GoBalance Bug Exposes .onion Addresses to High-Risk Hijack

Attackers have uncovered and used a serious vulnerability in GoBalance—a load-balancing tool many Tor dark-web sites deploy to remain reachable during denial-of-service assaults—that allows full takeover of.onion addresses by reconstructing private keys from public data. While attackers can’t access backend servers or data directly, control of an.onion address lets them reroute visitors to a malicious copy of the site. This critical flaw was exposed by cybersecurity firm Searchlight Cyber on October 8.

What’s Going Wrong Under the Hood

In Tor’s hidden-services system, each.onion address is backed by a public-key/private-key pair. Operator control over the private key grants authority over the address. To facilitate load balancing and uptime, GoBalance publishes a signed descriptor derived from this key material that Tor clients fetch. But the bug lives in how GoBalance signs that descriptor. Instead of supplying the full 64-byte Tor private key to signing routines, GoBalance provides only the first 32 bytes, discarding the latter half.

Dropping the second half of the key leaks part of the structure that keeps each signature’s secret value hidden. With enough information exposed via just one public descriptor, attackers can compute the private key. From then on, they can generate valid descriptors indefinitely and hijack the.onion address going forward.

Which Sites Are Vulnerable, and Real-World Consequences

GoBalance is a re-implementation in Go of Onionbalance, a component often bundled—especially in the EndGame toolkit—to help dark web sites stay online under stress. The vulnerability exists in GoBalance’s rewrite, not in Onionbalance or Tor itself.

Still, not every site using GoBalance is at risk. Sites that use Tor’s standard key format are vulnerable; those using GoBalance’s own “safer format” are not. That means exposure depends on how the private key was stored.

The issue came into harsh relief after Dread—a major dark-web forum—had two of its.onion addresses seized between October 5-7. The first takeover followed an accidental upload of Dread’s primary onion private key during a GoBalance update; the second involved their backup address, pointing strongly toward exploitation of the GoBalance flaw rather than mere human error.

After the events, Dread switched to a new address and urged users to reset passwords. The forum confirmed no servers or databases were breached, only the.onion addresses were compromised. Other dark-web services have reported similar fallout, including Omega market, which also decommissioned an old address after encountering the GoBalance issue.

Status of a Fix & Guidance for Operators and Users

As of October 9, there’s no official fix from either the Tor Project or GoBalance’s maintainers. No CVE identifier has been assigned yet. An independent researcher has, however, released a proof-of-concept recovery tool and patch; though it worked with test keys and has not been verified in production.

Because once a vulnerable descriptor is published the private key is irreversibly exposed, operators must generate entirely new.onion addresses. That’s the only way to secure access moving forward. For users, it’s crucial to treat old addresses as compromised—reset passwords and verify any new addresses via signed announcements before trusting them.

This vulnerability signals a deeper issue: the fragility of key formats and implementation details in cryptographic systems. Overlooking how tools carry or store private key material can lead to total loss of control. As more tools adopt re-implemented or rewritten cryptographic components, ensuring spec-correct key handling is non-negotiable. The GoBalance bug may become a cautionary tale for developers and dark-web operators alike—what at first appears a small implementation shortcut ends up opening the door for complete domain takeover.