Afaik a lot of Tor endpoints are actually run by the NSA / secret services. "If people try to use encrypted services they must seek to hide something"
But fortunately, even if what you're saying was true you're still safe! Endpoint alone can't tell much about the origin of the connection :)
The Tor client tries to take this into account when choosing entry and exit nodes, but it has to consider other threats as well and there's a limit to how well it can do. Remember the adversary only has to get lucky once to discover that you are a member of the Rebel Alliance and a traitor; you have to evade them every time.
Ross Anderson calls this "programming Satan's computer". It's like you have an NFA that always chooses the worst state transition rather than the correct one.