This is why we need WebAuthn[1] supporting browser-side encryption using passkeys (or any other secure enclave)[2]. Relying on servers to encrypt data for you will be seen as comical 5 years from now.
For dark-net markets, server-side encryption is already seen as a failsafe rather than a feature, and smart users ALWAYS encrypt client side (PGP). That said, for activities like these, smart users are not necessarily the majority...