FINDING · DEPLOYMENT

Client-puzzle DoS mitigation has been adopted in an official Tor protocol update and is in active use by several major onion services. An ethical live-network evaluation of OnionFlation attacks confirmed the vulnerability on the production Tor network, and the Tor Project has acknowledged the findings.

From 2025-lee-onions-got-puzzledOnions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion Services · Abstract · 2025 · USENIX Security 2025

Implications

Tags

defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.