1. The agent randomly (?) stumbling on a LinkedIn profile which matched the timeline/description of the Silkroad project, which prompted to seek another unidentified agent which had all kinds of juicy deets on the suspect.
2. CBP intercepted a package addressed to Ulbright containing a bunch of counterfeit official documents during a "routine border search".
3. Found Tor/PHP/curl-related posts on Stackoverflow from his real name account, but also says he changed his name/email to a fake one. Did they happen to stumble on it before he changed his name? Or had some kind of access to an earlier archive? Or cooperation from Stackoverflow? Unclear.
I'll update more as I run into them. Super interesting read.
Still, it's clear that they've done a ton of research on Silkroad and DPR. The notes are thorough and accurate. A job well done.