When the vpn company is subpoenaed because someone saw suspicious traffic coming out of their servers, regardless of the number of people, the logs and connections would point directly to you.
Edit: I must stress I'm not an expert, and would love to hear if the above is wrong.
Incredibly difficult to pinpoint you as the responsible party - but that information could certainly be outputting virtually anywhere, depending on the exit node.
But of course, if you aren't using TLS then your traffic is not encrypted as it leaves the pipe. So obviously you should use TLS over Tor.
If you read the original paper the researchers spell out the weaknesses, many of which were made in the name of performance over security.
Also, when I said doesn't work, I only meant that it's not an acceptable alternative to VPNs.