August 13, 2026
Updated: August 13, 2026
Torch is the oldest onion search engine, but its billion-page claim collapses against Tor Metrics. What it indexes, what it misses, and where it fits.
Abdalla Mohamed

The Torch search engine is the oldest keyword search engine running on the Tor network, and it does one thing that no clearnet engine does: it crawls .onion services and makes them findable by keyword. It applies no moderation, keeps no query logs, and verifies nothing it lists. That combination makes it genuinely useful for research and genuinely risky for casual browsing. This guide covers what Torch indexes, what it quietly misses, and where it belongs in a security team's workflow.
Torch, sometimes styled TORCH or TorSearch, is a search engine that indexes Tor onion services and returns them for keyword queries. It runs as an onion service itself, which means it is reachable only through Tor Browser and not through Chrome, Safari, or Firefox on the normal internet. Functionally it behaves like a stripped-down Google for the dark web: you type a term, you get a list of .onion results with short snippets.
It has been operating since roughly the early 2010s, which makes it one of the longest-running services of its kind. That longevity is the single most useful thing about it. Onion services churn constantly, and an engine that has been crawling for over a decade accumulates routes to content that newer crawlers never saw, including mirrors and defunct sites that still carry investigative value.

The reason a separate engine has to exist at all comes down to how onion services are addressed and routed. Understanding this is what separates a useful mental model from the usual dark web hand-waving, and it explains the limits of Torch's index better than any feature list.
Google finds pages by following links from pages it already knows. Onion services largely break that chain. An .onion address is a cryptographic identifier derived from the service's public key, not a human-chosen name registered in DNS, so there is no registrar list to enumerate and no zone file to walk. Most onion services are never linked from any clearnet page. If nobody publishes the address somewhere a crawler can see it, the service is effectively invisible, no matter how long it has been online. This is the same structural distinction that separates the deep web from the dark web, and it is why a dedicated crawler is necessary rather than merely convenient.
Traffic to an onion service never leaves the Tor network. There is no exit node in the path. Instead, the client and the server meet at a rendezvous point inside the network, which is precisely how onion services work and why the server's physical location stays hidden. For a crawler this means there is no network vantage point from which you can observe onion traffic and harvest addresses in bulk. Torch has to be told where to look, the same as everyone else, by finding addresses published on pages it has already indexed.
In practice Torch grows its index the way any crawler does: it starts from a seed list, fetches those pages, extracts every .onion link it finds, and queues them. Directories, forums, and link lists are therefore the backbone of its coverage. The consequence is a systematic bias. Well-linked services with an interest in being found get indexed thoroughly. Services that deliberately avoid publicity, which includes most of what an investigator would actually want to see, stay outside the index entirely.

Almost every page that ranks for this term repeats the same statistic: Torch indexes over a billion pages. A few sources say one million instead, and nobody appears to notice the thousand-fold discrepancy or ask where either number came from. Both figures trace back to Torch's own marketing copy, and neither has been independently verified.
Run it against the size of the network. The Tor Project publishes onion service statistics derived from relays acting as hidden service directories, and the count of unique v3 onion addresses visible on a typical day sits in the hundreds of thousands. The older v2 addresses were retired in 2021, so v3 is the whole picture. Not billions. The Tor Project has published its own analysis of onion service scale and has consistently found the ecosystem smaller than popular estimates assume. That is the entire addressable universe of onion services, indexed and unindexed, active and abandoned, and it includes every duplicate mirror and every short-lived test service.
A billion indexed pages against a few hundred thousand services would mean thousands of distinct pages per service on average, across a network where a large share of addresses are single-page landers, dead, or mostly inactive. The number is not impossible if you count aggressively at the page level and never expire dead results, but it is not the measure of coverage that readers assume it is. Treat it as a claim about crawl volume, not about how much of the dark web you can actually see.
This matters practically rather than pedantically. If you brief an executive that a free search engine covers a billion dark web pages, you have implied a completeness that does not exist, and the next question, "so are we in there or not," gets an answer that sounds far more authoritative than the evidence supports. It belongs alongside the other dark web myths that survive because they are repeated rather than checked.
The gap between what people assume Torch provides and what it actually provides causes more bad conclusions than any technical limitation. Four things are worth stating plainly.
