you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 1 min ago 255 onions tracked
home / news / security
25 November 2025 security 4 min read

Playpen and the NIT: the FBI hack that rewrote Tor Browser security

In February 2015, the FBI did something no law enforcement agency had done before: it kept one of the largest dark web child abuse sites running, then served malware to more than a thousand of its visitors. The operation, remembered simply as Playpen, became the defining legal fight over government hacking. It also forced the Tor Browser to harden itself against exactly this kind of attack.

The seizure that never shut the site down

Playpen was a hidden service on the Tor network with roughly 215,000 registered accounts. Investigators found its real server location through a misconfiguration, and in early 2015 the FBI took control of the hardware. Then came the unusual part: instead of pulling the plug, agents copied the site to a government server in Virginia and switched it back on. For thirteen days, from February 20 to March 4, 2015, the bureau itself operated one of the worst forums on the internet. The Electronic Frontier Foundation later described the campaign as the largest known hacking operation in US law enforcement history (EFF).

How the NIT broke through Tor

The weapon of choice was a Network Investigative Technique, or NIT, the government's preferred euphemism for an exploit. Whenever a user logged into Playpen, the site appended extra code to the pages it served. On Windows machines, that code attacked a vulnerability in the Firefox-based Tor Browser Bundle and executed outside the browser's usual limits. Once running, the payload phoned home with everything Tor exists to hide. Court records show it transmitted the machine's real IP address, host name, MAC address, active operating system username and a unique tracking identifier (Second Circuit opinion). Reporting by Motherboard's Joseph Cox put the yield at approximately 1,300 genuine IP addresses in under two weeks (Motherboard).
We are not talking about searching one or two computers. We are talking about the government hacking thousands of computers, pursuant to a single warrant.

One warrant, worldwide reach

A single warrant from Magistrate Judge Theresa Buchanan in the Eastern District of Virginia authorized the entire operation. Legal scholars immediately objected: the warrant claimed jurisdiction over computers located anywhere, which the rules of criminal procedure did not then permit. Ten federal circuit courts eventually upheld the searches anyway, applying the good-faith exception to what they accepted was a defective warrant. Congress then amended Rule 41 in December 2016 to explicitly authorize remote-search warrants like this one.

The secret the DOJ refused to give up

The NIT worked because of an unpatched flaw in Firefox, the codebase behind roughly 95 percent of the Tor Browser. Mozilla filed briefs asking to be told about the vulnerability so it could protect every Firefox user. The Justice Department refused, and in March 2017 it went further: prosecutors dropped the indictment of defendant Jay Michaud rather than disclose the exploit (WIRED). That decision crystallized the debate over vulnerability stockpiling. A flaw kept secret for investigations is a flaw left open for everyone else.

What changed inside the Tor Browser

The fallout produced concrete hardening measures, several of which remain in place:
  • Automatic updates arrived in August 2015, months too late for Playpen victims but standard ever since.
  • The security slider gained levels that fully disable JavaScript, closing the delivery path almost all browser exploits require.
  • Sandboxing and process isolation became priorities to limit what a successful exploit can actually read.
  • Mozilla-Tor collaboration deepened, with privacy patches shared upstream to both browsers.
The value of these defenses was proven quickly. When an unknown attacker deployed a nearly identical Firefox zero-day against Tor users in November 2016, developers shipped a fix for CVE-2016-9079 in under 24 hours, and users who had set their security level to High were untouched (Ars Technica). Analysts at Lawfare had already concluded that disabling JavaScript defeats virtually every NIT-style exploit (Lawfare).

The lasting lesson

An anonymity network is only as anonymous as the browser running on top of it. Playpen demonstrated that a single unpatched rendering-engine bug can undo routing, layering and encryption in one stroke. For anyone running onion services or browsing them today, the checklist has not really changed: keep the browser current, raise the security level, treat JavaScript as optional, and remember your setup guide before you need it. Our regular security notes track the exploits that still target Tor users, and our tor setup guide walks through the safest configuration.

more notes

all news ›