Skip to content
Esta página está disponible en español. Ver en español
Diese Seite ist auf Deutsch verfügbar. Auf Deutsch lesen
Cette page est disponible en français. Lire en français
Questa pagina è disponibile in italiano. Leggi in italiano
Esta página está disponível em português. Ler em português
Эта страница доступна на русском языке. Читать на русском
本页有中文版。 阅读中文版
tldlog.com

domain name news

Search
Menu
  • rss
  • glossary
  • stories
  • reading list
  • advertising
  • about
  • privacy
  • legal notice
en Language: English
  • Deutsch de diese Seite auf Deutsch
  • English en this page in English
  • Español es esta página en español
  • Français fr cette page en français
  • Italiano it questa pagina in italiano
  • Português pt esta página em português
  • Русский ru эта страница на русском
  • 中文 zh 本页的中文版
  • .featured
  • .policy
  • .gtld
  • .cctld
  • .market
  • .legal
  • .security
  • .business
  • .pricing
  • .all

10 oct 2026 22:55 .security link

originally published on 9 oct 2026

GoBalance bug lets attackers hijack Tor .onion addresses, researchers say

report an error (by email)

see your reading list

in plain words

Dark web sites use special web addresses ending in “.onion The reserved ending for Tor network services, kept outside the DNS. Full definition of .onion” that only work on the Tor privacy network. A tool called GoBalance, meant to keep these sites online during attacks, had a bug that let hackers steal the secret key controlling an address. This let attackers redirect visitors of the Dread forum and a market called Omega to fake copies of their sites, though the attackers could not access the real servers or data.

Searchlight Cyber disclosed on October 8 a flaw in GoBalance, a Go-language rewrite of Tor's Onionbalance tool bundled with the EndGame toolkit many dark-web sites use to stay online during denial-of-service attacks. The bug lets anyone recover the private key behind a .onion address using only publicly available data, then hijack the address, though not the underlying servers, database, or stored user data.

The flaw stems from how GoBalance signs the descriptor records sites publish so Tor can route visitors to them. A Tor private key is 64 bytes, but GoBalance only passed the first 32 bytes to its signing function, discarding the half that keeps each signature's secret value hidden. That omission makes the secret value a fixed, computable number, letting attackers reconstruct a site's long-term master key from a single published descriptor. Because the exposed key is permanent rather than short-lived, a recovered key can forge valid records indefinitely. Searchlight says the original Onionbalance and Tor itself are unaffected, and only GoBalance sites storing master keys in Tor's native format are exposed; GoBalance's setup tool uses a safer format by default.

The issue surfaced after both .onion addresses belonging to Dread, a major dark-web forum run by administrators HugBunter and Paris, were hijacked between October 5 and 7 and redirected to a rival site called Conclave. Paris initially blamed himself, saying he had mistakenly uploaded Dread's main private key during a GoBalance update. When Dread's separately stored backup address was also taken over two days later, HugBunter said the attacker had exploited a GoBalance vulnerability across multiple dark-web services. Searchlight agrees the second takeover points to the flaw, while treating the first as a possible separate leak. Dread has migrated to a new address, urged users to change passwords, and says its servers were not breached.

Omega, a dark-web market, confirmed on October 8 that it also moved to a new address because of the GoBalance bug. HugBunter said several other markets, including some already defunct, had addresses hijacked, without naming them.

As of October 9, The Hacker News found no CVE entry or official advisory from the Tor Project or GoBalance's maintainer. An independent researcher published an unofficial patch and proof-of-concept exploit using test keys only. Dread says it will release a patched GoBalance version. Because exposure cannot be reversed once a descriptor is published, affected operators must create new .onion addresses rather than simply patch.

Read on thehackernews.com, opens another website in a new tab

The original opens on the source's website.

tags

  • cybersecurity (tag)
  • dns-security (tag)

sponsored space

This space is available for sponsorship.

Advertising on tldlog

related

  • Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers

    link theregister.com

  • DOJ and FBI seize domains tied to alleged Chinese cyber espionage tools

    link circleid.com

  • ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover

    link icann.org

recently saved

    See the full reading list
    • rss
    • glossary
    • stories
    • reading list
    • advertising
    • about
    • privacy
    • legal notice
    • tldlog on X, opens another website in a new tab

    No cookies. No trackers.