A vulnerability in GoBalance, a Go rewrite of Tor's Onionbalance load balancer, can let an attacker recover the private key behind a dark-web site's .onion address using only public information. Searchlight Cyber disclosed the flaw on October 8, saying a recovered key lets an attacker redirect visitors to a copy of the site they control, though it does not grant access to the site's servers or databases.
The bug is in how GoBalance signs Tor descriptors. A Tor private key is 64 bytes, but GoBalance passes only the first 32 bytes to the signer, dropping the half that keeps each signature's secret value hidden. That makes the secret value a fixed, computable number, so a single published descriptor is enough to recover the site's long-term master key. The original Onionbalance and Tor itself are not affected, and sites whose keys are stored in GoBalance's safer setup format are also not exposed.
The flaw came to light after Dread, a major dark-web forum, had both of its .onion addresses taken over between October 5 and 7 and pointed at a rival site. Dread's operators first blamed their own key leak, but later said the attacker used a GoBalance flaw against several dark-web services. Searchlight agrees, calling the second takeover the stronger sign the flaw was used. At least one other site, the market Omega, confirmed it moved to a new address because of the bug.
There is no official fix yet, and no CVE has been published. An independent researcher has released a patch and a proof-of-concept that recovers a master key from a single descriptor, but it is not an official release. Because a published descriptor cannot be unpublished, operators of vulnerable sites must create a new .onion address and migrate, as Dread and Omega have done. Users should change passwords on affected sites and verify new addresses through signed announcements.