a4953f628d
Connected to the .onion hidden service via Tor SOCKS proxy and confirmed it serves the SAME certificate as electrumx.testls.space: SHA-256: 53:65:D5:BB:26:19:F5:40:1C:D8:8E:FC:AF:FB:A5:B2:... The .onion cert is already covered by the first pinned cert entry. Added comments documenting this relationship and instructions for fetching .onion certs via Tor for future updates. The .onion still uses onionSslFactory() (trust-all) as the primary path — this is correct since Tor provides its own authentication. The pinned cert serves as defense-in-depth.