/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: twice in 2021, 25%+ of Tor's entire exit node capacity was known to be malicious and involved in a scheme targeting users accessing crypto-related sites

The Record Catalin Cimpanu

Context & Ripple Effects

This report extends an established playbook. In 2020, researchers documented a group hijacking Tor exit relays to run SSL-stripping attacks that peaked at nearly 24% of all nodes; back in 2015, rogue exit relays were caught stealing Bitcoin from Blockchain.info users. The new finding — that twice in 2021, over 25% of exit capacity was malicious and aimed at crypto-related sites — shows the same attack class persisting at or above its previous peak.

The arc also carries a long-running legitimacy argument about Tor itself: CloudFlare once claimed 94% of the Tor traffic it saw was 'per se malicious,' which Tor disputed as flawed methodology. A measured capacity figure like this one is harder to wave off, because it quantifies attacker-controlled infrastructure rather than characterizing user intent.

First-order effects

  • Tor users visiting cryptocurrency sites are directly exposed: anyone running malicious exit nodes can intercept unencrypted traffic to those destinations, repeating the 2015 Bitcoin-theft pattern at greater scale.
  • The Tor project faces renewed pressure to harden relay admission and vetting, since its volunteer-run trust model is what let hostile operators amass a quarter of exit capacity.

Second-order effects

  • Crypto services already wary of anonymity networks gain fresh ammunition to block, CAPTCHA, or de-prioritize Tor traffic outright — pushing legitimate privacy-conscious users toward fewer on-ramps.
  • Exit-node operators who behave honestly absorb the reputational damage, as each incident makes downstream sites treat all exits as presumptively hostile.

Third-order effects

  • If exit-relay capture campaigns keep recurring roughly on this cadence, the durable lesson is that anything crossing an exit node unencrypted should be assumed compromised — accelerating the case for encryption-by-default across the web rather than trusting network middlemen.
  • Sustained abuse at this share of capacity could reshape Tor's structure itself: tighter operator identity requirements or curated relay sets would trade some of the project's decentralization for resilience against exactly this kind of infiltration.

The trend: Attackers repeatedly capture large shares of Tor's exit capacity in waves that disproportionately target cryptocurrency users, testing whether the volunteer relay model can survive without stronger operator verification.

Discussion

  • @quinnypig Corey Quinn on x
    Fortunately it soon rose back up to normal levels. https://twitter.com/...
  • @therecord_media @therecord_media on x
    For more than 16 months, a threat actor has been seen adding malicious servers to the Tor network in order to intercept traffic and perform SSL stripping attacks on users accessing cryptocurrency-related sites https://therecord.media/...