Flaw in GoBalance Tool Lets Attackers Take Over Dark Web Site Addresses
Researchers at Searchlight Cyber have disclosed a flaw in GoBalance, a tool many dark web sites use to stay reachable during attacks. The bug lets anyone work out the secret key controlling a site's .onion address using only public information, then take that address over. An attacker who does so can send visitors to a copy of the site they control. It does not give them access to the real site's servers, database or stored user data.
The problem lies in how GoBalance signs the public record that lets others find a site on the Tor network. A Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is what keeps each signature's secret value hidden. Without it, a single published record carries enough to recover the site's long-term master key, which could then be used to sign valid records far into the future.
GoBalance is a Go rewrite of Tor's Onionbalance and ships with the EndGame toolkit. Searchlight says the original Onionbalance and Tor itself are not affected, and only sites storing their master key in Tor's own key format are exposed. The flaw surfaced after both of the Dread forum's .onion addresses were taken over between October 5 and 7 and pointed at a rival site, Conclave. Dread's operators first blamed their own mistake.