The Mariana web is a 2012 troll. We trace the hoax and map the real dark web using Tor Metrics data, academic studies, takedowns and defender guidance.
OSINT beginner guide 2026 — a legal, ethics-first methodology for open-source intelligence. From Andrax Pentester.
9 min read
Build a zero-dependency Python 3.11+ AST detection engine that transpiles Sigma rules into Microsoft KQL, Elastic EQL, and real-time in-memory event evaluators.
13 min read
Somewhere below the dark web, the story goes, there's a deeper layer. It's called the Mariana web, after the deepest trench in the ocean. You can't reach it with Tor. You need a quantum computer and something called a "polymeric falcighol derivation". Down there are the Vatican's secret archives, the location of Atlantis, and whatever else you'd expect a conspiracy theory to hold.
None of it exists. The Mariana web started as a joke drawn on an iceberg, grew through image boards and YouTube, and eventually found its way into security sales pitches. It's worth tracing properly, though, because the myth hangs on real questions: what is the "dark web", how big is it, who uses it, and how does anyone get caught on it?
This piece first traces the Mariana web forensically: where it came from, how it mutated, and why each of its technical claims fails. Then it swaps the myth for data: live Tor Metrics telemetry, peer-reviewed studies, official law-enforcement records, and a defender's view of what "dark web monitoring" should mean.
Key takeaways
- The Mariana web comes from an iceberg "infographic". The canonical copy, "Another Infographic of the Ocean", was uploaded to Imgur on 1 September 2012, according to media scholar Robert W. Gehl. It's a troll, and its deepest level ends on a slur-laden punchline.
- "Polymeric falcighol derivation" returns zero results in Crossref's index of scholarly works and in arXiv. It isn't a real algorithm.
- There are no "levels" below Tor, I2P or Hyphanet. They're overlay networks that run on top of the ordinary internet.
- As of 23 September 2026, Tor Metrics counts about 9,450 relays and about 648,000 unique v3 onion addresses. That's a tiny number next to the 401.6 million registered domain names Verisign counted in Q2 2026.
- Most dark-web operators who got caught were undone by ordinary mistakes: a personal Gmail address, a Hotmail address in a welcome email, a laptop seized while unlocked. Exotic cryptanalysis played no part.
The Mariana web borrows its imagery from a legitimate idea. In 2001, Michael K. Bergman published "The Deep Web: Surfacing Hidden Value" in the Journal of Electronic Publishing. He argued that search engines trawl only the surface of the web, while most content sits in databases that crawlers can't reach. His numbers were dramatic for the time: public information on the deep web was "400 to 550 times larger than the commonly defined World Wide Web", holding 7,500 terabytes against the surface web's 19 terabytes.
Bergman's deep web was dull in the best sense: searchable databases, dynamic pages, content behind query forms. But as Gehl notes, it set up the ocean as the metaphor for hidden information, with boats skimming the surface and submarines in the depths. Everything that followed made that metaphor spooky.
The iceberg format arrived first. Know Your Meme traces the earliest known iceberg parody of the internet to an Imgur upload dated 31 May 2011. Popular sites sat above the waterline and "deep web" content sat below. By 12 June 2012, a Redditor was posting a copy to r/4chan and asking what the "Hidden Wiki" on it was, so the images were clearly circulating on 4chan by then.
The Mariana web's own birth certificate is harder to pin down. Researcher Robert W. Gehl's chapter "On the Cultural Power of the 'Marianas Web' Meme" dates the canonical graphic, titled "Another Infographic of the Ocean...", to an Imgur upload on 1 September 2012. It laid out five levels:
The graphic also claimed that "80% of the Internet exists below this line", then quietly hedged that this meant "80% of the information that effects [sic] you directly". Circulating versions of the chart also attach a pseudo-technical entry requirement to the bottom tier, a "polymeric falcighol derivation", explained in a caption that's now quoted everywhere:
"…you need to solve quantum mechanics in order to view this on even the normal web, let alone closed servers. Quantum Computation exists, and the government powers have them. So be careful what you do here."
