Are you absolutely certain you haven't been phished? Have you ever been asked for your PIN at the login screen? Have you ever attempted to login from a non-legit URL? (the correct one should be silkroadvb5piz3r.onion