One of the biggest links from the Silkroad owner's identity outside of tor was the fact that he promoted his own site in the early days, using an alias he had used to ask questions on stackoverflow. He probably didn't realise how important good OPSEC was until much later in the game.
I recently had the chance to help the FBI in an effort to catch a child abuser in collaboration with an NGO. It was very interesting to see how "techies" can piece together a scary level of detail about someone's identity using everyday things like the clothes they wear (if they bought them online) or how their house is decorated. Details of how were withheld from us, but the suspect got caught.
The flip side to this problem is that anyone with any notion of security is practically immune. With so many easy targets out there, the hard targets go untouched year after year.
I was once given some wise advice. If you've ever knowingly done something wrong, never tell anyone else, and never admit to it. Your mouth is your worst enemy.
TL;DR - you can never be too paranoid, so long as the overhead doesn't impact your operations. if it does, you need to take a deep look into your risk appetites.
Some of these people are serving jail time because their nicks were in a useless text file next to the pirated movies presenting them as proud members of a group (and hopefully with some ascii art).
This is not a mistake, it's pure stupidity...