The v3-only era: life after legacy onion addresses disappeared
In October 2021, millions of 16-character .onion addresses stopped resolving overnight. The Tor Project had removed support for version 2 onion services from its stable releases, closing a chapter that began more than a decade earlier. What followed was messy, occasionally painful, and ultimately transformative for the anonymous network.
Why v2 had to die
The case against v2 came down to one word, as the Tor Project's deprecation announcement put it: safety. Version 2 services leaned on RSA-1024 keys, SHA-1 truncated to just 80 bits, and the ancient TAP handshake that had been stripped from every other part of Tor years before. Those parameters were not merely dated. An adversary who could factor a 1024-bit RSA key could impersonate any v2 service outright, and researchers warned that HSDir relays could enumerate large numbers of hidden services because descriptors were uploaded in plain text. None of this was a secret. The cryptography underpinning v2 had been considered fragile for years before the shutdown became official policy in July 2020, when the project published its v2 deprecation timeline and gave operators roughly sixteen months to move.What prop-224 actually changed
Version 3 services grew out of proposal 224, first shipped for testing in Tor 0.3.2.1-alpha in 2017. The release notes were blunt about the headline change: SHA1/DH/RSA1024 was replaced with SHA3/ed25519/curve25519, bringing onion services onto modern cryptographic footing. The most visible consequence is address length. A v3 address embeds a full ed25519 public key, which is why it runs 56 characters instead of 16. That single design choice eliminates collision attacks and makes enumeration fundamentally harder. It also reworked the directory system. Because the address itself is the public key, everything uploaded to hidden service directories can be encrypted, with clients deriving a daily-rotated blinded public key. HSDir relays no longer see which services they are storing. OnionBalance support, offline keys, and improved client authorization followed later. By late 2020, the project argued v3 had reached feature parity and full network support, clearing the last practical objection to retirement.The growing pains nobody planned for
There was never a bridge between generations. As the Tor developers acknowledged, there was no mechanism to cross-certify the two addresses, so every service had to publish a brand new identity and hope its users would follow. Some software simply could not cope with longer addresses. Tools like onioncat needed patching, Bitcoin Core had to extend its address handling, and countless link directories woke up on October 15, 2021 to walls of dead entries. When Tor Browser 11.0 landed, visitors to old addresses got a plain "Invalid Onion Site Address" error, and the project asked users to notify site administrators rather than assume their browser was broken. For smaller operators who had ignored the warnings, discovery was abrupt and unforgiving.The ticket that deleted v2 from the code base was titled "Farewell Old Friend" - an acknowledgment that a decade of working infrastructure deserved a dignified exit, even if the crypto did not.
What the ecosystem looks like now
Four years on, the v3-only world has stabilized. Tor Metrics continues to track unique v3 .onion addresses daily, and independent research suggests the population is both larger and healthier than the v2 era ever allowed anyone to measure reliably. A 2025 study presented at PON/FOCI compiled the largest known collection of v3 onion addresses, 482,614 unique entries, and verified activity by deploying HSDir relays that harvest blinded public keys throughout 2024. The same research found surprisingly few false positives: over 93 percent of collected addresses corresponded to real descriptor traffic. The long addresses that once looked like a usability disaster turned out to be self-authenticating, copy-paste-proof identifiers.The lesson of the transition
The v2-to-v3 migration remains one of the largest forced protocol upgrades in privacy infrastructure. It succeeded because the timeline was public, the rationale was documented, and the replacement shipped and hardened well before the deadline hit.- v2 died for provable cryptographic reasons, not convenience
- v3 addresses contain their own public keys, enabling encrypted descriptors
- No cross-certification existed, so every identity changed hands manually
- Third-party tooling lagged longest, breaking fringe use cases