Also the case if they are missing a few nodes in the middle, as long as they control the entrance, exit, and never miss two in a row.
This isn't possible. Your tor daemon fetches the consensus from a directory server and picks the relays and exits itself.
The directory server can't tamper with that consensus because its signed by the directory authorities, a small set of servers that are necessary because of this attack.
What has always surprised me is that someone hasn't tried to install Tor nodes into compromised IoT devices, etc. If a virus is installing millions of nodes in the wild, that might be enough to keep the network majority non-attacker. As it stands, NSA or China, or whoever just ends up buying the whole network.
That would be enough to get thousands of nodes. (And probably a bit less illegal, although still not legal)
If you had the skill to compromise the devices with a tor node. Won't you use that node in your own private "tor" network, instead of sharing it with the wild?
Servers on the tor network aren't some magical machines. They sit in the same datacenter as any other server, and all their traffic reaches them via the internet. Controlling the nodes connected to them should give you a pretty good idea of at least the magnitude of traffic they're seeing. And even without running any nodes, attacking blocks of IPs suspected to include the service while measuring any potential impact on its latency allows you find their public IP (given enough resources and/or time). Then, there's the attack of try
If you're going to do illegal things, or want anonymity, remain on the network - domains ending with .onion. The regular web is inherently not anonymous.