← Back to list

Dark Web Investigation 04 : How Public PGP Keys Break Dark Web Anonymity

PGP stands for Pretty Good Privacy. It is a tool used to keep messages private and secure, and it’s very common on the dark web. People on…

abcdx65zxssa · 2025-07-19 07:56 · 30 claps · 4.3 min read
#darkweb #osint #investigation #pgpencryption #cybercrime
Open on Medium ↗
Wiki topics: AGT · AI Agents 🔒 · Cybersecurity

Dark Web Investigation 04 : How Public PGP Keys Break Dark Web Anonymity

PGP stands for Pretty Good Privacy. It is a tool used to keep messages private and secure, and it’s very common on the dark web. People on the dark web like marketplace vendors, hackers, or criminals use PGP to talk safely without showing their real identity. They don’t trust normal emails or websites because those can be tracked or hacked. To use PGP, the user creates two keys: a public key and a private key.

Public key : is shared with everyone. You use it to send an encrypted message to someone.

Private key : is kept secret by the owner. Only this key can unlock and read the encrypted message.

This is How Public PGP key Look Like

This is How Public PGP key Look Like

On the dark web, vendors often post their public PGP key on their profile. If you want to message them, you use this key to encrypt your message. Once encrypted, only the vendor with the private key can read it.

Because the private key is never shared, no one else not even police or website owners can read the message.

What Information can We found from the PGP

Public PGP keys on onion sites are often placed in the Contact Us section or on a separate page like examplexyz1234azseefdss.onion/pgp . Many darknet marketplaces, forums, or hacking-related sites include their PGP key in these areas. Sometimes, the PGP key is also shown on a vendor’s profile.

In OSINT investigations, a public PGP key can be a useful piece of evidence. It often reveals important details such as the :

1. Username or alias, 2. email address, 3. status of the key (whether it’s still valid or expired), 4. the date it was created, and 5. the Key ID.

These details can help investigators connect the key to accounts on forums, marketplaces, or email services like Proton Mail or Tutanota. If the same key is used across multiple platforms, it can be used to link different profiles together. Overall, public PGP keys can help build a digital footprint of the person behind them.

An example of a PGP key found on a dark web marketplace which offers services like swapping various cryptocurrencies into stablecoins such as USDT or USDC. On this site, a public PGP key is provided for secure communication. Investigators or users can copy the entire block of the public PGP key and save it as a .asc file. This file can then be imported into Kleopatra.

Kleopatra helps you create, import, export, encrypt, decrypt, sign, and verify PGP keys and messages. It acts as a user-friendly interface for the more technical GnuPG (GPG) command-line tool, which is the engine behind most PGP operations.

After importing the .asc file into Kleopatra, it reveals useful metadata such as the key owner’s username, email address, key status, validity dates, and the Key ID, all of which are valuable for OSINT investigations.

the email domain is belongs to Tuta.io (Tutanota), this adds an additional layer to the investigation. Tutanota is an end-to-end encrypted email service known for its strong privacy standards and commitment to user anonymity. While Tutanota does not store IP addresses or include them in email headers by default.

it does cooperate with law enforcement ?

when presented with a valid court order. In such cases, Tutanota can be legally compelled to begin live logging of user data, such as login IP addresses, timestamps, and metadata though only going forward, not retroactively. Therefore, if a suspect is using a Tutanota email linked to a PGP key, legal avenues can still offer a path for tracking through court-sanctioned surveillance.

https://tuta.com/support/security#anonymous-email

https://tuta.com/support/security#anonymous-email

in Another Example the Onion Site contain the Fingerprint ID Rather than The Public PGP key in this Scenario we will use Public PGP key Server https://keys.openpgp.org/ and Paste the Fingerprint ID To get the Public PGP key

it will give oublic PGP key in .asc file which we will open in the kleopatra tool

it will give oublic PGP key in .asc file which we will open in the kleopatra tool

How PGP key helps US authorities to took down the owners of darknet drug emporium Wall Street Market

Investigators found that the PGP public key used by a user named ‘TheOne’ on a dark web marketplace called WSM was exactly the same as the one used by another user named ‘dudebuy’ on a different hidden site called Hansa Market. That means both accounts were likely controlled by the same person.

They called this key Public Key 1, and it helped them make further connections. Specifically, ‘dudebuy’ had a refund wallet (a Bitcoin wallet used for returns) called Wallet 2.

When they traced transactions involving Wallet 2, they found that money sent from it was part of a Bitcoin transaction. The company that processed that payment had buyer records that showed the person behind the transaction was someone named Martin Frost, using the email klaus-martin.frost@…

So by linking the PGP key from ‘TheOne’ to ‘dudebuy’ and ‘dudebuy’ to the wallet and that wallet to Martin Frost they were able to prove that TheOne = dudebuy = Martin Frost.

This is how a single public PGP key, often overlooked, can become a powerful asset for law enforcement agencies and investigators.

Thanks


메타데이터
post_id
cd3687e82fd2
slug
dark-web-investigation-04-how-public-pgp-keys-break-dark-web-anonymity-cd3687e82fd2
url
https://medium.com/@abcdxz/dark-web-investigation-04-how-public-pgp-keys-break-dark-web-anonymity-cd3687e82fd2
canonical_url
https://medium.com/@abcdxz/dark-web-investigation-04-how-public-pgp-keys-break-dark-web-anonymity-cd3687e82fd2
author_url
https://medium.com/@abcdxz
status
ok
fetched_at
2026-07-26 23:38:14