Traffic in Tor network is being sniffed in the exit nodes

A security researcher conducted an experiment to demonstrate that someone is sniffing passing traffic from Tor network exit nodes.

When talking about Tor network, normally everyone assumes that you have an end-to-end security, but someone believes it may be wrong as it was discovered by the security researcher Chloe.

Tor network is free and it is the safest way to be anonymous since it hides your original IP from the destination server, to do that Tor uses relays to redirect traffic, but now the security researcher Chloe concludes that traffic is being sniffed in the exit nodes.

Chloe did the following tests to demonstrate its thesis:

  • Set up a dummy website with an admin sub-domain and a login page
  • Use Tor network to logging into the site several times(137,319 times)
  • Use a unique password in every logging attempt

This means that there was no password repetition made by Chloe.

The next thing to be done by Chloe was searching inside the logs for instances where the unique passwords (used in each logging) were used more than one time, what would indicate that someone was sniffing an exit not and trying to access and logging into Chloe’s dummy site.

What Chloe found out was at least surprising, 16 instances of multiple uses of unique passwords, meaning that someone was sniffing the traffic, to add to that, Chloe got 650 unique page visits.

Chloe claims that in this test it was used 1400 nodes, and that each node was used around 95 times, and the conclusion is, ” We can see that there’s passive MITM [man in the middle spying] going on in the Tor network. This is done by setting up a fully functional and trustworthy exit node and start sniffing.”

To the SCMagazineUK.com Chloe said, “It just shows that there’s bad guys out there that will try to take advantage of Tor-users. This is a problem that affects VPN and proxies too, but the problem is that anyone can anonymously set up a node and start sniffing.”

In the past Chloe criticized how Tor is organized, complaining about 10 or so authority nodes, which have the power to blacklist exit notes, even more, Chloe had in past notified Tor project by email about bad exit nodes, “But nothing happened. Still today the same node is actively sniffing traffic and making the Tor network unsafe for everyone,”

Roger Dingledine, the co-founder of the Tor project told to the SCMagazineUK.com that he is in communication with Chloe and that ” He disputed the number of suspect exit nodes discovered, saying it was seven rather than 15 or 16, a figure which is based on the number of unique Tor fingerprints, but even so he wasn’t surprised or overly concerned about it.”

Roger Dingledine also defends ” Tor is the best option out there in terms of privacy and anonymity, but there are still many open research questions in the area, and there’s always room for improvement. We rely in large part on community members, just like in this situation, to identify, understand, and help resolve problems,”

I love Tor and I run a few relays by myself actually… My recommendations are better URL for onions, like foobar.onion, better cryptography, more decentralised, more power to the users and more focus on keeping the network safe.

“What I mean about the last thing is that these attacks that are made by the exit nodes are not so prioritised, Tor tries to focus on the big attacks on AS-level and so on.

“Also, there needs to be better communication with Tor because I had some problems contacting the right people and even when I did, I did not get the response I was hoping for.”

About the Author Elsio Pinto

Elsio Pinto (@high54security) is at the moment the Lead McAfee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog McAfee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog McAfee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog http://high54security.blogspot.com/

Edited by Pierluigi Paganini

(Security Affairs – Tor Network, hacking)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

18 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

20 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.