GoBalance flaw enables recovery of Tor .onion service keys

A cryptographic flaw in GoBalance can allow an attacker to recover the long-term private key controlling a Tor hidden service’s .onion address from a single publicly available descriptor. Searchlight Cyber disclosed the issue on October 8, and says a recovered key can be used to publish valid records that redirect visitors to a site controlled by the attacker.
The problem was highlighted after Dread, a major dark-web forum operated by administrators known as HugBunter and Paris, lost control of two .onion addresses between October 5 and 7. Both addresses were pointed to Conclave, a rival site. Dread later migrated to a new address and urged users to change their passwords.
A signing error exposes the master key
Tor hidden-service addresses are public keys, and control rests with the holder of the corresponding private key. Services publish signed descriptors that Tor clients can retrieve. GoBalance, a Go rewrite of Tor’s Onionbalance load balancer, signs those descriptors when it is used to keep services reachable during denial-of-service attacks.
A Tor private key is 64 bytes long, but GoBalance supplied only the first 32 bytes to the signing operation. The remaining bytes normally keep the per-signature secret value hidden. Their omission makes that value fixed and computable, leaving one published descriptor sufficient to derive the service’s private key.
The key at risk is the long-term master key rather than a temporary credential. Consequently, someone who derives it can create valid descriptors for that address into the future. The takeover changes where visitors are directed; it does not, by itself, provide access to the victim’s servers, database, or stored user information.
Scope depends on deployment and key format
GoBalance is distributed with EndGame, a toolkit used by dark-web services seeking resilience against denial-of-service attacks. Searchlight Cyber says the defect is in the Go rewrite: Tor itself and the original Onionbalance implementation are not affected.
Exposure is also not universal among GoBalance users. It applies to deployments whose master keys are stored in Tor’s native key format. GoBalance’s setup utility creates keys in a safer format, so sites created through that path are not affected by this specific issue.
Dread initially attributed the first incident to an apparent key upload error, but the takeover of its backup address two days later led its operators to say a GoBalance weakness had been used against several services. Searchlight Cyber regards the second incident as the stronger indication of exploitation while treating the first address as a separate key leak. Omega, another dark-web market, said on October 8 that it had taken its former address offline because of the bug and moved to a new one.
Migration is required after exposure
As of October 9, no CVE identifier, public advisory from the Tor Project or GoBalance maintainer, or official fix had been identified. Dread said it intended to release a patched GoBalance version and assist affected services with migration. An independent researcher has released a patch and a proof of concept, although it is not an official release and was not tested by The Hacker News.
For operators, applying a patch cannot reverse publication of a vulnerable descriptor. Affected services must generate a new .onion address and move users to it, as Dread and Omega have done. Users should regard an old affected address as unsafe, confirm a replacement through a signed announcement, and change passwords on the affected service and other potentially affected sites.
The practical business implication is that teams operating hidden services should identify GoBalance deployments and their key formats promptly, then plan a verified address migration wherever vulnerable descriptors may have been published.