That line carries the whole mythology: some secret technology exists, the government has it, and you don't.
A forensic note: popular retellings say "it came from 4chan". The documentary record doesn't fully support that. The earliest dated copies sit on Imgur. One widely cited Skeptics Stack Exchange answer dropped its own 4chan attribution after it couldn't find supporting evidence. Some amateur trackers claim sightings as early as late 2011, but we couldn't verify a dated copy older than Gehl's September 2012 reference.
Hoaxes mutate as they spread. A later chart, "Levels of the Deep Web", was uploaded to Imgur on 10 January 2014, and the Internet Archive captured it four days later. Expanded versions stretched the iceberg to eight levels. Gehl reads the meme's staying power as an answer to "post-truth" anxiety: if the internet is layered and infinite, the truth must be down there somewhere.
Image boards gave the myth its start and YouTube made it big. A YouTube search for "marianas web" on 26 September 2026 surfaced these videos, among others:
| Upload date | Channel | Title | Views (26 Sep 2026) |
|---|---|---|---|
| 24 Jun 2015 | Takedownman | The Hidden Internet- Marianas web | 248,285 |
| 9 Jun 2018 | The Infographics Show | Marianas Web - The Scariest Part Of The Internet | 2,247,163 |
| 31 Jan 2022 | FING | UNSOLVED MYSTERY OF THE MARIANA WEB | 2,577,950 |
| 9 Nov 2024 | Alchemy Explainer | Every Level of Internet Explained in 7 Minutes | 1,624,664 |
| 15 May 2025 | Jaydone History | Every Layer of the Internet Explained | 2,463,343 |
Those five videos alone have about 9.2 million views. Several frame the Mariana web as unproven rather than fictional, and that hedge is how the myth survives. In October 2018, a Skeptics Stack Exchange question quoted The Infographics Show video saying "there is no concrete evidence that clearly proves or disproves its existence."
By 2025 the myth had crossed into fiction. The Marianas Web, a science-fiction horror film directed by Marco Calvise, was released in the Philippines on 15 October 2025.
A hoax that stays on image boards is harmless. This one escaped. In December 2015, Violet Blue wrote in Engadget that she had heard first-hand of infosec clients asking for threat-intelligence packages to include the Mariana web. She called the graphic "an epic troll that people have interpreted as fact." Gehl traces the same thinking into consumer "dark web scan" marketing that uses the iceberg model to sell fear.
That's the practical reason to debunk it. Buyers who believe in the Mariana web will pay for coverage of a place that doesn't exist.
Networks don't gate access by what kind of processor you own. To reach any service, whether on the clearnet, Tor, I2P or Hyphanet, you need three things: a route to it, the protocol it speaks, and any keys it requires. A quantum computer adds none of those.
The real relationship between quantum computing and the dark web runs the opposite way from the myth. Quantum computers are a potential threat to the public-key cryptography that anonymity networks rely on, not a key to hidden layers. Tor's v3 onion services use ed25519 and curve25519, both classical elliptic-curve schemes. That's why NIST finalised its first three post-quantum encryption standards in August 2024, "designed to withstand the attack of a quantum computer." If quantum computing touches the dark web at all, the likely effect is to weaken it.
On 26 September 2026 we queried the Crossref scholarly index and arXiv for "falcighol". Both returned zero results. The term appears in no paper, patent family or standard we could find. It lives only in meme text, Urban Dictionary-style entries and wikis that repeat them. RationalWiki files it under "quantum woo", and Gehl uses the same frame.
The internet has layers in the protocol sense: physical, link, IP, transport, application. It has no layers in the depth sense. Tor's own documentation describes onion services as "an overlay network on top of TCP/IP". I2P and Hyphanet are overlays too. Each one is a different set of rules for sending packets over the same cables. None of them sits "below" another, and nothing sits below all of them. As Gehl puts it after years of participant observation on dark-web social networks, there are "no layers 'deeper' than Tor (or Freenet, or I2P)." "Closed Shell System" is not a term of art in networking or operating systems. It's decoration.
