GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
Read original article ↗AI Summary
A critical vulnerability in GoBalance, a Go-based reimplementation of Tor's OnionBalance used by dark web sites for availability, allows attackers to recover the full private key of a .onion service from publicly available descriptors. This flaw stems from GoBalance using only the first 32 bytes of a 64-byte Tor private key during signing, effectively exposing the secret randomness used in signatures and enabling full key recovery from a single descriptor. As a result, attackers can hijack .onion addresses by creating valid descriptors for the same address, redirecting traffic to malicious sites. High-profile dark web services including Dread and Omega were confirmed compromised, with Dread attributing the incident to this flaw after initially suspecting operator error.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.