FBI uses malware created by an ex-employee of the Tor Project, Matt Edman, to hack Tor users
Former Tor developer created malware for the FBI — How does the U.S. government beat Tor, the anonymity software used by millions of people around the world? By hiring someone with experience on the inside.
Context & Ripple Effects
This report closes the loop on a pattern the FBI had been building for years: rather than breaking Tor from the outside, the bureau went around the anonymity layer by hiring someone who helped build it. Matt Edman, a former Tor Project developer, wrote malware for the FBI that targets Tor users directly — an inside job that no amount of network hardening by the Tor Project can fully defend against.
It also fits a documented escalation. The FBI's earlier [[a:824625|Operation Torpedo relied on repurposed Flash code from an abandoned Metasploit side project]] to identify Tor users, and Amy Hess, chief of the bureau's Operational Technology Division, later confirmed on the record that the FBI uses zero-day exploits against its targets. Hiring the author of the software you want to defeat is the next step up: buying institutional knowledge instead of just borrowing code.
First-order effects
- Tor users — including people whose only crime was visiting sites the FBI was monitoring — face working malware built with insider knowledge of how Tor and its ecosystem are engineered, making deanonymization cheaper and more reliable than external attacks.
- The Tor Project now has to contend with the fact that its own alumni can be recruited to attack the network, putting former developers' knowledge of internals on the same threat list as software bugs.
Second-order effects
- Browser vendors get pulled into the fight whether they like it or not: Mozilla was later forced to rush patches for a Firefox zero-day being used in the wild to unmask Tor users, because Tor Browser rides on Firefox and every FBI exploit against it becomes a Firefox emergency.
- Allied law enforcement treats the FBI's methods as transferable — court documents show Australian authorities hacked Tor users on US soil as part of a child-pornography investigation and shared findings with the FBI, meaning each new technique propagates across partner agencies.
Third-order effects
- If hiring insiders becomes standard practice, open-source privacy projects face a structural problem: their transparency, which makes the software auditable, also produces a pool of vetted experts whom intelligence agencies can hire to defeat their own work — a tension between openness and operational security that no code release resolves.
- The pattern points toward routine government stockpiling of offensive capability against civilian anonymity infrastructure, which will keep forcing courts to decide where lawful hacking ends — the same contested terrain visible in the FBI's later operations, from proving NetWire was a RAT to justify seizing its sales site to running the Anøm encrypted-phone sting detailed in Dark Wire.
The trend: Law enforcement is shifting from exploiting software bugs to recruiting the people who built privacy tools, turning insider expertise into a standing offensive capability against anonymity networks.