Researchers and law enforcement have documented several methods for tracing Tor users:
- Traffic correlation attacks: An adversary who can observe both the Tor entry and exit points can correlate timing and volume patterns to link traffic to a user. This requires monitoring large portions of the internet (ISP-level or nation-state capability). Academic research shows this is theoretically possible but extremely difficult at scale.
- JavaScript/browser exploits: The FBI used a zero-day JavaScript exploit ("Network Investigative Technique" or NIT) to de-anonymize users of a Tor-hosted service in 2015. The exploit ran code in Tor Browser that reported the user's real IP address. This is why disabling JavaScript (Safest mode) is critical.
- Operational security failures: Most Tor users who were identified made mistakes: logging into personal accounts, reusing usernames, sending identifiable information, or downloading files that connected outside Tor. User error is the primary cause of de-anonymization.
- Relay-level attacks: Running a large number of Tor relays allows traffic analysis. A 2014 attack confirmed that Tor relays run by the same entity could correlate users with hidden services. The Tor Project implemented defenses against this.