Operational Security (OPSEC) Checklist for Darknet Users
Operational security is the practice of protecting your identity and activities through careful compartmentalization and consistent habits. This checklist covers the essential OPSEC measures every darknet user should implement.
Identity Protection
- Use unique usernames for each market and service
- Never reuse usernames from clearnet accounts
- Avoid sharing personal information in profile or messages
- Use a dedicated email address (Proton Mail or similar) for darknet activities
- Never link your darknet identity to social media accounts
Device Security
- Keep your operating system updated
- Use full-disk encryption (BitLocker, FileVault, LUKS)
- Install and maintain antivirus software
- Use a dedicated device or virtual machine for darknet activities
- Consider Tails OS or Whonix for high-security needs
Communication Security
- Use PGP encryption for all sensitive messages
- Verify PGP fingerprints through independent channels
- Use Signal or Matrix for real-time encrypted chat
- Never discuss operational details on unencrypted channels
Financial OPSEC
- Use Monero instead of Bitcoin when possible
- Never deposit from KYC exchanges directly to market wallets
- Use intermediate wallets for all cryptocurrency transfers
- Keep minimal balances on market wallets
- Use hardware wallets for long-term storage
Incident Response
- Have a plan if your identity is compromised
- Know how to generate new PGP keys quickly
- Maintain offline backups of critical keys
- Document trusted addresses and keys in an encrypted journal
For the foundational security rules, see our Security page. For wallet-specific security, read our Crypto Wallet Guide.