Full Report
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.
Analysis Summary
# Vulnerability: GoBalance Ed25519 Private Key Recovery and Onion Address Hijacking
## CVE Details
- **CVE ID:** Not yet assigned (Disclosed Oct 8, 2026)
- **CVSS Score:** N/A (Estimated Critical/High)
- **CWE:** CWE-327: Use of a Broken or Risky Cryptographic Algorithm / CWE-310: Cryptographic Issues
## Affected Systems
- **Products:** GoBalance (a Go-based load balancer for Tor hidden services).
- **Versions:** All versions prior to October 8, 2026; specifically those bundled with the **EndGame** toolkit.
- **Configurations:** Hidden services using GoBalance where the master private key is stored in **Tor’s native key format**. (Note: Keys generated via GoBalance’s internal setup tool are reportedly in a safer format and may not be affected).
## Vulnerability Description
The flaw resides in the Ed25519 signing implementation within GoBalance. A standard Tor private key is 64 bytes long. During the process of signing a service descriptor (the record that tells the Tor network how to reach a site), GoBalance incorrectly passed only the first 32 bytes of the private key to the signer, discarding the remaining 32 bytes.
In Ed25519, the discarded half contains the prefix used to hide the secret deterministic value of each signature. Without this prefix, the secret value becomes a fixed, computable number. By analyzing a single publicly available signed descriptor, an attacker can mathematically derive the hidden service's master private key.
## Exploitation
- **Status:** **Exploited in the wild.** Used to hijack the "Dread" forum and "Omega" market. A PoC is also available on GitHub.
- **Complexity:** Low (Key recovery is automated once the descriptor is fetched).
- **Attack Vector:** Network (Publicly accessible via the Tor network).
## Impact
- **Confidentiality:** Low (Does not grant access to backend servers or databases).
- **Integrity:** **High** (Attackers can redirect site visitors to a malicious clone or phishing site).
- **Availability:** **High** (The legitimate operator loses control over the .onion address).
## Remediation
### Patches
- **Official Patch:** None currently available from the GoBalance maintainers or the Tor Project as of October 9, 2026.
- **Community Patch:** An independent researcher has released an unofficial patch at `https[:]//github[.]com/kolmteistov/gobalance-patch`. (Use with caution).
### Workarounds
- **Key Migration:** Affected operators must generate a new .onion address and migrate users, as the old master keys are permanently compromised.
- **Format Change:** Ensure master keys are not stored in the specific Tor-format exposed by this bug, though migration to a new key is the only way to guarantee security for hijacked addresses.
## Detection
- **Indicators of Compromise:** Unexpected redirection of .onion traffic to different introduction points or mirrors not controlled by the owner.
- **Detection Methods:** Check if the site's public descriptor has been modified or if the private key matches the vulnerable 32-byte signing pattern. Searchlight Cyber and other dark-web monitoring tools can identify if a site's address has been redirected.
## References
- **Searchlight Cyber Research:** `https[:]//www[.]slcyber[.]io/research/leaking-the-keys-to-the-kingdom-how-a-single-slip-handed-over-a-darknet-empire`
- **Proof-of-Concept/Unofficial Patch:** `https[:]//github[.]com/kolmteistov/gobalance-patch`
- **Tor Project Address Spec:** `https[:]//spec[.]torproject[.]org/address-spec[.]html`