you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 14 min ago 255 onions tracked
home / news / tor network
07 January 2025 tor network 4 min read

When the Onion Goes Dark: A Short History of DDoS on Tor

For three straight winters, roughly between 2020 and 2023, distributed denial-of-service attacks turned parts of the dark web into a ghost town. Marketplaces vanished for days at a time.

The waves were not random vandalism. They were competitive weapons, extortion leverage, and occasionally collateral damage that spilled onto the Tor network itself.

The marketplace wars begin

The first big wave hit darknet markets in late 2020 and intensified through 2021. Researchers at DarkOwl documented more than 30 percent of known markets going dark within weeks, with administrators blaming competitors for circuit-based flooding attacks (DarkOwl). Cannazon, a large cannabis market, threw in the towel in November 2021 after a sustained attack made normal operations impossible. Its admins signed a PGP-keyed retirement note insisting they were not exit scamming (BleepingComputer). DDoS became the cheapest way to kill a rival without touching a server. The extortion angle deserves its own mention: several operators paid attackers simply to stay online during high-volume periods. Others rotated mirrors weekly, which eroded user trust as much as the downtime did.

Collateral damage reaches the network

In January 2021 the fighting stopped being contained. A coordinated attack overwhelmed hidden-service directory infrastructure, and a consensus-handling bug compounded it: all v3 onion services went offline for up to 12 hours, taking legitimate sites like Wasabi and Bisq down with them (TechNadu). That episode made something explicit that operators had long suspected. An attack on one busy onion service is never really local, because introduction points, guards, and directory caches all share the load.

What Tor shipped: the toolbox era

The Tor Project had been building defenses incrementally since 2018. Rate limiting on introduction points, onion-service-side stream caps, and better CPU protections arrived first, alongside operational guidance for hardening deployments.
  • Introduction-point rate limiting via HiddenServiceEnableIntroDoSDefense
  • PoW-defended introductions, shipped experimentally in Tor 0.4.8
  • Vanguards-style layer guarding against targeted node discovery
Engineers were candid that these measures moved the goalposts without solving the game. In their own words, the rendezvous protocol's asymmetry meant an evil client sends a small message while the service performs expensive work in response (Tor Project blog). Horizontal scaling through OnionBalance helped distribute introduction load across multiple frontend instances. But scaling also multiplied cost, which mattered little to well-funded markets and a lot to everyone else.

Proof of work changes the economics

Proposal 327, drafted in April 2020 by Kadianakis, Perry, Goulet, and tevador, proposed flipping the asymmetry: clients would solve a computational puzzle before their introduction requests got queued (Tor proposal 327). It took until Tor 0.4.8 in late 2023 for the design to land as a default-capable defense. The mechanism stays dormant under normal load, then raises suggested puzzle effort as stress increases, prioritizing verified traffic in a queue (Tor Project).
Solvers face diminishing returns by design: every additional request raises the effort required, until attacking costs more than it gains.
Typical solves take milliseconds for ordinary users, stretching toward a minute only under heavy attack. That trade-off is deliberate, trading a little latency for reachability when everything else has failed.

Why the problem never fully goes away

Onion DDoS is structurally hard because Tor deliberately strips out the signals defenders rely on. There are no IP addresses to rate-limit, no accounts to ban, no anycast edge to absorb floods at. Every connection request looks like every other request. Fairness therefore defaults to equal treatment, which structurally favors whoever can send the most requests. The PoW defense narrows that gap but does not close it. Determined botnets can still solve puzzles at scale, and services must weigh real usability losses against speculative attack resistance. Still, the trajectory from 2020 to today is clear: from helpless downtime, to rate-limit toolboxes, to built-in economic deterrence. For a network designed around anonymity rather than availability, that is genuine progress.

more notes

all news ›