Tor deanonymization vulnerability prompts Agora admins to temporarily shut down access to the website

Aug 27, 2015 07:36 GMT  ·  By

Agora, a Dark Web marketplace used by nefarious actors to exchange drugs, weapons, and other illegal products, has decided to temporarily shut down due to a security weakness in the Tor anonymization network.

The weakness in question was discovered by researchers at MIT and the Qatar Computing Research Institute (QCRI), and allows third-parties to deanonymize TOR traffic using malicious nodes added to the network, all with an 88% accuracy percentage.

Since Agora is operated as a Tor hidden service, allowing users access based on an Onion address alone, the site is 100% dependent on Tor and the Onion routing system, making the aforementioned vulnerability, a very serious threat, even if the researchers said it relies on a lot of luck to get it working.

Agora stands by its motto: Anonymity is sacrosanct here

In a statement sent out to users, Agora administrators have described how after the recent Tor security research paper came out, they've started seeing suspicious activity around one of their servers.

Fearing the same fate as Silk Road, which was raided and shut down by the FBI in October 2013, the administrators decided to play it safe.

"We have recently been discovering suspicious activity around our servers which led us to believe that some of the attacks described in the research could be going on and we decided to move servers once again, however this is only a temporary solution," as was noted in the Agora admins statement.

Agora is currently bigger than Silk Road

As WIRED reported back in September of 2014, Agora is not only the current king of the Dark Web underground marketplaces, but has managed to outgrow even Silk Road in its heyday.

Silk Road's administrator, Ross Ulbricht, was recently sentenced to life in prison by a US judge, so the Agora administrators are well aware they are playing with their livelihoods, and risk more than a few years in prison, like most hackers get.

But they don't plan to go into hiding or start over again. The same statement revealed they already have a fix in mind, and are instructing users how to withdraw their money from the marketplace, hoping to make a comeback in the future, without alienating the current userbase by blocking access to their funds during their downtime.

The Agora admins statement
The Agora admins statement

Photo Gallery (2 Images)

Agora black marketplace shuts down
The Agora admins statement
Open gallery