On July 4 2014 Tor Team discovered a group of malicious relays that they assume were trying to deanonymize Tor Network users with confirmation attack technique. 115 malicious fast non-exit relays (6.4% of whole Tor network) were involved in the attack, the servers were actively monitoring the relays on both ends of a Tor circuit in an effort to de-anonymize users. Bad actors were targeting relays to track users accessing Tor networks or access Tor hidden services.”]
Source: http://securityaffairs.co/wordpress/27193/hacking/attacks-against-tor-network.html

