Has Tor Suffered a Large-Scale Sybil Attack?

The Tor network has experienced several large-scale Sybil attacks throughout its history, with varying degrees of success. In a Sybil attack, a single adversary creates and controls a massive number of pseudonymous nodes to gain disproportionate influence over a decentralized network. While no single Sybil attack has permanently broken Tor’s overall infrastructure, major incidents—such as the 2014 Carnegie Mellon University research operation and the persistent 2020–2021 “Kax17” campaign—successfully compromised significant portions of the network to deanonymize users and manipulate traffic before being detected and neutralized.

How a Sybil Attack Works on Tor

Tor relies on a three-hop circuit comprising a Guard (entry) node, a Middle node, and an Exit node. Tor protects user anonymity through layered encryption, meaning no single node knows both the origin and the destination of the traffic.

However, if an attacker operates both the entry Guard and the Exit relay in a specific circuit, they can perform statistical traffic correlation attacks. By comparing traffic patterns, packet sizes, and timestamps entering and exiting the network, the attacker can deanonymize the user. A Sybil attack achieves this by flooding the network with thousands of malicious relays, increasing the statistical probability that a user selects attacker-controlled nodes for both entry and exit points.

Major Large-Scale Sybil Incidents

The 2014 Carnegie Mellon University Attack

Between February and July 2014, researchers from Carnegie Mellon University (CMU) deployed a sophisticated Sybil attack on the live Tor network. By running a large cluster of modified relays, the researchers exploited a flaw in Tor’s traffic-tagging mechanism.

The attack successfully targeted hidden services (onion services) and individual users, leading to the deanonymization of numerous Tor users. The vulnerability was patched in subsequent Tor releases, and the malicious relays were expelled once identified.

The 2020–2021 “Kax17” Campaign

One of the largest persistent Sybil attacks on Tor was orchestrated by an entity tracked as “Kax17.” At its peak, this threat actor operated thousands of malicious relays, accounting for roughly 10% to 27% of the total network relay capacity at various intervals.

Kax17 added servers primarily configured as Guard and Middle nodes across dozens of autonomous systems worldwide. The scale of this deployment strongly suggested an attempt to conduct widespread traffic analysis and user deanonymization. The Tor Project systematically removed these nodes in batches as they were uncovered throughout 2020 and late 2021.

Cryptocurrency Interception via Malicious Exit Relays

Starting in 2020, security researchers discovered a threat actor controlling over 23% of Tor’s total exit relay capacity. Rather than attempting pure deanonymization, this Sybil attack performed SSL stripping on unencrypted web traffic to replace cryptocurrency addresses with the attacker’s own wallet addresses during transactions. The operators generated hundreds of exit nodes over several months before the Tor Directory Authorities purged them from the consensus.

How Tor Mitigates Sybil Attacks

The Tor Project relies on several architectural defenses to detect, reduce, and eliminate the impact of Sybil attacks:

Tor has never suffered a fatal or permanent Sybil compromise, but it remains constantly targeted by large-scale node flooding campaigns designed for intelligence gathering, deanonymization, and financial theft.