Understanding exit node risks requires knowing how Tor circuits work:
- Entry node (guard): Knows your real IP address but cannot see what you're browsing. Encrypted traffic passes through.
- Middle relay: Knows neither your IP nor your destination. Just passes encrypted traffic between entry and exit nodes.
- Exit node: Decrypts the final layer of Tor encryption and sends your request to the destination website. Can see the content of your traffic if you're visiting HTTP (unencrypted) sites.
Key insight: Exit nodes only handle traffic going to regular (clearnet) websites. If you're visiting .onion sites, there is NO exit node - traffic is encrypted end-to-end between you and the onion service. This is a major security advantage of .onion sites.