Can the FBI Track Tor?
Sometimes, in targeted cases. But the public record does not show a general FBI ability to trace any Tor user on demand.
The FBI can identify some Tor users in specific investigations, but public evidence points mostly to endpoint exploits, seized onion services, OPSEC failures, financial records and conventional investigation. The public record does not show the FBI breaking Tor's core cryptography or casually tracing all Tor users.
The phrase track Tor hides the most important distinction. An agency can identify a Tor user by attacking the network, exploiting the browser, seizing a server, following money or proving identity through ordinary records. Those are different claims.
In the strongest public cases, the FBI usually worked around Tor rather than through Tor. That does not make the cases less serious, but it changes what they prove.

Answer
The FBI can identify Tor users, but not usually by tracing Tor itself
Public FBI-linked cases show real capability against Tor users and onion services. Silk Road, Silk Road 2.0, Playpen, AlphaBay and later marketplace operations all show that using Tor does not make a target unreachable.
Those cases do not all prove the same thing. Playpen was an endpoint and browser operation. AlphaBay involved identity and infrastructure evidence. Silk Road involved a disputed server-discovery account plus OPSEC and physical evidence. CMU is the major case that points closest to a real Tor network-layer attack.
So the correct answer is conditional. The FBI can track some Tor users when it has a target, time, legal authority, technical access or outside evidence. That is not the same as saying the FBI can watch every Tor circuit or decrypt Tor traffic.
What the evidence supports
- There is public evidence of FBI identification of specific Tor users.
- There is no public evidence of a general break of Tor's layered encryption.
- Endpoint exploits and server seizures are better documented than direct network tracing.
- The CMU relay-early episode is the strongest warning against saying Tor itself is never attacked.
What FBI-related Tor cases actually prove
The method matters because each one supports a different claim about capability.
| Example | What it proves | What it does not prove | |
|---|---|---|---|
| Playpen | FBI-operated site and Network Investigative Technique | Endpoint exploits can identify visitors to a controlled site | That Tor routing was decrypted |
| Silk Road | Server lead, OPSEC records, surveillance and laptop seizure | A Tor-hosted marketplace can be investigated successfully | That the FBI publicly proved a protocol break |
| CMU relay-early episode | Controlled relays and traffic confirmation | Network-layer attacks against hidden-service users are real | That every Operation Onymous arrest used that method |
| AlphaBay | Email, infrastructure, assets and cryptocurrency records | Identity leaks outside Tor can be decisive | That Tor failed as a relay network |
The case that keeps the answer from being simple
The Tor Project's 2014 relay-early advisory described relays that appeared to be trying to deanonymize hidden-service users through traffic confirmation. The Tor Project later linked the episode to Carnegie Mellon researchers and said it believed the FBI had paid for the work.
That is the strongest public reason not to dismiss Tor network attacks as purely theoretical. It involved relays, hidden services and traffic confirmation, not merely a careless username or a seized laptop.
The uncertainty is also important. The public record does not cleanly prove which specific arrests depended on that technique, and it still does not show Tor cryptography being broken.
Most public FBI successes worked around Tor
Playpen is the clearest example. The FBI controlled the destination site and used code designed to make visitors' computers return identifying information. That is a browser or endpoint attack, not a defeat of onion routing.
Marketplace cases show another path. If investigators identify or seize an onion-service server, obtain administrator records or capture a device while it is logged in, they can build a case without tracing every packet through Tor.
This is why the phrase track Tor is imprecise. The FBI may track a person who used Tor through evidence outside Tor.
What the public record does not show
It does not show that the FBI can casually identify any Tor user. It does not show that Tor's layered cryptography has been broken. It does not show that seeing someone connect to Tor automatically reveals which onion service they visited.
It does show that a targeted investigation can combine multiple weak signals until anonymity fails: browser behavior, server records, payment trails, account reuse, institutional logs, seized devices and undercover contact.
A careful public answer has to leave room for classified capabilities. Absence of public evidence is not proof that no classified capability exists, but it is also not a license to claim unlimited capability.
FAQs
Questions people ask
Sources
Further reading
- Tor security advisory: relay early traffic confirmation attackTor Project
- Did the FBI Pay a University to Attack Tor Users?Tor Project
- United States v. Hall, Operation Pacifier discussionFederal court record mirror
- Manhattan U.S. Attorney Announces the Indictment of Ross UlbrichtU.S. Department of Justice
- AlphaBay, the Largest Online Dark Market, Shut DownU.S. Department of Justice
Glossary
Terms in this guide
Continue learning