GoBalance signing bug lets anyone recover a dark-web site's .onion master key from its public descriptor: Searchlight Cyber links it to the takeover of both Dread forum addresses; no fix or CVE yet
Searchlight Cyber disclosed on 8 October 2026 a flaw in GoBalance, a Go rewrite of Tor's Onionbalance load balancer that ships with the EndGame anti-DDoS toolkit used by many dark-web sites. A Tor ed25519 private key is 64 bytes, but GoBalance passed only the first 32 bytes to the signer, dropping the half that keeps each signature's secret nonce hidden; the nonce becomes computable, so one published service descriptor is enough to recover the site's long-term master key and sign valid descriptors for its .onion address. Taking over the address lets an attacker redirect visitors to a copy of the site, but does not give access to its servers or data. Only sites whose master key is stored in Tor's own key format are exposed; keys written by GoBalance's setup tool use a safer format, and the original Onionbalance and Tor itself are not affected. Between 5 and 7 October both onion addresses of the Dread forum were hijacked and pointed at a rival site, Conclave; Searchlight says the second takeover is the stronger sign the flaw was used, while the first may have been a separate key leak. Dread has moved to a new address, and the Omega market said on 8 October that it also moved because of the bug. There was no official fix or CVE as of 9 October; a community patch has been published. For defenders and investigators, the lesson is that onion addresses seen in threat intelligence can change hands without the original operators. Primary: Searchlight Cyber; wire: The Hacker News.
- Product
- GoBalance (Go Onionbalance rewrite, bundled with EndGame) — onion service descriptor signing
- Versions
- GoBalance with master keys stored in Tor key format; no fixed release yet
- Exploited in Australia?
- unknown
- Patch to
- Operators: stop using Tor-format master keys with GoBalance and rotate to a new address. Threat-intel teams: treat onion addresses for Dread and other EndGame-fronted sites seen before 8 Oct as possibly attacker-controlled and re-verify them.
Primary: Searchlight Cyber — Leaking the keys to the kingdom: how a single slip handed over a darknet empire (8 Oct 2026) · The Hacker News — GoBalance flaw lets attackers hijack .onion addresses by recovering Tor-format keys (9 Oct 2026)
