Court document for Silk Road 2 trial suggests investigators may have spent six months last year exploiting Tor anonymity bug
Dan Goodin / Ars Technica :
Context & Ripple Effects
This Ars Technica report is the first crack in what became a multi-year disclosure fight over how the FBI broke Tor's anonymity. A court document in the Silk Road 2 case suggests investigators ran an exploitation of a Tor bug for roughly six months before the site was taken down — meaning the deanonymization was sustained infrastructure work, not a one-off intercept.
The arc that follows confirms the scale: Tor alleged the FBI paid Carnegie Mellon $1M to help identify Silk Road 2 users in court documents showing a university assisted the FBI, the FBI later subpoenaed Carnegie Mellon's Software Engineering Institute for IP addresses captured through its DoD-funded research (confirmed via a new court filing), and prosecutors ultimately began dropping charges across 135+ Playpen cases rather than reveal the hack's source code (prosecutors dropping charges to keep the source code secret).
First-order effects
- Silk Road 2 defendants now have grounds to challenge the provenance of the evidence against them, since a six-month exploit implies mass collection of user identities rather than targeted investigation.
- Tor faces an immediate credibility problem: its core anonymity guarantee was reportedly defeated at scale by a single undisclosed bug.
Second-order effects
- Mozilla is forced into the fight, filing in court to obtain details of the underlying Firefox/Tor browser flaw so it can patch and protect Firefox users before the vulnerability becomes public.
- Other prosecutions built on the same technique become legally fragile — the Playpen case pattern shows the government choosing to abandon convictions rather than expose the tooling in discovery.
Third-order effects
- Law enforcement adoption spreads beyond the FBI: Australian authorities were later documented hacking Tor users inside the US and sharing findings with American investigators, turning anonymity-network exploits into routine cross-border intelligence tradecraft.
- The pattern pushes Tor toward structural hardening — next-generation onion services and rapid zero-day patching with Mozilla — while exit-node trust itself erodes, as shown when over a quarter of exit capacity was found malicious in 2021.
The trend: Government investigators are treating anonymity networks like Tor as standing intelligence targets, with courts becoming the battleground where surveillance capability collides with defendants' disclosure rights.