During the course of this investigation, the FBI has located a
number of computer servers, both in the United States and in
multiple foreign countries, associated with the operation of Silk
Road. In particular, the FBI has located in a certain foreign
country the server used to host Silk Road's website (the "Silk
Road Web Server"). Pursuant to a Mutual Legal Assistance Treaty
Request, an image of the Silk Road Web Server was made on or
about July 23, 2013 and produced thereafter to the FBI.
This server image seems to have been the source of a lot of the evidence leading to the arrest warrant: the IP logs that matched his location, an account name that matched his StackOverflow account, and of course all the private messages and chat logs regarding his personal location (messages indicating Pacific time), operation of the site (payments to other admins), and the extortion attempt/attempted hit.What the complaint doesn't specify is how the FBI managed to locate the Silk Road server. It's possible that they already had some suspicion of DPR's identity, and managed to bug his computers or otherwise track his activity well enough to figure out what systems he was logging into. But given how coy the complaint is about this, I wonder if in fact this is the result of a sophisticated analysis of Tor network traffic (possibly in collaboration with the NSA?). If that's the case, it betrays a level of capability that ought to be frightening for the operators of other anonymous Tor services. Anyone with more Tor expertise want to comment on how likely this is?
Edit: the excerpt quoted is from the (now unsealed) FBI complaint, first linked elsewhere in this thread: http://krebsonsecurity.com/wp-content/uploads/2013/10/Ulbric.... The whole thing is pretty interesting reading.