The 2025 darknet market ecosystem closed with significant structural shifts compared to the prior year. Open-source monitoring aggregators provide the data basis for this review — all figures are estimates with inherent uncertainty and should be treated as directional indicators rather than precise measurements.
Market Landscape
The number of active darknet markets at year-end 2025 was estimated at 14 — down from 19 at the start of the year. Three exits were law enforcement actions, two were exit scams, and one was a voluntary administrator closure with orderly fund withdrawal. Net new entries partially offset exits, with Nexus Darknet and several smaller markets entering in H2 2025.
Nexus ended 2025 ranked in the top five active markets by estimated active listing count and vendor base size, despite launching only in July. This rapid growth reflects the market's successful capture of the migration wave following H2 2025 exit events.
Transaction Volume Trends
Full-year 2025 darknet market transaction volume, estimated from blockchain analytics and forum data, showed a 7% decline from 2024 on a USD-equivalent basis. However, XMR-denominated volume increased significantly as a proportion of total activity — estimated at 58% of all transactions by year-end compared to 41% at the start of 2025. This structural shift toward privacy currency continues a multi-year trend driven by chain analysis effectiveness against Bitcoin.
Exit Scams
Two documented exit scams in 2025 resulted in combined estimated user losses exceeding the prior year's exit scam total. The increasing loss amounts reflect growing market concentrations — as individual platforms grow larger before exiting, the potential scam yield grows proportionally. Multi-signature escrow adoption across the ecosystem is the most effective structural defense against exit scam losses.
DDoS Activity
DDoS attacks against darknet markets reached a five-year high in 2025 as measured by attack frequency. Average attack duration increased, suggesting more sophisticated and persistent threat actors. Markets with multi-mirror architectures experienced significantly better availability during peak attack periods than single-address platforms.