Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

The Hacker News by The Hacker News
October 9, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site’s .onion address using only public information, and then take that address over.

Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site’s visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site’s servers, database, or stored user data.

How the Flaw Works

An .onion address is really a public key, so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record.

The flaw is in the signing step. A Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that keeps each signature’s secret value hidden.

Without that half, the secret value becomes a fixed number anyone can compute. A single published descriptor then carries enough to recover the site’s private key, with no access to its servers.

Because the exposed key is the site’s long-term master key, not a short-lived one, a recovered key can sign valid records for the address far into the future.

Which Sites Are at Risk

GoBalance is a version of Tor’s Onionbalance load balancer rewritten in Go, and it ships with EndGame, a widely used toolkit that keeps dark web sites online during denial-of-service attacks. The flaw is in the rewrite.

Searchlight says the original Onionbalance and Tor itself are not affected.

It also affects only sites whose master key is stored in Tor’s own key format. GoBalance’s setup tool writes keys in a safer format that is not at risk, so not every site running GoBalance is exposed.

The Dread Takeover

The flaw came to light through Dread, one of the dark web’s biggest forums, run by administrators who go by HugBunter and Paris. Between October 5 and 7, both of Dread’s .onion addresses were taken over and pointed at a rival site, Conclave.

Dread’s operators first blamed their own mistake. On October 5, Paris said he had “stupidly uploaded dread’s main onion private key into a gobalance update.”

Two days later the second address, a backup kept for premium members, was taken over as well. A backup is harder to explain as a slip, and HugBunter then said the attacker had used a GoBalance flaw against several dark-web services. Searchlight takes the same view, calling the second takeover the stronger sign the flaw was used, while still treating the first address as a separate key leak.

Dread has since moved to a new address and told users to change their passwords. In a signed message on October 7, the operators said the forum had “migrated, permanently, following onion private key exposure due to a vulnerability in third-party software,” and that “other hidden services may be affected.” They say Dread’s servers were not broken into.

Who Else Is Affected

How many other sites are affected is not clear. HugBunter said several dark-web markets had their addresses taken over, including some that had already shut down, but did not name them or give a number.

At least one other site has confirmed it publicly. Omega, a dark-web market, said in a signed note on October 8 that it took its old address offline “due to an issue caused by the GoBalance bug” and moved to a new one.

No Official Fix Yet

There is no official fix. On October 9, The Hacker News found no CVE identifier for the flaw in the US National Vulnerability Database and no public advisory from the Tor Project or GoBalance’s maintainer. Dread has said it plans to release a patched version of GoBalance and help affected sites move across.

An independent researcher has published a patch and a working proof-of-concept that recovers a master key from a single public descriptor. The researcher says the demonstration used only keys made for the test and that no real service was targeted. The Hacker News has not run the code, and it is not an official release.

What Operators and Users Should Do

For site operators, a patch alone does not undo the exposure. Once a descriptor has been published, the key it leaks cannot be pulled back, so a site that ran a vulnerable version has to create a new .onion address and move to it, as Dread and Omega have done.

For users of a site that may be affected, Dread’s advice was to change your password on it and on other sites that may be affected, and to treat the old address as unsafe. Confirm any new address through a signed announcement before trusting it.



Source link

The Hacker News

The Hacker News

Next Post

Even ‘Law & Order’ Is Terrified of AI

Recommended.

North Korea-Linked Hackers Steal .02 Billion in 2025, Leading Global Crypto Theft

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

December 18, 2025
Groove Technology Solutions Receives DIRECTV HOSPITALITY Dealer Dedication Award

Groove Technology Solutions Receives DIRECTV HOSPITALITY Dealer Dedication Award

July 17, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio