The FBI used Flash code from abandoned Metasploit side project to identify Tor users in Operation Torpedo
The FBI Used the Web's Favorite Hacking Tool to Unmask Tor Users — For more than a decade, a powerful app called Metasploit has been the most important tool in the hacking world …
Context & Ripple Effects
Operation Torpedo sits at the start of a documented FBI campaign against Tor hidden services: the bureau took Flash code from an abandoned Metasploit side project and rebuilt it into the tracking payload that identified visitors to sites it had seized. Later coverage filled in the pattern — court documents revealing the FBI hacked more than 1,000 computers across a single sting, an ex-Tor Project employee writing the FBI's malware, and Australian authorities hacking US-based Tor users and handing the results to the bureau.
First-order effects
- Visitors to the Operation Torpedo target sites were deanonymized by a tool whose origins were in the open-source penetration-testing world, meaning the FBI could attribute them without developing its own exploit capability from scratch.
- Metasploit's maintainers faced the fallout of their own abandoned research being weaponized by a law-enforcement agency — the dual-use problem landing directly on the tool's community.
Second-order effects
- Browser vendors were pulled into the fight: Mozilla moved to patch an in-the-wild Firefox zero-day being used to unmask Tor users, one similar to the FBI's earlier technique, forcing rapid-response patching driven by law-enforcement operations rather than criminal exploitation alone.
- Allied agencies adopted the playbook — Australian investigators hacked US Tor users under their own authority and shared findings with the FBI, extending the technique beyond any single bureau's legal jurisdiction.
Third-order effects
- If the pattern holds, the boundary between offensive security research and state surveillance keeps thinning: code written by hackers becomes the default instrument of deanonymization, and the public learns of each operation only when court documents surface months or years later — making judicial disclosure the de facto accountability mechanism for government hacking.
- The recurring role of insiders and leaked artifacts — an ex-Tor developer authoring FBI malware, forum databases and exchange records surfacing in investigations — points toward anonymity networks being contested less at the crypto layer than through operational intelligence around them.
The trend: Law enforcement is systematically repurposing hacker-built tooling and browser exploits to strip anonymity networks like Tor, with the full scope emerging only through court-document disclosures.