Hacker Factor has a series of articles about various attacks on Tor: https://www.hackerfactor.com/blog/index.php?/archives/868-De... The tor daemon really needs to be re-written and audited. Apparently the codebase right now is a huge mess.
Just assume any one of their servers were vulnerable to RCE attacks, they hosted dynamic web sites on conventional web hosting stacks! These things leak deanonymizing information like a sieve.