GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
GoBalance flaw exposes .onion addresses, allowing attackers to hijack them using public information and Tor keys.
Intelligence analysis by Qwen 2.5 (3B)

A bug in GoBalance, a tool used by dark web sites, lets attackers hijack .onion addresses by recovering Tor-format keys, potentially exposing sites to takeover.
A bug in a tool used by dark web sites lets attackers find out the secret key that controls a site's hidden address. They can then take over the address and redirect visitors to their own site.
Analysis
{"heading_1":"How the Flaw Works","paragraph_1":"For site operators, a patch alone does not undo the exposure. Once a descriptor has been published, the key it leaks cannot be pulled back. A site that ran a vulnerable version has to create a new .onion address and move to it.","paragraph_2":"For users of a site that may be affected, Dread's advice was to change their password on the affected site and on other sites that may be affected, and to treat the old address as unsafe. Confirm any new address through a signed announcement before trusting it.","paragraph_3":"The flaw affects sites whose master key is stored in Tor's own key format. Sites running GoBalance in a safer format are not at risk.","heading_2":"Which Sites Are at Risk","heading_3":"What Operators and Users Should Do"}
Key points
- GoBalance flaw exposes .onion addresses to potential hijacking
- The flaw affects sites whose master key is stored in Tor's own key format
- Users should change their passwords on affected sites and on other sites that may be affected
- Site operators should create a new .onion address and move to it
- No official fix is available yet
Once a site moves to a new address, the risk of exposure is reduced, and users can change their passwords to protect themselves.
If the flaw is not patched, sites could continue to be exposed, and users could still be at risk of having their data compromised.



