GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
AI-summarised brief · reviewed before publication
A flaw in GoBalance, a Go rewrite of Tor’s Onionbalance used by dark‑web sites to stay online during attacks, allows attackers to recover a site’s long‑term private key from a single public descriptor. The bug stems from truncating the 64‑byte key to 32 bytes during signing, exposing the key’s secret half. Searchlight Cyber disclosed the issue on October 8 after Dread’s .onion addresses were hijacked. The vulnerability does not affect Tor itself or sites using safer key formats, but affected sites must change addresses and users should reset passwords.
💡 Why It Matters
- · The flaw exposes the core identity of hidden services, enabling persistent takeover without server access.
- · It forces operators to abandon compromised addresses, disrupting anonymity and trust in the dark web ecosystem.