WTN Claim Register What people say about We The North, checked one claim at a time
Register › When it goes wrong

We The North addresses

Three published addresses for the same platform. Copy rather than retype, and verify the signature once you are through.

Address 1 hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion
Address 2 hn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onion
Address 3 hn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onion

This site publishes the list and does not monitor it. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

Support can restore my account

The claimSupport can restore my account if I lose access
Partly true Sometimes, with what you saved at setup. Never through anything outside the platform.

The part that is true

Recovery processes exist and they work when you hold the material you were given at setup. That is the entire condition. With it, the process is routine. Without it, recovery is limited and frequently not possible, because the alternative would be a mechanism for taking over accounts you do not own.

The conditionThis is why the recovery material matters more than the password. Save it at setup, before closing the page, somewhere separate from the password.

The dangerous half

There is no support email, no chat group, no messaging account and no forum representative. Every one of those that exists is impersonation, and they exist in quantity because a person locked out is the most receptive audience there is.

Somebody who has just lost access is anxious, motivated, and looking specifically for a channel that does not exist. That combination is why lockout impersonation is one of the most reliable attacks in this space, and why the answer is categorical rather than a judgement about which contact looks legitimate.

Before assuming the worst

Most lockouts are boring. Work through these in order, because the first one changes what you should do next.

  1. Verify you are on a real address. A login that refuses correct credentials is what a clone looks like after taking them. Check before retrying, not after.
  2. Try another address. Sessions are shared, so failing at one and working at another points at that address.
  3. Build a new circuit. A dying circuit produces failures that read exactly like rejection, including codes appearing wrong.
  4. Check your clock. Time based codes fail on a drifted machine, which accounts for a surprising share of these.
  5. Check the username character by character. People change a character and then debug the password field for an hour.
  6. Wait an hour. Repeated attempts trigger rate limiting, which looks identical to refusal.

If it was compromised

Work in this order, because it puts what an attacker can act through ahead of what you are most worried about. Password first, from an address you verified yourself. Then reset the second factor. Then read the message log, because a stolen account is most valuable as a way to talk to people who trust it. Then open orders. The balance last, which is counterintuitive and correct.