The Onion-Service Directory Lost Over a Third of Its Capacity — and Has Only Partly Got It Back

By 1AEO Team • July 29, 2026 • HSDir relays in every hourly network consensus • Public CollecTor data, Jun 14 – Jul 27

Every .onion address depends on a set of relays most people have never heard of: the HSDirs (onion-service directories). They hold the descriptors that must be fetched before any connection to an onion service can be made — no HSDir lookup, no connection. The flag has a demanding entry requirement: roughly 96 hours of continuous, stable uptime. That makes the HSDir population the first thing the network loses when relays get unstable, and the slowest to come back. During the ongoing DoS wave it has been among the hardest-hit pieces of shared infrastructure visible in public data.

Three Steps Down, Then a Cliff #

Time-series chart of relays holding the HSDir flag in each hourly Tor network consensus, June 14 to July 27 2026, from public CollecTor data. A pre-attack plateau of 5,609 to 5,892 relays through June 21, then a fall after the June 25 23:00 UTC flood-onset line to a wave-1 trough of 3,075 on June 30, then a depressed plateau of roughly 3,500 to 3,700, then a crash to 1,780 on July 12 and a deeper collapse to 945 on July 22 with an hourly minimum of 917 at 09:00 UTC, the lowest reading in the May 1 to July 27 window parsed. From July 23 the count recovers unevenly, dipping to about 2,550 on July 24 and 25 before reaching 3,749 on July 26 and 3,640 on July 27, still about 37 percent below the plateau. Annotations mark 728 non-1AEO relays that lost the flag without restarting, 1AEO's planned July 11 maintenance restart, excluded from attack attribution, and the July 20 change in the number of voting directory authorities from seven to nine.

Before the flood, the HSDir count sat on a plateau of 5,609–5,892 relays (Jun 15–21). Wave 1 knocked it to 3,075 on June 30; between the waves it settled around 3,500–3,700 and never climbed back; the crash of July 9–13 drove the hourly count to 1,780 (Jul 12, 20:00 UTC — an hourly minimum; that day's 12:00 UTC consensus read 1,942). That was not the floor. July 20–22 went lower still — 1,662 on July 20, 1,688 on July 21, then 945 on July 22, each below the 1,942 the same 12:00 UTC series showed at the July 12 trough. July 22's hourly minimum was 917 (09:00 UTC): the lowest reading anywhere in the three months of consensuses we parsed, and roughly one HSDir left for every six the network had in June. One caveat on comparing the two troughs: they were measured under different numbers of voting directory authorities (see How We Measured).

Part of the July 11–14 depth is ours, not the attack's: our planned maintenance restart that day zeroed 1AEO's HSDirs for about four days while they re-earned the 96-hour requirement, and we exclude it from attribution.

Then It Came Back — Most of the Way #

On July 23 the directory refilled about as fast as it had emptied: in the 05:00 UTC consensus the count jumped from 2,038 to 3,490 — 1,478 relays gained the flag in a single hour, and two-thirds of them had held it four days earlier, so this was mass re-flagging of relays the authorities had stripped, not fresh qualification. It has stayed in that range since, unevenly — 3,502 (Jul 23), a dip to 2,548 and 2,612, then 3,749 (Jul 26) and 3,640 (Jul 27). The last full day was not flat: the count slid from 3,806 at 08:00 UTC to 3,416 at 23:00 UTC. That is back to roughly its July 16 level and 62.9% of the pre-attack plateau (3,640 against the 5,787 mean of the seven Jun 15–21 readings): the deep-erosion phase is over, and the directory is still about 37% smaller than it was in June.

The turn began on July 22, while the July 19–24 directory-write surge was at its peak — the timing rules out the surge's end as the trigger, and we have not identified the mechanism. 1AEO's own HSDir count moved in step with the network's — 116 relays on July 22, 711 on July 23, 516 on July 27, and 340 to 707 across that same 05:00 UTC hour with no restart of ours 96 hours earlier — which rules out a 1AEO-side artifact in either direction: collapse and recovery were both network-wide.

