On December 25, notorious hacker group Lizard Squad took down the PSN and Xbox Live networks spoiling Christmas for many. Despite a warning from Anonymous, it ‘tried’ to hack the Tor Network the very next day.

Nadim Kobeissi, a computer researcher, tweeted a screenshot of what the Tor network looked like after the Lizard Squad signed up the 3000 new Tor relays.

The hackers acquired almost half of 8000 Tor relays to dominate in the numbers game for the ownership of Tor relay.

Tor later in a statement confirmed that they were working to remove these relays.

This looks like a regular attempt at a Sybil attack: the attackers have signed up many new relays in hopes of becoming a large fraction of the network. But even though they are running thousands of new relays, their relays currently make up less than 1% of the Tor network by capacity. We are working now to remove these relays from the network before they become a threat, and we don’t expect any anonymity or performance effects based on what we’ve seen so far. Tor keeps a user’s IP address anonymous by bouncing its data packets through a random path of relays. Each relay knows only of the relay that sent it data and the next relay in the random path. A user’s connection remains anonymous as long as the entry and exit relays do not collude. A group that controls almost half the total number of Tor relays could track the traffic over them. Security researcher, Runa Sandvik told Zdnet that since Lizard Squad-controlled relays were operated on Google Cloud services and in the same IP-address range, the hacking couldn’t affect the Tor network. In addition, the hackers only signed up new relays that required numerous verification steps to get fully active and be a part of the Tor relay network. Sensing that the attack was a complete failure, a rattled Lizard Squad then shut down the Tor project’s official website via their favourite DDoS attack.


Angry privacy lovers around the globe then asked Lizard Squad to end their evil deeds:

Lizard Squad simply replied:

Tor users were still not sure whether the hackers had taken down the entire Tor network or it was only the website that was targeted. Anonymous clarified on Twitter:

Tor’s website was functioning normally after the DDoS attack that lasted only a few hours.


