GoBalance bug lets attackers hijack Tor .onion addresses, researchers say
in plain words
Dark web sites use special web addresses ending in “.onion The reserved ending for Tor network services, kept outside the DNS. Full definition of .onion” that only work on the Tor privacy network. A tool called GoBalance, meant to keep these sites online during attacks, had a bug that let hackers steal the secret key controlling an address. This let attackers redirect visitors of the Dread forum and a market called Omega to fake copies of their sites, though the attackers could not access the real servers or data.
Searchlight Cyber disclosed on October 8 a flaw in GoBalance, a Go-language rewrite of Tor's Onionbalance tool bundled with the EndGame toolkit many dark-web sites use to stay online during denial-of-service attacks. The bug lets anyone recover the private key behind a .onion address using only publicly available data, then hijack the address, though not the underlying servers, database, or stored user data.
The flaw stems from how GoBalance signs the descriptor records sites publish so Tor can route visitors to them. A Tor private key is 64 bytes, but GoBalance only passed the first 32 bytes to its signing function, discarding the half that keeps each signature's secret value hidden. That omission makes the secret value a fixed, computable number, letting attackers reconstruct a site's long-term master key from a single published descriptor. Because the exposed key is permanent rather than short-lived, a recovered key can forge valid records indefinitely. Searchlight says the original Onionbalance and Tor itself are unaffected, and only GoBalance sites storing master keys in Tor's native format are exposed; GoBalance's setup tool uses a safer format by default.
The issue surfaced after both .onion addresses belonging to Dread, a major dark-web forum run by administrators HugBunter and Paris, were hijacked between October 5 and 7 and redirected to a rival site called Conclave. Paris initially blamed himself, saying he had mistakenly uploaded Dread's main private key during a GoBalance update. When Dread's separately stored backup address was also taken over two days later, HugBunter said the attacker had exploited a GoBalance vulnerability across multiple dark-web services. Searchlight agrees the second takeover points to the flaw, while treating the first as a possible separate leak. Dread has migrated to a new address, urged users to change passwords, and says its servers were not breached.
Omega, a dark-web market, confirmed on October 8 that it also moved to a new address because of the GoBalance bug. HugBunter said several other markets, including some already defunct, had addresses hijacked, without naming them.
As of October 9, The Hacker News found no CVE entry or official advisory from the Tor Project or GoBalance's maintainer. An independent researcher published an unofficial patch and proof-of-concept exploit using test keys only. Dread says it will release a patched GoBalance version. Because exposure cannot be reversed once a descriptor is published, affected operators must create new .onion addresses rather than simply patch.