Close Menu
NCIJ Network NCIJ Network
    What's Hot

    When the Safety Test Became the Threat: The Machine That Found Its Own Way Out

    October 10, 2026

    Bitcoin Core Developer Responds To AI & Quantum Risk

    October 10, 2026

    Crackdown reveals ‘industrial-scale’ wildlife and timber trafficking across Latin America

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • When the Safety Test Became the Threat: The Machine That Found Its Own Way Out
    • Bitcoin Core Developer Responds To AI & Quantum Risk
    • Crackdown reveals ‘industrial-scale’ wildlife and timber trafficking across Latin America
    • Real Madrid beat Villarreal 1-0 but Vinicius sent off for hair pull | Football
    • Why David Ellison thinks he can win at Warner Bros.
    • GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
    • Ledger Warns Buyers Not To Set Up Wallets From Reseller
    • MIT astronomers catch a star in a feast that could last billions of years
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site’s .onion address using only public information, and then take that address over.

    Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site’s visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site’s servers, database, or stored user data.

    How the Flaw Works

    An .onion address is really a public key, so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record.

    The flaw is in the signing step. A Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that keeps each signature’s secret value hidden.

    Without that half, the secret value becomes a fixed number anyone can compute. A single published descriptor then carries enough to recover the site’s private key, with no access to its servers.

    Cybersecurity

    Because the exposed key is the site’s long-term master key, not a short-lived one, a recovered key can sign valid records for the address far into the future.

    Which Sites Are at Risk

    GoBalance is a version of Tor’s Onionbalance load balancer rewritten in Go, and it ships with EndGame, a widely used toolkit that keeps dark web sites online during denial-of-service attacks. The flaw is in the rewrite.

    Searchlight says the original Onionbalance and Tor itself are not affected.

    It also affects only sites whose master key is stored in Tor’s own key format. GoBalance’s setup tool writes keys in a safer format that is not at risk, so not every site running GoBalance is exposed.

    The Dread Takeover

    The flaw came to light through Dread, one of the dark web’s biggest forums, run by administrators who go by HugBunter and Paris. Between October 5 and 7, both of Dread’s .onion addresses were taken over and pointed at a rival site, Conclave.

    Dread’s operators first blamed their own mistake. On October 5, Paris said he had “stupidly uploaded dread’s main onion private key into a gobalance update.”

    Two days later the second address, a backup kept for premium members, was taken over as well. A backup is harder to explain as a slip, and HugBunter then said the attacker had used a GoBalance flaw against several dark-web services. Searchlight takes the same view, calling the second takeover the stronger sign the flaw was used, while still treating the first address as a separate key leak.

    Dread has since moved to a new address and told users to change their passwords. In a signed message on October 7, the operators said the forum had “migrated, permanently, following onion private key exposure due to a vulnerability in third-party software,” and that “other hidden services may be affected.” They say Dread’s servers were not broken into.

    Who Else Is Affected

    How many other sites are affected is not clear. HugBunter said several dark-web markets had their addresses taken over, including some that had already shut down, but did not name them or give a number.

    At least one other site has confirmed it publicly. Omega, a dark-web market, said in a signed note on October 8 that it took its old address offline “due to an issue caused by the GoBalance bug” and moved to a new one.

    Cybersecurity

    No Official Fix Yet

    There is no official fix. On October 9, The Hacker News found no CVE identifier for the flaw in the US National Vulnerability Database and no public advisory from the Tor Project or GoBalance’s maintainer. Dread has said it plans to release a patched version of GoBalance and help affected sites move across.

    An independent researcher has published a patch and a working proof-of-concept that recovers a master key from a single public descriptor. The researcher says the demonstration used only keys made for the test and that no real service was targeted. The Hacker News has not run the code, and it is not an official release.

    What Operators and Users Should Do

    For site operators, a patch alone does not undo the exposure. Once a descriptor has been published, the key it leaks cannot be pulled back, so a site that ran a vulnerable version has to create a new .onion address and move to it, as Dread and Omega have done.

    For users of a site that may be affected, Dread’s advice was to change your password on it and on other sites that may be affected, and to treat the old address as unsafe. Confirm any new address through a signed announcement before trusting it.

    addresses Attackers Flaw GoBalance hijack keys lets Onion Recovering TorFormat
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    US Disrupts Chinese State-Sponsored Hacking Tools

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

    ARTEX AI, Claude agents used in cyberattacks on South Korean banks

    Cyber exec arrested in case allegedly tied to ShinyHunters hackers

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    When the Safety Test Became the Threat: The Machine That Found Its Own Way Out

    October 10, 2026

    Bitcoin Core Developer Responds To AI & Quantum Risk

    October 10, 2026

    Crackdown reveals ‘industrial-scale’ wildlife and timber trafficking across Latin America

    October 10, 2026

    Real Madrid beat Villarreal 1-0 but Vinicius sent off for hair pull | Football

    October 10, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    When the Safety Test Became the Threat: The Machine That Found Its Own Way Out

    October 10, 2026

    Bitcoin Core Developer Responds To AI & Quantum Risk

    October 10, 2026

    Crackdown reveals ‘industrial-scale’ wildlife and timber trafficking across Latin America

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.