Torch is one of several engines, and the differences between them are about editorial policy far more than technology. The practical split is between engines that filter and engines that do not.
Ahmia is the main alternative and takes the opposite position: it actively excludes abuse material and has been associated with the Tor Project since 2014, which gives it a legitimacy the unfiltered engines cannot claim. That makes Ahmia the sensible default for anyone who needs to demonstrate to a compliance function that their research was conducted responsibly. Torch's appeal is the mirror image, since an unfiltered index surfaces emerging infrastructure, scam clusters, and mirror networks that a moderated engine deliberately removes.
The others fill narrower roles. DuckDuckGo's onion service searches the clearnet privately rather than indexing .onion sites, which is a distinction people routinely get wrong. Haystak sells access to a larger index behind a paid tier. OnionLand and the various not Evil clones sit closer to Torch in policy and well behind it in reliability. We cover the full field in our breakdown of dark web search engines compared.
| Engine | Indexes | Moderation | Best used for |
|---|---|---|---|
| Torch | .onion services | None | Unfiltered discovery, mapping mirror and scam infrastructure |
| Ahmia | .onion services | Excludes abuse material | Documented professional research with a defensible audit trail |
| Haystak | .onion services | Limited | Broader historical coverage, with the useful depth behind a paid tier |
| DuckDuckGo onion | Clearnet only | Standard | Private clearnet search, not dark web discovery |
| OnionLand / not Evil | .onion services | None | Cross-checking a Torch result against a second unfiltered index |
Two habits are worth building. Run any significant query through both a filtered and an unfiltered engine, because the difference between the two result sets is itself informative and often tells you more than either list alone. And record which engine produced which result, since six months later the provenance of a finding matters considerably more than the finding did at the time.
The honest summary is that no onion search engine is comprehensive, and running two with opposite filtering policies tells you more than running either alone.
These get asked together and deserve separate answers, because one is simple and one is not.
Torch is a search engine. Using it is not a crime in the United States, the United Kingdom, or the EU, in the same way that using Dark Web Browser is not a crime. What you do with the results determines legality. Accessing, downloading, or transacting with illegal content and services is illegal whether you arrived there through Torch, a link list, or a direct address, and the anonymity of the network does not change the law or, increasingly, the practical odds. Investigators have well-developed methods for attributing dark web activity, which we cover in how law enforcement tracks dark web criminals.
If you are doing this as part of a job, the constraint that binds first is usually organizational rather than legal. Most enterprises require dark web research to run from an isolated environment under a documented authorization, and doing it from a corporate laptop on a whim is a policy violation long before it is anything else.
Unfiltered results mean you can land on genuinely harmful content with no warning from a single ambiguous query. That is the obvious risk. The less obvious and more common one is that Torch itself is heavily impersonated. Its address has rotated multiple times over the years, and phishing clones that reproduce the interface exactly are widespread. Those clones exist to harvest credentials, serve malware, and redirect users to services that pay for traffic. A researcher who arrives at a convincing fake and trusts its results is being fed a curated view by whoever runs it.
Torch also keeps no logs and runs no analytics, which is a genuine privacy property and not a security one. No logging protects you from Torch. It does nothing about a malicious mirror, a compromised endpoint, or a service that fingerprints your browser configuration. If you want the fuller picture of what the network does and does not protect, see how anonymous the dark web really is.
A significant share of people searching for Torch want the address, so it is worth explaining the omission rather than leaving it conspicuous.
The address has changed repeatedly, and convincing phishing clones are common. An address published in an evergreen guide keeps getting served to readers long after it rotates, and at that point the page is no longer providing a reference. It is providing a link to whoever now occupies that string. Every guide that hardcodes an onion address is one rotation away from routing its readers somewhere hostile, and most of them will never notice.
There is a second reason worth being direct about. We test systems for a living, and publishing a live entry point to an unmoderated index does nothing for that work while creating real brand and search-quality exposure. Anyone who needs the current address can obtain it from Ahmia or the Tor Project community resources, where it is maintained rather than frozen.
This is the part almost nobody writes about, because most content on Torch is aimed at curious readers rather than practitioners. Used deliberately, Torch has a narrow but real role.
