Protections against directory authority/Tor Project collusion/compromise.

It seems to me that there are very few directory authorities, and those that there are are hardcoded into all clients by the Tor Project. What is stopping them from colluding to serve a sufficient number of malicious relays for the purpose of deanonymising users?

Doesn’t this mean users have to trust the dir auths or at least the Tor Project like one would a VPN company? Albeit it’s harder to deanonymise someone that way versus just taking logs and looking them up, but it is still a single point of failure.

In addition, has there been any research done on concentration of client devs? Tor clients seem pretty concentrated, with only one third-party developer that I can think of (the Guardian Project).

Contrast I2P, which has a P2P protocol. But also a similar number of developers of mature clients (Java I2P, I2P+, and I2Pd).

Has anyone thought about and addressed this issue before? I can’t imagine it hasn’t come up but I couldn’t find a topic.