[1] https://www.theverge.com/2013/12/18/5224130/fbi-agents-track...
[1] https://www.theverge.com/2013/12/18/5224130/fbi-agents-track...
Then they noticed that "that the originating IP address would have been revealed in the email header, which would have indicated Tor usage"
And from there "agents checked to see if anyone had accessed Tor through the local wireless networks. That led them to <culprit>, who promptly confessed."
Doesn't sound like they even had to engage with Tor infrastructure or Guerrilla Mail backends, just 'hmmm did a student use Tor, oh some did, let's check them out in full FBI livery' which freaked the kid out and he confessed.
It's easy to check if an IP is a Tor exit node, but unless you happen to also have egress logs it's still a thornier problem to de-anonymize without heavy resources.
It's an easy problem if you control the majority of the nodes. All it takes is throttling traffic on an exit node and watching which inbound traffic is affected. It is cheap for the US to fund the operation of all Tor nodes in return for the massive intelligence boost it offers.
However FBI tracing bomb-threat is probably still not using NSA-level resources... given the whole not our citizens wink wink thing.
Intercepting encrypted domestic communication is fair game as far as the TLAs are concerned. They also always have the option of routing domestic traffic outside the country to make it "foreign origin".
To me, comparing tor's privacy features against normal VPN is like comparing a jet plane to a tricycle