Torch's lack of moderation is an advantage when you are trying to see structure rather than find a specific document. Scam clusters, mirror networks, and rapidly replicated phishing infrastructure often surface in an unfiltered index before curated sources catch up, because curation lags by design. If you are mapping how a particular brand is being impersonated across onion services, a raw index shows you the shape of the thing. Treat every result as a lead requiring independent confirmation, never as a finding.
After a breach or a credential dump, teams frequently want to know whether their data has surfaced. Torch can occasionally confirm that something is publicly discoverable, and a positive result is meaningful. A negative result is close to worthless, because the absence of a hit tells you only that the term is not in this particular index today. Data that has been sold privately, posted to a vetted forum, or listed on a site that Torch never crawled produces exactly the same empty page as data that was never stolen. For context on what surfaces and what it goes for, our analysis of what stolen data actually sells for is a better starting point than a search box.
There is a straightforward educational case. Analysts who have looked at how leak sites are structured, how listings are worded, and how quickly infrastructure moves make better decisions than analysts working from headlines. Set against the scale of activity documented in our review of daily dark web activity, an afternoon of supervised exploration in an isolated environment is reasonable professional development. It is not a monitoring program.

The structural problem with using Torch as a monitoring approach is that it is a pull model against a target that changes constantly. You have to remember to look, know what to look for, and be looking on the day the data appears. Listings get taken down, forums rotate addresses, and the window between something appearing and disappearing is frequently shorter than the interval between manual checks.
The index bias compounds it. Torch covers what is well linked, and the material that matters most to a defender, meaning credential dumps traded privately and pre-publication ransomware listings, is systematically the least linked. You are searching hardest in the region where coverage is weakest, and the search returns nothing, and nothing feels like reassurance.
This is the case for tooling rather than habit. Continuous collection across multiple sources, including sources no public engine indexes, is what dark web monitoring tools exist to do. Torch is a useful instrument for a specific investigative question. It is not a control, and it should never appear in a risk register as one.
Torch is a search engine that crawls and indexes Tor onion services, making .onion sites findable by keyword. It runs as an onion service itself and requires Tor Browser to reach. It applies no content filtering and keeps no query logs.
Yes. Torch is a search engine, and using one is legal in the United States, the United Kingdom, and the EU. Legality depends entirely on what you do with the results. Accessing or transacting with illegal content and services remains illegal regardless of how you found it.
Not for casual use. Results are unfiltered, so harmful content can appear without warning, and phishing clones of Torch are widespread. Security researchers who use it work from isolated environments under documented authorization rather than from everyday machines.
Torch continues to operate, though its onion address has changed several times over the years. Because those rotations are frequent and impersonation is common, obtain the current address from a maintained source such as Ahmia rather than from a static guide.
Ahmia filters abuse material and has been associated with the Tor Project since 2014. Torch applies no moderation. Ahmia is the safer default for documented professional research; Torch surfaces unfiltered infrastructure that moderated engines deliberately exclude.
Torch states that it keeps no query logs and runs no analytics. That protects you from Torch specifically. It offers no protection against a phishing clone, a compromised endpoint, or a service that fingerprints your browser.
Sometimes, and a positive result is meaningful. A negative result is not. Torch only covers publicly linked services, while most stolen data is traded privately or posted to forums it never crawls, so an empty search says very little about your actual exposure.
Onion addresses rotate for operational and security reasons, and services move when infrastructure is seized or compromised. This churn is why hardcoded addresses in guides go stale and why clones are so effective at capturing traffic from outdated links.
Torch is worth understanding and worth using occasionally, with a clear head about what it is: an unmoderated, unverified, structurally incomplete index of the publicly linked portion of the Tor network. It answers "is this discoverable" and it does not answer "are we exposed." The billion-page figure is marketing, not measurement, and the coverage gap it obscures falls exactly where a defender's interest lies.
Most organizations discover their real exposure well before anything reaches an onion index, in an unpatched service, a reused credential, or an access path nobody mapped. That is the work our team does. If you want to know what an attacker would find in your environment before it turns into a listing someone else searches for, our US penetration testing services start with a manual assessment by testers who operate the way real threat actors do.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us