Private networks do exist (intranets, air-gapped and classified systems), but they're separate from the internet, not deeper, and you get in with authorisation, not a secret algorithm.
The 80% figure is a garbled echo of Bergman's deep-web estimate, which was about databases and dynamic pages. It was never about hidden criminal layers. The actual dark web is small. As of 23 September 2026, Tor Metrics estimated about 648,000 unique v3 onion addresses. Verisign counted 401.6 million registered domain names at the end of Q2 2026. Even taken at face value, the onion address count is under 0.2% of that. It's also generous to the dark web, because many onion addresses aren't websites at all (more on that below).
| Claim | Reality |
|---|---|
| "The deep web and the dark web are the same thing." | They aren't. The deep web is anything search engines don't index: your inbox, online banking, paywalled journals, company intranets. You use it every day. The dark web is the small set of services reachable only through anonymity overlays such as Tor onion services, I2P or Hyphanet. |
| "The deep web is 90%+ of the internet, so it's mostly criminal." | The size claims refer to un-indexed databases and logged-in pages (Bergman, 2001). Nearly all of that is mundane and legal. |
| "The internet has 5 (or 8) levels." | There are no depth levels, only protocol layers and separate overlay networks running on the same infrastructure. |
| "Tor is the dark web." | Most Tor use is ordinary browsing of the regular web. The Tor Project's 2015 estimate put onion-service traffic at about 3.4% of client traffic (6.1% as seen at relays). |
| "Going to the dark web is illegal." | In most countries, using Tor is legal. What matters is what you do. Major broadcasters and platforms run onion sites for exactly that reason (see below). |
| "Nobody can be traced on the dark web." | Operators of the largest markets were identified through operational-security failures, infiltration and financial tracing. |
A Tor client routes traffic through three volunteer relays (guard, middle, exit), wrapped in one encryption layer per hop. Each relay peels off its layer and learns only its neighbours: the guard knows who you are but not where you're going, and the exit knows the destination but not the sender. No single relay sees both ends. That's the core property, and the core weakness: an adversary watching both ends can try to correlate them (see Part 7).
Onion services turn this around so the server is hidden too. Per the Tor Project's documentation and the v3 rendezvous specification:
.onion address is 56 characters long because it encodes the service's full ed25519 public key. When a client fetches the descriptor, it checks the signature against that key. Tor calls this end-to-end authentication: nobody else can impersonate the address.The older v2 protocol used an 80-bit truncated SHA-1 hash of a 1024-bit RSA key. In 2013, Biryukov and colleagues collected 39,824 hidden-service descriptors in a single day "by exploiting protocol and implementation flaws in Tor". v3 (first supported in Tor 0.3.2.9 on 9 January 2018, with v2 retired from October 2021 under the Tor Project's published timeline) closed that door:
In practice, a directory relay can no longer harvest a list of onion services. That's why every modern onion count is a privacy-preserving statistical estimate, not a census.
All figures below were retrieved from Tor Metrics' public CSV exports on 26 September 2026 (IST) and cover data through 23 September 2026.
| Metric | Latest (23 Sep 2026) | Context |
|---|---|---|
| Running relays | 9,448 | Annual median rose from 7,121 (2016) to 8,877 (2025) and about 9,800 so far in 2026 |
| Running bridges | 2,330 | Unlisted entry relays for censored users |
| Directly connecting users (estimate) | ~3.45 million | 30-day median about 3.2 million; annual medians mostly 1.8–2.4 million in 2015–2022 |
| Bridge users (estimate) | ~213,000 | 30-day median about 217,000, up from an annual median of about 128,000 in 2025 |
| Unique v3 onion addresses (estimate) | ~648,000 | Peaked at about 1.32 million on 10 Mar 2026; annual median about 861,000 in 2025 |
| v3 onion-service traffic at rendezvous points | ~15 Gbit/s | Annual median grew from 8.6 Gbit/s (2022) to 15.6 Gbit/s (2025) |
| Total relay bandwidth consumed / advertised | ~532 / ~1,260 Gbit/s | 30-day medians |
How to read these numbers honestly:
All three are parallel overlays. None of them unlocks a secret level.
