Every .onion address depends on a set of relays most people have never heard of: the HSDirs (onion-service directories). They hold the descriptors that must be fetched before any connection to an onion service can be made — no HSDir lookup, no connection. The flag has a demanding entry requirement: roughly 96 hours of continuous, stable uptime. That makes the HSDir population the first thing the network loses when relays get unstable, and the slowest to come back. During the ongoing DoS wave it has been among the hardest-hit pieces of shared infrastructure visible in public data.
Before the flood, the HSDir count sat on a plateau of 5,609–5,892 relays (Jun 15–21). Wave 1 knocked it to 3,075 on June 30; between the waves it settled around 3,500–3,700 and never climbed back; the crash of July 9–13 drove the hourly count to 1,780 (Jul 12, 20:00 UTC — an hourly minimum; that day's 12:00 UTC consensus read 1,942). That was not the floor. July 20–22 went lower still — 1,662 on July 20, 1,688 on July 21, then 945 on July 22, each below the 1,942 the same 12:00 UTC series showed at the July 12 trough. July 22's hourly minimum was 917 (09:00 UTC): the lowest reading anywhere in the three months of consensuses we parsed, and roughly one HSDir left for every six the network had in June. One caveat on comparing the two troughs: they were measured under different numbers of voting directory authorities (see How We Measured).
Part of the July 11–14 depth is ours, not the attack's: our planned maintenance restart that day zeroed 1AEO's HSDirs for about four days while they re-earned the 96-hour requirement, and we exclude it from attribution.
On July 23 the directory refilled about as fast as it had emptied: in the 05:00 UTC consensus the count jumped from 2,038 to 3,490 — 1,478 relays gained the flag in a single hour, and two-thirds of them had held it four days earlier, so this was mass re-flagging of relays the authorities had stripped, not fresh qualification. It has stayed in that range since, unevenly — 3,502 (Jul 23), a dip to 2,548 and 2,612, then 3,749 (Jul 26) and 3,640 (Jul 27). The last full day was not flat: the count slid from 3,806 at 08:00 UTC to 3,416 at 23:00 UTC. That is back to roughly its July 16 level and 62.9% of the pre-attack plateau (3,640 against the 5,787 mean of the seven Jun 15–21 readings): the deep-erosion phase is over, and the directory is still about 37% smaller than it was in June.
The turn began on July 22, while the July 19–24 directory-write surge was at its peak — the timing rules out the surge's end as the trigger, and we have not identified the mechanism. 1AEO's own HSDir count moved in step with the network's — 116 relays on July 22, 711 on July 23, 516 on July 27, and 340 to 707 across that same 05:00 UTC hour with no restart of ours 96 hours earlier — which rules out a 1AEO-side artifact in either direction: collapse and recovery were both network-wide.
The cleanest fingerprint in the consensus data: during the July 9–13 crash, 728 non-1AEO relays lost the HSDir flag without restarting — their median uptime was 15.5 days when the flag disappeared. These relays did not go down. They stayed up under load, flapped in and out of the directory authorities' reachability probes, and the authorities stripped the flag from machines too busy to answer the door. It is not a voting artifact either — the number of directory authorities voting stayed constant at seven through the July 9–13 crash.
The descriptor keyspace doesn't shrink when HSDirs disappear — it just gets divided among fewer relays. The chart below tracks that on one convention throughout: non-1AEO directories on both sides of the ratio, so none of our own restarts can move the line. From the flood's onset the load climbed to a sustained ~1.7x that never recovered between waves; at the July 12 trough each surviving directory carried 2.85x its normal share of the keyspace; and on July 22 it peaked at 6.3x (an hourly extreme, 09:00 UTC; 6.1x in that day's 12:00 UTC consensus). As of the July 27 12:00 UTC consensus it is back to about 1.6x, and 1.7x by that day's last hour. That concentration lands on machines already under the same flood; we saw the receiving end first-hand, with our own relays' descriptor caches hitting their limits by late June (see the anatomy post's HSDir-cache section).
As of July 29 the population is still short of its pre-attack plateau, and the flood's original circuit-rejection mode is still running. The 96-hour rule that makes the flag meaningful also makes recovery slow: every burst of instability resets the clock.
All of it is public and reproducible: Tor's hourly network consensuses from CollecTor, counting the relays holding the HSDir flag in each consensus, June 14 – July 27. Daily figures are the 12:00 UTC consensus; where a number is an hourly extreme we say so. The "three months" comparison covers May 1 – July 27 (May's hourly minimum was 3,977). The 728-relay figure compares consecutive consensuses and relay-reported uptimes to find non-1AEO relays that lost the flag without a restart. The load line uses a single convention: the pre-attack median non-1AEO count (June 17–24, 5,066) divided by the non-1AEO count in each hourly consensus — a broader baseline (the non-1AEO June 1–24 median, 4,475) is equally defensible and would scale every multiple by 0.88x. The 62.9% is baseline-sensitive in the same way: measured against the wider June 1–24 hourly median (5,028 relays) the July 27 count is about 28% short rather than 37%.
One caveat on comparing the two troughs: the number of directory authorities voting was seven from July 9 to July 20 16:00 UTC (with two single-hour dips to six), and eight or nine from July 20 17:00 UTC onward as two authorities rejoined — nine from 20:00 UTC that day. The HSDir flag needs a majority of the authorities voting, so the July 22 reading was taken under a stricter threshold than the July 12 one, and part of the gap between them is that change rather than the flood. The hour-by-hour moves do not line up with the rejoin hours, so this is a comparability limit, not evidence that the second collapse was an artifact.
Caveats: because the flag requires ~96 hours of continuous uptime, the count lags — it understates instability as it happens and recovers days after conditions improve. Two 1AEO restarts have to be handled, and neither is attack damage: the July 11 maintenance restart excluded above, and a fleet-wide service restart on July 28 that reset the uptime clock and has zeroed our HSDir flag since — our Running-relay count stayed flat across it and no relays dropped out, which is the discriminator. Both charts end at July 27 23:00 UTC, the last complete day in the archive.
Related reading: The Tor Network Is Under a Circuit-Building DoS Wave — the network-wide view from Tor's public data. Anatomy of the Attack — including our first-party view of HSDir descriptor caches being pruned at their limits.