/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FBI uses malware created by an ex-employee of the Tor Project, Matt Edman, to hack Tor users

Former Tor developer created malware for the FBI  —  How does the U.S. government beat Tor, the anonymity software used by millions of people around the world?  By hiring someone with experience on the inside.

The Daily Dot Patrick Howell O'Neill

Context & Ripple Effects

This report closes the loop on a pattern the FBI had been building for years: rather than breaking Tor from the outside, the bureau went around the anonymity layer by hiring someone who helped build it. Matt Edman, a former Tor Project developer, wrote malware for the FBI that targets Tor users directly — an inside job that no amount of network hardening by the Tor Project can fully defend against.

It also fits a documented escalation. The FBI's earlier [[a:824625|Operation Torpedo relied on repurposed Flash code from an abandoned Metasploit side project]] to identify Tor users, and Amy Hess, chief of the bureau's Operational Technology Division, later confirmed on the record that the FBI uses zero-day exploits against its targets. Hiring the author of the software you want to defeat is the next step up: buying institutional knowledge instead of just borrowing code.

First-order effects

  • Tor users — including people whose only crime was visiting sites the FBI was monitoring — face working malware built with insider knowledge of how Tor and its ecosystem are engineered, making deanonymization cheaper and more reliable than external attacks.
  • The Tor Project now has to contend with the fact that its own alumni can be recruited to attack the network, putting former developers' knowledge of internals on the same threat list as software bugs.

Second-order effects

  • Browser vendors get pulled into the fight whether they like it or not: Mozilla was later forced to rush patches for a Firefox zero-day being used in the wild to unmask Tor users, because Tor Browser rides on Firefox and every FBI exploit against it becomes a Firefox emergency.
  • Allied law enforcement treats the FBI's methods as transferable — court documents show Australian authorities hacked Tor users on US soil as part of a child-pornography investigation and shared findings with the FBI, meaning each new technique propagates across partner agencies.

Third-order effects

  • If hiring insiders becomes standard practice, open-source privacy projects face a structural problem: their transparency, which makes the software auditable, also produces a pool of vetted experts whom intelligence agencies can hire to defeat their own work — a tension between openness and operational security that no code release resolves.
  • The pattern points toward routine government stockpiling of offensive capability against civilian anonymity infrastructure, which will keep forcing courts to decide where lawful hacking ends — the same contested terrain visible in the FBI's later operations, from proving NetWire was a RAT to justify seizing its sales site to running the Anøm encrypted-phone sting detailed in Dark Wire.

The trend: Law enforcement is shifting from exploiting software bugs to recruiting the people who built privacy tools, turning insider expertise into a standing offensive capability against anonymity networks.