The fact that this guy even posted an AMA shows that it's either entirely fake (doesn't seem it), or he's way too cocky. I suspect some trouble may be coming his way soon. He seems to think that he's infallible and that he won't catch a charge for running a botnet.
From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.
Every bit of bragging about himself makes it easier to find him. He has disclosed this information so far:
* He tried to apply for a job at Kaspersky during last year. Didn't have enough credentials and still whines about it.
* He hangs out on Anonymous IRC.
* Uses Liberty Reserve.
* Exchanges bitcoins to dollars (periodically I guess).
* May be German-speaking. Understands Russian.
Well, we can suppose all that is transmitted thru TOR and he never used any personal emails/old passwords/etc when signing up there, so that wont help us
For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.
He is using Tor, which gets a lot of criticism for not being secure but actually defeats Syrian or Chinese governments. If the US can track a hidden service in Tor, they will probably not waste this trump by catching such a small fish.
You don't need to crack Tor for that. Get the list of Germans hanging out on Anonymous IRC. Choose only college students. Remove ones that don't have time to do this stuff due to actually working somewhere. Intersect with HBCI users in banks where there aren't many of those. Remove Mac users and Linux users (he mentions he only uses Windows). Remove families that use credit cards (he mentions his family does not). This would already probably end up in reasonably short list. Now amending this list with various other bits of info he left - such as which sites he frequents, which drinks he prefers, which software he uses, etc. I don't believe it should pose any major challenge for a law enforcement agency, even if part of the info is lies - they are used to legwork and assembling small pieces. But probably with his size nobody would bother unless he does something major (i.e. catching him generates a big press-release) or he just hands himself to law enforcement by doing something stupid like drinking too much and bragging about being elite haxor criminal to a female undercover officer. If he just does it for a year and then stops, he has good chances to get away with it, but not because of mighty Tor, but because the law enforcement would never notice him.
Is something like a reddit thread enough to arrest someone then? Even the person behind the AMA is tracked down, is that evidence enough to get him in jail?
As evidence - of course not. But as means to fin out who that is - sure, why not. Once the person is identified, it is a question of good old survelliance, and they are professionals at that, so chances are the guy will make a mistake, and sooner rather than later, and the hard evidence will be there. Look what happened to LulzSec - once the person is known, if he continues to do what he does, he will lose. Even professional spies can not pull it off if identified, what to say about some college students?
It is more of an attitude that he has. He either gets out soon or he will get caught sooner or later, the longer you go with attitude like that the more proud you become, the more shortcuts you take and then one day you make one mistake too many