A lot of "hacker" mentality projects involve putting a tremendous amount of effort into something with questionable utility.
People climb mountains because they're there.
>Let's say I as a private individual
Pay people on Fiverr to set them up for you at different ISPs so that all the setup information is different. You can use crypto to pay if you want anonimity (this is actually the main reason I used to use bitcoin - I'd pay ISPs in Iceland to run TOR exit nodes for me without linking them to my identity).
This isn't a difficult problem. A single individual with a good job could do it.
And sure, each connection only has a very small chance of being found, but aggregate it over a year or two and you could catch half of the users of a site if they connected with a new circuit one time per day.
I honestly can't see why a nation state or two hasn't already done this.
With insignificant data caps. To get the data needed I believe you're looking at a couple hundred a month, to start.
Not speaking to the effectiveness of the detection (it's hard!), but there's information available, for example:
https://blog.torproject.org/malicious-relays-health-tor-netw...
https://gitlab.torproject.org/tpo/network-health/team/-/wiki...
https://gitlab.torproject.org/tpo/network-health/team/-/wiki...
They don't have plausible evidence to subpoena the guard node if a middle node only sees encrypted traffic. They would also need to control the exit nodes which communicate with the target's host or they simply control the host as a honeypot.
Ad hominem: your username spells out MIB, Men in Black, surely you are joking.
All Tor hosts use a small set of "guard" nodes as their first hops, because it's considered that directly connecting to a compromised node immediately reveals your IP address, in most cases. Using a small set of first hops reduces the probability that at least one of them is compromised. In older versions of Tor, the middle node is completely random, which means sometimes it is compromised. The German government is thought to have used statistical methods to identify when their compromised node was the middle node, and log the address of the node before it - the guard node. Then, they used legal methods to sniff the traffic on the guard node to find the server's IP address.
In newer versions of Tor, this is more difficult because onion servers use two layers of guard nodes - they use a small infrequently-rotated set of entry guard nodes, and a larger more-frequently-rotated set of middle guard nodes, and the third is still random.