A security flaw in GoBalance, a widely used tool for keeping dark-web services online during denial-of-service attacks, has let at least one attacker hijack .onion addresses by recovering their underlying private keys.
What happened
GoBalance is a Go rewrite of Tor's Onionbalance load-balancing toolkit, bundled with the anti-DDoS suite EndGame. Researchers at Searchlight Cyber disclosed on October 8 that the rewrite handles Tor's signing keys incorrectly: a Tor .onion private key is 64 bytes long, but GoBalance only passes the first 32 bytes to its signing process, silently dropping the second half — the portion meant to keep each signature's secret value hidden.
Without that missing half, the secret value collapses into a number anyone can compute. That means a single signed descriptor — the record every .onion site publishes so Tor clients can find it — carries enough information for an attacker to reconstruct the site's full private key. Because that key is the site's permanent identity, not a short-lived session key, recovering it lets an attacker forge valid address records indefinitely, long after the original compromise.
With the key in hand, an attacker can redirect a site's visitors to a lookalike .onion address they control. Searchlight and Tor's original Onionbalance project stress this does not grant access to the real site's servers, database, or stored user data — it hijacks the address, not the backend. Only deployments where the master key sits in Tor's own key format are exposed; GoBalance's own setup tool writes keys in a safer format and is not affected, so not every GoBalance deployment is at risk.
The clearest casualty so far is Dread, one of the largest dark-web discussion forums. Between October 5 and 7, both of its published .onion addresses were taken over and pointed to a rival site. Operators first described the takeover as a mistake — administrator Paris said a private key had been accidentally included in a GoBalance update — but the second takeover, of a backup address reserved for paid members, is harder to explain as human error. Searchlight and Dread's own team now treat it as evidence the GoBalance flaw was exploited. Dread has since moved to a new address, told users to change their passwords, and said its servers were not breached. A dark-web marketplace, Omega, has separately confirmed it moved to a new address after the same bug took its old one offline. Dread's operators say other services may be affected but have not published a count.
Why it matters
There is no CVE entry and no official patch yet from the Tor Project or GoBalance's maintainer. An independent researcher has already published a working proof-of-concept that recovers a master key from a single descriptor, using only test keys — a sign the technique is well understood and could be reproduced by others before a fix ships. Because leaked descriptors are public and permanent, patching the signing bug does not undo an exposure that has already happened: once a key has been recoverable from a published descriptor, it has to be treated as compromised for good.
What to do
- Operators running GoBalance: assume any master key stored in Tor's native key format is compromised. Generate a new .onion address and migrate, as Dread and Omega did — a patch alone won't restore a leaked key.
- Check your key storage format before assuming you're safe; only the native Tor key format is affected, not GoBalance's own setup-tool format.
- Users of affected dark-web services: change your password, treat old .onion addresses as unsafe, and verify any new address only through a signed announcement from the operator before trusting it.
- Watch for an official advisory from the Tor Project or GoBalance's maintainer and apply it once a patched version is available — but treat it as forward-looking protection, not a fix for keys already exposed.
