When the Onion Goes Dark: A Short History of DDoS on Tor
For three straight winters, roughly between 2020 and 2023, distributed denial-of-service attacks turned parts of the dark web into a ghost town. Marketplaces vanished for days at a time.
The waves were not random vandalism. They were competitive weapons, extortion leverage, and occasionally collateral damage that spilled onto the Tor network itself.The marketplace wars begin
The first big wave hit darknet markets in late 2020 and intensified through 2021. Researchers at DarkOwl documented more than 30 percent of known markets going dark within weeks, with administrators blaming competitors for circuit-based flooding attacks (DarkOwl). Cannazon, a large cannabis market, threw in the towel in November 2021 after a sustained attack made normal operations impossible. Its admins signed a PGP-keyed retirement note insisting they were not exit scamming (BleepingComputer). DDoS became the cheapest way to kill a rival without touching a server. The extortion angle deserves its own mention: several operators paid attackers simply to stay online during high-volume periods. Others rotated mirrors weekly, which eroded user trust as much as the downtime did.Collateral damage reaches the network
In January 2021 the fighting stopped being contained. A coordinated attack overwhelmed hidden-service directory infrastructure, and a consensus-handling bug compounded it: all v3 onion services went offline for up to 12 hours, taking legitimate sites like Wasabi and Bisq down with them (TechNadu). That episode made something explicit that operators had long suspected. An attack on one busy onion service is never really local, because introduction points, guards, and directory caches all share the load.What Tor shipped: the toolbox era
The Tor Project had been building defenses incrementally since 2018. Rate limiting on introduction points, onion-service-side stream caps, and better CPU protections arrived first, alongside operational guidance for hardening deployments.- Introduction-point rate limiting via HiddenServiceEnableIntroDoSDefense
- PoW-defended introductions, shipped experimentally in Tor 0.4.8
- Vanguards-style layer guarding against targeted node discovery
Proof of work changes the economics
Proposal 327, drafted in April 2020 by Kadianakis, Perry, Goulet, and tevador, proposed flipping the asymmetry: clients would solve a computational puzzle before their introduction requests got queued (Tor proposal 327). It took until Tor 0.4.8 in late 2023 for the design to land as a default-capable defense. The mechanism stays dormant under normal load, then raises suggested puzzle effort as stress increases, prioritizing verified traffic in a queue (Tor Project).Solvers face diminishing returns by design: every additional request raises the effort required, until attacking costs more than it gains.Typical solves take milliseconds for ordinary users, stretching toward a minute only under heavy attack. That trade-off is deliberate, trading a little latency for reachability when everything else has failed.