Tor Traffic Volume After Silk Road Closure

When the FBI seized the Silk Road marketplace in October 2013, many assumed the Tor network would experience a devastating decline in activity. However, the closure did not cause a significant drop in authentic Tor traffic. While network metrics showed a sharp drop in connections around the same time, this reduction was driven by the dismantling of an unrelated malware botnet, not the disappearance of the darknet marketplace.

In late August 2013, just weeks before the Silk Road seizure, Tor’s daily user count mysteriously jumped from roughly one million to over five million users. This massive spike was not caused by drug buyers or privacy advocates, but by the Sefnit (or Mevade) botnet, which used Tor’s infrastructure to control infected computers. In late September and October, security researchers and antivirus providers disabled the botnet’s Tor communication capabilities. This caused Tor connection numbers to plummet back to their baseline levels, coinciding almost exactly with the Silk Road’s shutdown on October 2, 2013.

Beyond the statistical distortion caused by the botnet, the fundamental architecture and usage patterns of Tor prevented the Silk Road’s closure from harming total traffic. Onion services (hidden services) historically account for only a small fraction—estimated between 1.5% to 5%—of the overall bandwidth on the Tor network. The vast majority of Tor users rely on the network to access the standard internet anonymously through exit nodes, meaning the loss of any single hidden service has a minimal impact on total data flow.

Additionally, user demand for darknet commerce did not evaporate with the Silk Road. Within weeks of the seizure, buyers and vendors migrated to alternative platforms such as Black Market Reloaded, Sheep Marketplace, and the quickly launched Silk Road 2.0. This rapid migration redistributed hidden service traffic rather than eliminating it, ensuring that actual human participation across the Tor ecosystem remained stable.