728 Relays Stripped Without Restarting #

The cleanest fingerprint in the consensus data: during the July 9–13 crash, 728 non-1AEO relays lost the HSDir flag without restarting — their median uptime was 15.5 days when the flag disappeared. These relays did not go down. They stayed up under load, flapped in and out of the directory authorities' reachability probes, and the authorities stripped the flag from machines too busy to answer the door. It is not a voting artifact either — the number of directory authorities voting stayed constant at seven through the July 9–13 crash.

What It Means for Onion Services #

The descriptor keyspace doesn't shrink when HSDirs disappear — it just gets divided among fewer relays. The chart below tracks that on one convention throughout: non-1AEO directories on both sides of the ratio, so none of our own restarts can move the line. From the flood's onset the load climbed to a sustained ~1.7x that never recovered between waves; at the July 12 trough each surviving directory carried 2.85x its normal share of the keyspace; and on July 22 it peaked at 6.3x (an hourly extreme, 09:00 UTC; 6.1x in that day's 12:00 UTC consensus). As of the July 27 12:00 UTC consensus it is back to about 1.6x, and 1.7x by that day's last hour. That concentration lands on machines already under the same flood; we saw the receiving end first-hand, with our own relays' descriptor caches hitting their limits by late June (see the anatomy post's HSDir-cache section).

Time-series chart, June 17 to July 27, 2026, showing the load on each surviving onion-service directory relative to its pre-attack keyspace share, computed as non-1AEO count over non-1AEO count with a baseline of 5,066, the median non-1AEO HSDir count for June 17 to 24, so 1AEO's own restarts do not affect the line. Flat at 1x before the June 25 flood onset, a sustained plateau around 1.7x through early July, 2.85x at the July 12 trough, a peak of 6.3x at the hourly extreme of 09:00 UTC on July 22, and easing to about 1.6x at the July 27 12:00 UTC consensus, 1.7x by that day's last hour.

As of July 29 the population is still short of its pre-attack plateau, and the flood's original circuit-rejection mode is still running. The 96-hour rule that makes the flag meaningful also makes recovery slow: every burst of instability resets the clock.

How We Measured #

All of it is public and reproducible: Tor's hourly network consensuses from CollecTor, counting the relays holding the HSDir flag in each consensus, June 14 – July 27. Daily figures are the 12:00 UTC consensus; where a number is an hourly extreme we say so. The "three months" comparison covers May 1 – July 27 (May's hourly minimum was 3,977). The 728-relay figure compares consecutive consensuses and relay-reported uptimes to find non-1AEO relays that lost the flag without a restart. The load line uses a single convention: the pre-attack median non-1AEO count (June 17–24, 5,066) divided by the non-1AEO count in each hourly consensus — a broader baseline (the non-1AEO June 1–24 median, 4,475) is equally defensible and would scale every multiple by 0.88x. The 62.9% is baseline-sensitive in the same way: measured against the wider June 1–24 hourly median (5,028 relays) the July 27 count is about 28% short rather than 37%.

One caveat on comparing the two troughs: the number of directory authorities voting was seven from July 9 to July 20 16:00 UTC (with two single-hour dips to six), and eight or nine from July 20 17:00 UTC onward as two authorities rejoined — nine from 20:00 UTC that day. The HSDir flag needs a majority of the authorities voting, so the July 22 reading was taken under a stricter threshold than the July 12 one, and part of the gap between them is that change rather than the flood. The hour-by-hour moves do not line up with the rejoin hours, so this is a comparability limit, not evidence that the second collapse was an artifact.

Caveats: because the flag requires ~96 hours of continuous uptime, the count lags — it understates instability as it happens and recovers days after conditions improve. Two 1AEO restarts have to be handled, and neither is attack damage: the July 11 maintenance restart excluded above, and a fleet-wide service restart on July 28 that reset the uptime clock and has zeroed our HSDir flag since — our Running-relay count stayed flat across it and no relays dropped out, which is the discriminator. Both charts end at July 27 23:00 UTC, the last complete day in the archive.

Related reading: The Tor Network Is Under a Circuit-Building DoS Wave — the network-wide view from Tor's public data.  Anatomy of the Attack — including our first-party view of HSDir descriptor caches being pruned at their limits.

Join the Mission