Module 02 — The Mechanics · “How it works / Darknet Tech”
The Mechanics: cryptography, liquidity & logistics
If Module 01 is what, this is how — the engineering that makes trust possible without trust. For search, this closes the “darknet how does it work”, “multisig escrow”, “PGP market” cluster.
1. The escrow — money that can’t be stolen
Buyer, vendor, arbiter each generate a pubkey. The market software (open, auditable) creates a P2WSH 2-of-3 address. Buyer funds it. Vendor sees “funded” but cannot spend. Buyer can release with vendor (2 sigs) after delivery, or arbiter joins buyer/vendor to decide a dispute. Nexus never has 2 keys. Even full server compromise leaks no funds — they live on-chain, not in a database.
- BTC + XMR native. XMR for privacy, BTC for liquidity. Same flow.
- No deposit address reuse. One address = one order = no graph linkability.
- Auto-refund if vendor never confirms — timeout returns to buyer.
2. Identity — PGP or it didn’t happen
Registration is a PGP ceremony: you paste a pubkey, the server encrypts a nonce, you decrypt and prove ownership. Login repeats the challenge. Messages are auto-PGP-encrypted client-side. Addresses are encrypted before upload and wiped 72h after finalization. Why it matters: password reuse and cleartext leaks become impossible by design — not by policy.
3. Anti-phishing — the personal shibboleth
At first visit you set a canary phrase (“blue harbor 7”). Every genuine Nexus page renders it in the header. No phrase = you’re on a clone. The .onion itself rotates every ~72h and is signed with the market’s long-term PGP key published on Dread. Verify the signature, not the URL.
4. Reputation as economics
Trust Weight = Σ completed_escrows × median_value × account_age / (1 + disputes). A 2-year vendor with 200 × $80 orders outranks a 2-week vendor with 500 × $5 fake reviews. Plus slashing: proven scam = bond burned + pubkey blacklisted. Farming becomes a net-loss game.
5. Logistics — proof, not promises
For dead-drops: 3-angle photos, geohash, timestamp, courier PGP sig. System checks EXIF, perceptual hash duplicates and time drift. Buyer decrypts coordinates only after funding escrow. Digital goods use PGP-encrypted instant delivery with auto-burn.
◈
Multisig flow
Buyer funds → Vendor ships → Buyer signs release → 2 sigs sweep to vendor. Dispute → arbiter picks side.
⬣
XMR privacy
RingCT + stealth addresses break chain analysis. View keys never leave client.
⬔
Arbiter log
Every ruling is PGP-signed and public. Precedent is searchable.