thehackernews.com 9 Oct 2026, 09:03 UTC

GoBalance Flaw Lets Attackers Hijack Dark Web Sites’ .onion Addresses

A security flaw in GoBalance, a Go-based version of Onionbalance used by many dark‑web sites to stay reachable during attacks, could let attackers hijack a site’s .onion address. The flaw arises during the signing of the descriptor that binds a public onion address to its private key. GoBalance only passed the first 32 bytes of a Tor Ed25519 private key (64 bytes total) to the signer, discarding the remaining half.

With the missing portion, the secret value becomes computable, enabling an attacker to recover the site’s private key from a single published descriptor and then redirect visitors to a rival site. Taking over the address does not grant access to the site’s servers or user data, but it lets the attacker sign valid records for the address in perpetuity because the key is long‑term.

The bug affects GoBalance’s rewrite of Onionbalance and its inclusion in EndGame, used to keep dark‑web sites online during attacks. Onionbalance and Tor itself are not reported as affected. The extent of compromised sites is unclear, though Dread—the large dark‑web forum—had both of its .onion addresses taken over in early October, with others including the Omega market also confirming disruptions.

There is currently no official fix or CVE, though a patched GoBalance version is being prepared and a published patch and proof‑of‑concept exist on GitHub. For operators, a cure is not enough: once a descriptor is published, the leaked key cannot be pulled back, so affected sites must move to a new .onion address; users are advised to treat the old address as unsafe and verify new addresses via signed announcements.

View full article

Article by CyberSIXT