I think the easiest attack on SR would not be one of the attacks mentioned in the article (although similar to their second attack, but focused on legal implications instead of fraud), but rather:
a. Law enforcement creates a large number of vendor and customer accounts. Due to the pseudonymity, they can create as many as they like and they can't be linked (they may need to create them over time to avoid making the pattern too obvious).
b. The fake customer accounts buy from the fake vendor accounts and leave positive comments, building up a reputation for the fake vendors. This would give money to the operators of SR for fees, but aside from fees there would be no loss for the operators.
c. Eventually, the number of fake vendors could be sufficient that it makes up most of the volume of SR.
d. The fake customers buy from some real vendors and claim that the goods never arrived or that they got arrested and it looks like the vendor tipped the police off.
e. Any real customer who buys from a fake vendor gets their details sent to their local police.
f. Most vendors, real and fake, accumulate comments saying that they tipped people off to the police, with no way to tell which vendors are real vendors with mostly genuine good feedback and a few forged complaints of being police run, and which have a few real complaints of being police run and mostly forged good feedback.
g. Police forces issue press releases announcing how many people they have caught buying things on SR, and buying becomes a highly risky proposition.