I've studied Tor vulnerabilities for two years. I'm seeing signs of traffic confirmation (active), traffic confirmation (passive), stream watermarking, and a massive willingness to shape control of the network with DoS. Just about every attack on hidden services (active and passive), of which I am aware, was deployed, all at once. The malformed packet DoS was especially clever. And I'm sure a ton more were used that never made it to the academic research.
It was almost comical, like the star ship captain saying "now on my mark, fire all photon torpedoes!" They just revealed a massive amount of capability to send a message: Tor is not safe. They want everyone to know that despite that sticker on Snowden's laptop, Tor remains vulnerable.
But what remains interesting, and glaringly obviously absent, is user identification. The NSA does not appear to be able to deanonymize users at will. That is, given enough time and enough resources, they can ID hidden services and long-term users, but given an arbitrary Tor exit and and TCP stream, they can't simply follow it back to its origin.
A for effort. But in organizaton it looks like a military campaign, not a cyber attack. Straight out of the "total dominance" playbook.
But of course it won't work. Tor isn't a country. Its an idea. You can't force the Internet to "submit."
All this did was make blindingly obvious holes that many researchers have been asking to be fixed for a while.