Searchlight Cyber disclosed a critical flaw in GoBalance, a tool widely used by dark-web sites to maintain availability during attacks. The vulnerability permits an attacker to deduce the secret key controlling a site's .onion address from publicly available information. This key recovery allows attackers to redirect visitors to a malicious replica of the site, though it does not grant access to the site's backend servers or user data.
An .onion address is essentially a public key, with control residing with the holder of the corresponding private key. GoBalance signs a descriptor, a public record fetched by Tor network participants. The flaw occurs during this signing process: GoBalance incorrectly passes only the first 32 bytes of a 64-byte Tor private key to the signer, omitting the portion that secures the signature's secret value. This omission makes the secret value computable, allowing a single published descriptor to reveal the site's long-term master private key without server access.
GoBalance is a Go-language rewrite of Tor's Onionbalance load balancer and is included in the EndGame toolkit, which helps dark web sites resist denial-of-service attacks. The vulnerability is specific to this rewrite; the original Onionbalance and Tor itself are not affected. Only sites whose master key is stored in Tor's native key format are at risk. GoBalance's setup tool generates keys in a different, secure format, meaning not all GoBalance users are exposed.
The flaw's existence was highlighted by the takeover of Dread, a prominent dark web forum. Between October 5 and 7, both of Dread's .onion addresses were redirected to a rival site, Conclave. Initially, Dread's operators attributed the incident to an accidental key upload. However, after a second address was compromised, they concluded that an attacker had exploited the GoBalance flaw.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A vulnerability in GoBalance, a tool used by dark-web sites for resilience, allows attackers to recover a site's .onion address private key using only public information. This flaw enables redirection of site visitors to attacker-controlled copies, impacting sites that store their master key in Tor's specific key format.