WeTheNorth Market Registration Guide
Complete walkthrough for creating your WeTheNorth Market account with maximum security. Follow these steps carefully to protect your anonymity and funds.
â Prerequisites - Complete These First
Before registering on WeTheNorth Market, ensure you have:
đ Tor Browser Configured
Downloaded from torproject.org, security level set to "Safest", JavaScript disabled. Never use regular browsers for .onion sites.
đ VPN Active
VPN connected before launching Tor (Mullvad/IVPN/ProtonVPN recommended). Kill switch enabled to prevent leaks.
đ PGP Keys Generated
Public/private key pair created with 4096-bit RSA. Public key exported and ready to paste. Private key backed up securely.
đ Password Manager Ready
KeePassXC or similar password manager installed. Prepared to generate strong, unique password (20+ characters recommended).
đ Step 1: Access WeTheNorth Market Safely
- Verify Official Mirror Link:
- Visit https://www.wethenorth-darknet.wiki/mirrors for PGP-verified .onion links
- Cross-reference links on Dread forum (/d/WeTheNorth)
- NEVER trust links from search engines, Reddit, or random forums
- Copy .onion Address: Copy primary mirror link (e.g., wethenorthmarket1abc.onion)
- Paste into Tor Browser: Open Tor Browser, paste link into address bar
- Verify You're on Real Site:
- Check URL matches exactly (one character difference = phishing)
- Look for professional design (phishing sites are often poorly made)
- Real WeTheNorth has Canadian theme (maple leaf branding)
- Bookmark Verified Link: Once confirmed legitimate, bookmark in Tor Browser (never search again)
đ Step 2: Create Your Account
- Click "Register" or "Sign Up": Usually in top-right corner of homepage
- Choose Username:
- Use pseudonym (NEVER real name or existing online handles)
- Avoid patterns: Don't use same username as clearnet accounts
- Example: "MapleUser2025", "CanadianBuyer47" (generic, untraceable)
- Username is public - vendors see it, so choose wisely
- Generate Strong Password:
- Use password manager to generate random 20+ character password
- Mix uppercase, lowercase, numbers, symbols
- Example:
K7$mP9#qL2@nX4!wR6^tY8* - NEVER reuse passwords from other sites
- Save password in password manager immediately
- Security PIN (if required):
- Some markets require 6-digit PIN for withdrawals
- Generate random PIN (don't use birthday, phone number)
- Store in password manager alongside password
- Login Phrase / Mnemonic Code:
- WeTheNorth generates random mnemonic phrase (e.g., "purple elephant dancing")
- CRITICAL: Write this down immediately
- This phrase appears on real WeTheNorth login page (phishing sites can't show it)
- Used to verify you're on legitimate site every login
- Store in password manager AND write on paper (offline backup)
- Complete CAPTCHA: Solve anti-bot challenge (usually simple text/image CAPTCHA)
- Click "Register" or "Create Account"
đ Step 3: Configure Security Features (CRITICAL)
Immediately after registration, configure these security features:
A) Add PGP Public Key
- Navigate to Settings â Security or Profile â PGP Key
- Copy your entire PGP public key (from Kleopatra/GPG Keychain):
-----BEGIN PGP PUBLIC KEY BLOCK----- (your key here) -----END PGP PUBLIC KEY BLOCK-----
- Paste into PGP Public Key field
- Click "Verify" or "Save"
- Marketplace may send encrypted test message - decrypt it to verify key works
B) Enable 2FA (Two-Factor Authentication)
- Navigate to Settings â Security â 2FA / Two-Factor Authentication
- Choose 2FA Method:
- PGP 2FA (RECOMMENDED): Market encrypts 2FA code with your PGP key. You decrypt it on login. Most secure, requires PGP.
- TOTP (Time-Based OTP): Use authenticator app (Aegis, andOTP on mobile; KeePassXC on desktop). Generates 6-digit codes.
