People often ask how law enforcement tracks criminals on the dark web, usually assuming investigators break Tor's encryption directly. That is rarely what happens. Most unmasking comes from old-fashioned investigative work, human error, and infiltration rather than a magic technical exploit.
Tor hides your IP address, not your behavior
Tor Browser routes traffic through multiple relays, which makes it very hard to trace a connection back to an IP address using network observation alone. This is a real and useful protection.
But Tor does not make an action anonymous by itself. If someone logs into a personal account, reuses a username, or downloads a file that phones home, Tor cannot undo that choice. According to Wikipedia's entry on the Tor network, investigators have found that the most reliable route to identifying a user is the user's own mistakes, not a flaw in the Tor protocol itself.
Open source intelligence comes first
Before any technical measure, investigators lean on OSINT: open source intelligence. These are tools and techniques that legally gather information from publicly available sources, including dark web forums and marketplaces themselves.
As Wikipedia's dark web article explains, police cannot pull an IP address the way they would on the open internet, since Tor is built to prevent exactly that. OSINT becomes a primary method: piecing together usernames, writing style, posting times, images, and other details that a suspect leaves scattered across both the dark web and the surface web.
A person who reuses a handle from a clearnet forum on a dark web marketplace has effectively connected the two identities for anyone patient enough to look.
Infiltration and takeovers: the Operation Bayonet model
Some of the most significant dark web takedowns have come from infiltrating or seizing the infrastructure of criminal marketplaces themselves.
In 2017, an international law enforcement effort known as Operation Bayonet took down AlphaBay and Hansa, two major dark web marketplaces, according to reporting from Wired and the BBC. Investigators did not just shut Hansa down. They secretly took control of it and kept it running under police supervision, quietly logging the activity of people who believed they were using a secure, hidden marketplace. Nine countries participated in the broader probe. This kind of operation depends on patience and secrecy rather than breaking Tor's core cryptography.
Technical attacks on the network itself have happened
Tor's design has occasionally been probed and, in specific cases, partially defeated. Wired reported that a 2014 law enforcement operation, which took a number of dark web sites offline including a version of Silk Road, is believed to have relied on a technique developed by researchers that could "mark" traffic to hidden services in a way that helped de-anonymize it.
This was not a routine capability. It depended on a specific research technique and access that most investigations do not have. The Tor Project has since worked to close such gaps, and claims that large percentages of Tor users would be quickly de-anonymized have not held up over time.
Stolen credentials and self-inflicted exposure
Sometimes the unmasking does not come from police action at all. According to reporting from The Record, researchers at Recorded Future found that malware used to steal login credentials from ordinary computers also swept up credentials for darknet accounts, including accounts on sites used to share child sexual abuse material.
By cross-referencing this stolen credential data with partner organizations, researchers said they were able to identify roughly 3,300 unique users tied to at least one such darknet site, and shared their findings with law enforcement. The investigators involved described it plainly: people who engage in risky behavior online, including installing pirated software or clicking unsafe links, often expose themselves without any dark web exploit being involved at all.
Why directories like "the Hidden Wiki" are part of the risk
Readers sometimes stumble onto link lists calling themselves "the Hidden Wiki," assuming it is some kind of safe or official starting point for the dark web. It is not. There is no single trustworthy Hidden Wiki anymore. What circulates under that name today is a sea of clones and copycats, often loaded with outdated, scam, or outright dangerous links. Treat any site using that name as a caution sign, not a map.
What this means for ordinary privacy-minded readers
If you use Tor Browser for legitimate privacy reasons, such as avoiding tracking, researching sensitive topics, or accessing a service in a country with heavy censorship, the lessons above still apply to you in a smaller way.
- Do not reuse usernames or writing habits across identities you want kept separate.
- Avoid logging into personal accounts, like a personal email or social media, over Tor if you want that session kept separate from your identity.
- Get onion addresses directly from an organization you already trust on the surface web, such as checking The Tor Project's own site, and verify the address there rather than trusting a search result or directory link.
- Remember that tools like DuckDuckGo or Proton Mail can support privacy, but no single tool guarantees anonymity on its own.
Law enforcement rarely breaks Tor. They work around it through patience, infiltration, OSINT, and the mistakes people make when they assume a tool alone can protect them.