← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

GoBalance Flaw Allows .onion Address Hijacking via Tor-Format Key Recovery

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GoBalance flaw exposes .onion address private keys.
  • Attackers can redirect site traffic to their own servers.
  • Vulnerability affects sites using Tor's key format with GoBalance.
  • The original Onionbalance and Tor are not affected.

GoBalance Vulnerability Disclosed

Searchlight Cyber disclosed a critical flaw in GoBalance, a tool widely used by dark-web sites to maintain availability during attacks. The vulnerability permits an attacker to deduce the secret key controlling a site's .onion address from publicly available information. This key recovery allows attackers to redirect visitors to a malicious replica of the site, though it does not grant access to the site's backend servers or user data.

Technical Details of the Flaw

An .onion address is essentially a public key, with control residing with the holder of the corresponding private key. GoBalance signs a descriptor, a public record fetched by Tor network participants. The flaw occurs during this signing process: GoBalance incorrectly passes only the first 32 bytes of a 64-byte Tor private key to the signer, omitting the portion that secures the signature's secret value. This omission makes the secret value computable, allowing a single published descriptor to reveal the site's long-term master private key without server access.

Affected Systems and Scope

GoBalance is a Go-language rewrite of Tor's Onionbalance load balancer and is included in the EndGame toolkit, which helps dark web sites resist denial-of-service attacks. The vulnerability is specific to this rewrite; the original Onionbalance and Tor itself are not affected. Only sites whose master key is stored in Tor's native key format are at risk. GoBalance's setup tool generates keys in a different, secure format, meaning not all GoBalance users are exposed.

Real-World Exploitation on Dread

The flaw's existence was highlighted by the takeover of Dread, a prominent dark web forum. Between October 5 and 7, both of Dread's .onion addresses were redirected to a rival site, Conclave. Initially, Dread's operators attributed the incident to an accidental key upload. However, after a second address was compromised, they concluded that an attacker had exploited the GoBalance flaw.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 09

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A vulnerability in GoBalance, a tool used by dark-web sites for resilience, allows attackers to recover a site's .onion address private key using only public information. This flaw enables redirection of site visitors to attacker-controlled copies, impacting sites that store their master key in Tor's specific key format.