Measurement studies differ in methods, dates and definitions, but their broad findings are consistent, and far less cinematic than the iceberg.
In short, onion services carry a disproportionate share of illicit activity compared with the open web, but the ecosystem is small, churning and heavily policed, and it hosts legitimate services too.
| Date (announced) | Operation / target | What the official record says |
|---|---|---|
| 1 Oct 2013 (arrest) | Silk Road | Ross Ulbricht was arrested in San Francisco. The SDNY says Silk Road served more than 100,000 buyers and displayed nearly 13,000 listings for controlled substances as of 23 Sep 2013. He was sentenced to life in May 2015, with $183,961,921 forfeiture, and received a full presidential pardon on 21 Jan 2025. |
| 20 Jul 2017 | AlphaBay (with Dutch action against Hansa) | DOJ called AlphaBay the largest criminal marketplace online. It cited a staff claim of more than 200,000 users and 40,000 vendors, and more than 250,000 drug and chemical listings. Administrator Alexandre Cazes was arrested in Thailand on 5 July and died in custody on 12 July. |
| June–July 2017 | Hansa (Operation Bayonet) | Dutch police covertly ran the market for 27 days after German arrests on 20 June, logging about 27,000 transactions. After AlphaBay went dark, registrations surged to more than 5,000 a day, eight times the normal rate, according to Dutch officers interviewed by WIRED. |
| 5 Apr 2022 | Hydra Market | Servers were seized in Germany by the BKA. DOJ says Hydra accounted for about 80% of all darknet-market cryptocurrency transactions in 2021 and received about $5.2 billion in crypto since 2015. |
| 5 Apr 2023 | Genesis Market (Operation Cookie Monster) | Sold access harvested from more than 1.5 million infected computers holding more than 80 million account credentials, plus browser fingerprints and cookies. Eleven domains were seized. |
| 20 Feb 2024 | LockBit (ransomware leak-site infrastructure) | More than 2,000 victims and more than $120 million in ransoms, per DOJ. Authorities seized public-facing sites and admin servers and obtained decryption keys. |
The Silk Road case is the classic. IRS Special Agent Gary Alford testified in January 2015 that in 2013 he searched for early mentions of Silk Road dated before its launch. He found a user called "altoid" promoting it on bitcointalk.org and shroomery.org. The same user later posted a job ad asking applicants to email rossulbricht at gmail dot com. No cryptography was broken. Someone joined the dots between a pseudonym and a real name.
AlphaBay repeated the pattern. According to the civil forfeiture complaint reported by Ars Technica, the site's early welcome emails carried pimp_alex_91@hotmail.com in their headers. Canadian authorities linked that address to Alexandre Cazes, born in 1991. When Thai police arrested him, his laptop was found open, unencrypted, and logged in as "Admin", with text files listing passwords for the site and its servers.
In the Hansa case, investigators took over the platform itself. The Dutch NHTCU told WIRED it altered the site's code to collect more identifying information and tricked dozens of vendors into opening a beacon file that revealed their locations. Of Genesis Market, DOJ said it "falsely promised a new age of anonymity and impunity."
Several of the official releases above credit financial tracing: DEA "followed the money" in Silk Road, and IRS-CI is credited in AlphaBay and Hydra. In the Hydra case, IRS Criminal Investigation said its Cyber Crimes Unit "once again used their cryptocurrency tracking expertise". Blockchains are public ledgers, and an exchange account with KYC details can connect a pseudonymous wallet to a real person.
