FINDING · EVALUATION

The OnionFlation attack family artificially inflates the required client-puzzle difficulty for all connecting clients without causing noticeable congestion at the targeted onion service, rendering any existing onion service largely unusable at an attack cost of a couple of dollars per hour.

From 2025-lee-onions-got-puzzledOnions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion Services · Abstract · 2025 · USENIX Security 2025

Implications

Tags

defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.