Here is the pattern that matters. In almost every well-documented case, the tools held and the person failed. Tor was not broken. Encryption was not defeated. People were undone by their own behaviour: a reused name, a real detail leaking into an anonymous space, a device seized while still signed in.
These happen to be criminal cases, because those are the ones recorded in public court documents. They appear here only to teach, because the same mistakes expose journalists, activists, whistleblowers and ordinary people who have done nothing wrong. Learn the failure, not the crime.
Case 1: Silk Road, and the trail that ran backwards
Ross Ulbricht ran Silk Road behind Tor for years, and investigators still walked a trail of breadcrumbs back to him. The breadcrumbs were all his own.
- To promote the site in its early days, he posted under the handle “altoid” on public forums, then reused that same handle in a post asking people to contact his real personal email address.
- He asked a question on a public developer forum about running a Tor hidden service, under a username that also appeared in his server’s login key.
- When arrested, he was signed in to the site as its administrator in a public library, with the evidence open in front of him.
The lesson. An operational-security trail runs in both directions. Investigators start at the activity and follow the crumbs back to the person. Every reused username, real email address and public post is a crumb. One identity must never touch another.
Ulbricht was sentenced to life imprisonment in 2015 and pardoned in January 2025. The operational lessons stand regardless of what you think of the sentence or the pardon.
Case 2: The bomb threat, and being the only person on Tor
A student emailed a bomb threat to his university to avoid sitting a final examination, using Tor together with a temporary anonymous email account. That is a technically sound combination. He was identified within a day.
- The message headers showed the threat had come through Tor. That told investigators what had been used, even though it concealed who had used it.
- To reach Tor at all, he had first signed in to the university’s wireless network, which required his real credentials. Cross-referencing showed that he was one of very few people using Tor on that network during the relevant period.
- That made him the obvious person to interview. Conventional questioning did the rest, and he admitted it.
The lesson. Using a rare tool on a small, monitored network makes you the prime suspect. Plausible deniability cuts the other way when almost nobody else on the network is doing the same thing. Tor did not fail; the surrounding circumstances did. Using a network not connected to your identity would have changed the outcome, and so would declining to answer questions.
Case 3: AlphaBay, and one email address from years earlier
Alexandre Cazes ran AlphaBay, a marketplace considerably larger than Silk Road, and was identified through a single stale identifier.
- The marketplace’s automated messages, including welcome and password-recovery emails, carried a personal email address in the header. It was an address he had used for years.
- That same address, and an old handle, appeared on forum posts going back to 2008, some of them signed with his real name, and were connected to bank and payment accounts.
- When authorities raided him, his laptop was open, unlocked and signed in to the administrator account.
The lesson. An anonymous identity is only as clean as its oldest reused detail. One email address created years earlier and carried into a new context links everything together. A genuinely separate identity shares nothing at all with your real one — no address, no handle, no password — and the device is encrypted when it is not in use.
The common threads
The same handful of failures recur across all three cases.
- Identity reuse. The same username, email address or password bridging a real identity and an anonymous one.
- Real details leaking. A genuine name, address or account slipping into a space meant to be separate.
- Standing out. Being the rare user of a security tool on a network that can see you, which flags you as the person to look at.
- Endpoint capture. These tools protect network traffic, not a device seized while it is unlocked and signed in.
- Answering questions. Ordinary interviews, not broken cryptography, closed most of these cases.
Every one of these maps directly to the habits section of Browse the web anonymously. The tools are the easy part. The discipline is the whole game.
Sources and further reading
- US Department of Justice: Ross Ulbricht sentenced (opens in a new tab)
- US Department of Justice: AlphaBay takedown (opens in a new tab)
- Tor Project: am I totally anonymous if I use Tor? (opens in a new tab)
- EFF: Surveillance Self-Defense (opens in a new tab)
These summaries are drawn from public court records and contemporaneous reporting, and appear here solely to illustrate how anonymity fails. Nothing here endorses the underlying conduct.