The Tor Project openly acknowledges that an adversary who observes both ends of a circuit can try to correlate traffic. In 2013, Johnson et al. (ACM CCS) modelled realistic adversaries and found that "80% of all types of users may be deanonymized by a relatively moderate Tor-relay adversary within six months." In July 2014, the Tor Project disclosed that a group of relays had run a "relay early" traffic-confirmation attack from 30 January to 4 July 2014, and warned that anyone who operated or accessed onion services in that window should assume they were affected. Its advisory adds that "the general class of passive (statistical) traffic confirmation attacks remains unsolved."
The lesson isn't that "Tor is broken". It raises the cost of surveillance a great deal, but it isn't magic. The court records never mention quantum super-weapons. They're full of human error, seized servers and ledgers.
The same technology protects people doing nothing wrong, many of whom have a lot to lose.
Moore and Rid's observation is worth repeating: legitimate onion operators usually identify themselves. They use onion services for security and reach, not to avoid accountability.
Security teams have real reasons to watch these ecosystems: staff credentials in infostealer dumps, access brokers listing your VPN, leak sites naming your suppliers. Here's how to do it legally and usefully.
The U.S. Department of Justice's Cybersecurity Unit published Legal Considerations when Gathering Online Cyber Threat Intelligence and Purchasing Data from Illicit Sources (Version 1.0, February 2020). Its core distinctions are worth building into policy even outside the U.S.:
Write that into rules of engagement, involve counsel, and keep analysts off personal devices and accounts. Our OSINT for Beginners 2026: A Legal, Ethics-First Methodology covers the same principles for open-source work.
Good credential monitoring checks for compromise without spreading secrets further:
Is the Mariana web real? No. It started as a trolling "infographic". The canonical version was uploaded to Imgur in September 2012, and it later spread through expanded charts and YouTube videos. It has no technical basis, and its "polymeric falcighol derivation" doesn't appear in any scholarly index.
What's the difference between the deep web and the dark web? The deep web is anything search engines don't index: email, banking, paywalled and logged-in content. The dark web is the small set of services reachable only through anonymity overlays such as Tor onion services, I2P or Hyphanet.
How big is the dark web in 2026? Tor Metrics estimated about 648,000 unique v3 onion addresses on 23 September 2026, many of them ephemeral or non-web endpoints, carried by about 9,450 volunteer relays. For comparison, there were 401.6 million registered domain names in Q2 2026.
Is using Tor illegal? In most countries, no. The BBC and Facebook have run official onion sites, and newsrooms use Tor-based SecureDrop. Some governments block Tor, which is why bridges exist. Check your local law.
How do people get caught on the dark web? In the major cases, mostly through opsec mistakes (personal email addresses tied to pseudonyms, unlocked devices), undercover takeovers and cryptocurrency tracing. Traffic correlation is a real research threat, but human error dominates the court records.
Do quantum computers let you access hidden parts of the internet? No. Network access depends on routes, protocols and keys, not processor type. Quantum computing matters to the dark web mainly as a future threat to its cryptography, which is why post-quantum standards exist.
Should my company pay for dark web monitoring? Yes, if it's scoped to your real exposure (credentials, sessions, brand, access listings, leak-site claims), collected lawfully, and backed by verifiable evidence. Be sceptical of anyone promising "full dark web coverage".
The Mariana web lasted because it answered a feeling rather than a fact: the sense that the truth is always one layer deeper. The real dark web is smaller, more measurable and more human. Its operators are caught by their own habits, its best-documented legitimate users include newsrooms and people under censorship, and its size fits in a CSV file anyone can download.
At AndraxPentester we spend most of our research time on the next frontier of that same problem: how trust, identity and hidden instructions work in the agentic era, where AI agents act on text they can't verify. If that interests you, start with our MCP security guide.
An exhaustive analysis of 5,308 Model Context Protocol (MCP) servers, introducing the mcpgrade-1.4.0 assessment framework and remediation blueprint.
4 min read