automated support.

2026-09-11e2ee

Mandatory E2EE for addresses and tracking — enforcement live

Postal addresses, tracking numbers and PII must be PGP-encrypted before sending. Plaintext tracking costs vendors the listing; plaintext addresses risk cancellation.

2026-09-18vendor policy

Applications: bond unchanged, volume extreme

Post-collapse application volume is extreme. Bond required in most cases; waivers only with independently verifiable PGP vending history. FE is strictly staff discretion.

2026-09-16support

Automated knowledge base updated

New articles: partial XMR payments, multi-vendor cart edge cases, AF-timer extensions, delivered-not-finalized disputes. 99.5%+ still resolve without staff.

2026-09-13ddos

Sustained DDoS — PoW difficulty raised

Public endpoints under heavy attack 48 hours; PoW temporarily harder. Private mirrors completely unaffected — by design.

2026-09-08opsec

Quarterly purge: ~4,800 accounts removed

The 6-month inactivity purge ran on schedule. Deliberate OpSec, not data retention. No recovery path.

2026-09-05withdrawals

Batches now settle in ~18 hours

Average vendor withdrawal settlement improved to ~18 h under normal load. Offline batches remain; no hot wallets exist on web-facing servers.

2026-09-03tools

Vendor bulk-edit & keyword assistance

Good-standing vendors get bulk quick-edit, suggested keywords and better photo replacement. Abuse revokes the tools.

2026-08-31bans

CIS / Russian Federation prohibition — reminder

Selling to, from or about RF/CIS remains strictly prohibited. Violation: permanent ban, no appeal, forfeiture of pending balances.

2026-08-29impersonators

No support on external platforms — ever

Staff do not answer on Dread, Session, Telegram, Jabber or email. Official communication: inside the authenticated interface, or PGP-signed announcements.

2026-08-26scraping

Private-mirror scrapers terminated

Accounts aggressively scraping private mirrors detected and terminated. Session-linked, personal use only; sharing is an instant permanent ban.

Reading the wire like an analyst

Three patterns recur across the archive and explain almost every headline: attacks on public endpoints (friction rises, private mirrors stay untouched), phishing campaigns (the sign-in message is the tripwire — see the verification ritual), and steady hardening of the crypto-economic design (invoice-only checkout, offline withdrawal batches, mandatory E2EE, inactivity purges). None of the changes are cosmetic; each closes a specific abuse.

Verification rule for this archive: a post that cannot be matched to the staff key fragment above did not come from the market — regardless of which platform it was screenshotted on.