Skip to main content
CybersecurityHacking

GoBalance Flaw Exposes Dark Web Sites to Hijacking

Rack-mounted equipment and cables fill a dimly lit server room with rows of patch panels.

"stupidly uploaded dread's main onion private key into a gobalance update," said Paris.

How the flaw works: a 64‑byte key and a dropped half

The vulnerability lies in GoBalance’s signing step for .onion service descriptors. In Tor, an .onion address is a public key and control of the matching private key grants control of the address. A site publishes a signed descriptor that anyone on the Tor network can fetch; GoBalance signs that record for some dark-web sites.

Searchlight Cyber, which disclosed the flaw on October 8, reported the technical root cause: a Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half contains the part that keeps each signature’s secret value hidden; without it the secret value becomes a fixed number anyone can compute. A single published descriptor therefore carries enough information to recover the site’s private key, with no access to its servers.

The exposure is severe because the leaked material is the site's long‑term master key, not a short‑lived signing key. Once recovered, that master key can be used to sign valid descriptors far into the future.

Dread takeover and the Conclave redirect, October 5–7

The bug surfaced publicly in a high‑profile incident on the dark web. Between October 5 and 7, both of Dread’s .onion addresses were taken over and pointed at a rival site called Conclave. Dread is run by administrators who use the names HugBunter and Paris.

On October 5 Paris initially blamed operator error with the statement quoted above. When a second, backup address was taken over two days later — a backup kept for premium members — HugBunter said the attacker had used a GoBalance flaw against several dark‑web services. Searchlight Cyber described the second takeover as the stronger sign that the coding flaw was used, while still treating the first address as a separate key leak.

Dread said its servers were not broken into, moved to a new address, and told users to change passwords. In a signed message on October 7 Dread stated it had "migrated, permanently, following onion private key exposure due to a vulnerability in third-party software," and warned that "other hidden services may be affected."

Which sites are at risk: GoBalance, EndGame, and file formats

GoBalance is a Go rewrite of Tor’s Onionbalance load balancer and ships with EndGame, a toolkit used to keep dark‑web sites online during denial‑of‑service attacks. Searchlight said the flaw is in the rewrite; the original Onionbalance and Tor itself are not affected.

The vulnerability applies only to services whose master key is stored in Tor’s native key format and processed by the flawed signing path. GoBalance’s setup tool can write keys in a safer format that is not at risk, so not every installation of GoBalance exposes a service. How many sites used the vulnerable key format is not known.

At least one other site publicly confirmed impact: Omega, a dark‑web market, said in a signed note on October 8 that it took its old address offline "due to an issue caused by the GoBalance bug" and moved to a new one. HugBunter said several dark‑web markets had their addresses taken over but did not name them or give a number.

No official fix yet; independent patch and proof‑of‑concept

As of October 9 there was no official fix published. The Hacker News reported it found no CVE identifier for the flaw in the U.S. National Vulnerability Database and no public advisory from the Tor Project or GoBalance’s maintainer. Dread said it plans to release a patched version of GoBalance and help affected sites migrate.

An independent researcher has published a patch and a working proof‑of‑concept that recovers a master key from a single public descriptor. The researcher said the demonstration used only keys created for the test and that no real service was targeted. The Hacker News has not executed the code, and the researcher’s release is not an official remediation.

How site operators, users, and maintainers are responding

  • Site operators and dark‑web forum administrators: Operators that ran a vulnerable version must assume any published descriptor has permanently exposed their master key and therefore must create a new .onion address and move to it — a step Dread and Omega have already taken.
  • End users of affected services: Dread advised users to change passwords on the forum and on other sites that may be affected, to treat the old address as unsafe, and to confirm any new address via a signed announcement before trusting it.
  • Maintainers, researchers, and third‑party tool authors: Searchlight Cyber disclosed the flaw; an independent researcher released a patch and proof‑of‑concept; Dread said it will ship a patched GoBalance. The Tor Project and GoBalance’s maintainer had made no public advisory as of October 9, according to The Hacker News.

The immediate technical lesson is stark and immutable: once a descriptor that leaks a master key is published, the key cannot be retracted. For services that depend on the secrecy of that key, the practical remedy is replacement of the .onion address and careful verification of any new address through signed messages — steps several of the affected operators have already taken.

Original story