- For PGP 2FA: Enable it, marketplace will send encrypted code on each login
- For TOTP 2FA:
- Scan QR code with authenticator app (or manually enter secret key)
- Enter 6-digit code from app to confirm setup
- BACKUP SECRET KEY: Store secret key in password manager (allows recovery if phone lost)
- Save Backup Codes: Marketplace provides 5-10 backup codes for account recovery
- Copy ALL backup codes to password manager
- Write on paper and store securely (offline backup)
- If you lose 2FA access, these codes are ONLY way to recover account
C) Set Anti-Phishing Image
- Navigate to Settings â Security â Anti-Phishing Image
- Choose unique image from marketplace gallery (or upload custom image if allowed)
- Select distinctive image you'll remember (not generic)
- How It Works:
- Your chosen image displays on login page BEFORE you enter password
- If image is missing or wrong = phishing site (DO NOT LOGIN)
- Phishing sites can't show your image because they don't know which you chose
D) Withdrawal PIN (if not set during registration)
- Settings â Security â Withdrawal PIN
- Create 6-digit PIN for withdrawing funds (different from login password)
- Store in password manager
- Required every time you withdraw XMR from marketplace to external wallet
â Step 4: Test Your Security Setup
Before making first order, verify everything works:
1ī¸âŖ Test PGP Encryption
- Navigate to a vendor profile
- Copy vendor's PGP public key
- Encrypt test message: "This is a test"
- If encryption works, your PGP setup is correct
2ī¸âŖ Test 2FA Login
- Logout of marketplace
- Login again with username + password
- Enter 2FA code (from PGP decrypt or TOTP app)
- Verify login succeeds
3ī¸âŖ Verify Anti-Phishing Image
- Logout and return to login page
- Confirm your chosen image displays
- Memorize this image (check it EVERY login)
4ī¸âŖ Check Mnemonic Code
- On login page, verify your mnemonic phrase appears
- Should match phrase you wrote down during registration
- If different phrase = phishing site
âī¸ Recommended Account Settings
Optimize these settings for security and privacy:
Privacy Settings:
- Hide Online Status: Enable if available (prevents tracking of login patterns)
- Disable Order History Logging: Some markets allow this - reduces forensic evidence
- Auto-Logout Timer: Set to 15-30 minutes of inactivity (protects if you walk away from computer)
Notification Settings:
- Disable Email Notifications: If marketplace allows email, disable it (no email = no email leaks)
- Enable On-Site Notifications: For vendor messages, order updates (check while logged in)
Display Settings:
- Currency Display: Set to preferred currency (USD, CAD, EUR) for price display
- Timezone: Set to your timezone or UTC (for easier tracking of order timestamps)
â Post-Registration Security Checklist
Verify you've completed all critical security steps:
- â Account created with strong, unique password (20+ characters)
- â Password saved in password manager
- â Mnemonic phrase written down and stored securely
- â PGP public key added to account settings
- â PGP encryption tested (can encrypt/decrypt messages)
- â 2FA enabled (PGP 2FA or TOTP)
- â 2FA backup codes saved (password manager + paper backup)
- â Anti-phishing image set and memorized
- â Withdrawal PIN created and saved
- â Login tested successfully with 2FA
- â Mnemonic code verified on login page
- â .onion link bookmarked in Tor Browser
đ§ Common Registration Issues
â "Username Already Taken"
Solution: Try different username. Add numbers/underscores (e.g., CanadianBuyer_2025).
â CAPTCHA Keeps Failing
Cause: Tor Browser security settings may interfere.
Solution: Try different Tor circuit (New Identity), or temporarily lower security level to "Safer" (change back to Safest after registration).
â "Invalid PGP Key"
Cause: Key format incorrect or incomplete.
Solution: Ensure entire key is copied (including BEGIN/END lines). Try exporting again from Kleopatra.
â Registration Page Not Loading
Cause: Mirror might be down, or circuit issue.
Solution: Try different mirror link from /mirrors page. Request new Tor circuit (New Identity).
Continue Your Journey
Registration complete! Now learn how to acquire Monero and understand the escrow system.