- Searchlight Cyber says GoBalance hands its signer half a Tor key. For sites storing the key in Tor's native format, one public record reveals the master key.
- Searchlight judges the flaw the likelier cause of Dread losing its second address. Both Searchlight and Dread's founder say the first address was lost through a different event, a leaked key.
- When a trusted tool is rewritten, ask what protections the original gave quietly. Then test that the copy still gives them.
A rewrite can keep the features and lose the guarantee
Here is the lesson. In GoBalance, the part of the code that signs with a Tor-format key assumed it had received an already-expanded 64-byte key. It received only 32 bytes. The tool still ran, but the guarantee was gone.
Searchlight Cyber found this in GoBalance. Darknet sites use it to share traffic across several servers. The researchers say anyone can work out a vulnerable site's master signing key from records the site already publishes. Whoever has that key can steal the site's .onion address and steer its visitors to a server of their choice.
What happened to Dread
Dread is a well-known darknet forum. Between October 5 and 7, both of its .onion addresses were hijacked and pointed at a rival site, Conclave.
The first loss came with a human explanation. Co-administrator Paris said he had "stupidly uploaded dread's main onion private key into a gobalance update." Founder HugBunter published a report that backed this account.
The second address was a backup reserved for premium members. It fell too. One careless upload can leak one key. It is hard to see how it leaks two.
Searchlight therefore calls the GoBalance flaw the likelier cause for the second address. It does not claim the same for the first. For that address, Searchlight keeps the leaked-key explanation and sees the loss as a different event.
After the backup address was recovered, HugBunter changed course. He said an attacker had exploited a previously unknown GoBalance weakness against several darknet services. For the main address, he held to the leaked-key account.
Dread has moved to a new address and asked users to change their passwords. The operators say their servers were not broken into.
How the flaw works
An .onion name is built from a public key. The matching private key is what proves who owns it. Whoever holds that private key can speak for the address.
To be found, a site posts a signed notice that says how to reach it. Tor calls this a descriptor. Anyone on the network can download it. GoBalance does the signing.
A Tor private key is 64 bytes. It has two halves. One is the secret number used to sign. The other keeps the random ingredient of each signature hidden. Picture a lock that needs two keys while the signer is handed one.
GoBalance called a Go function that returns only the first 32 bytes. For Tor-format keys, that discarded the second half. The random ingredient became one fixed number that anyone can calculate.
A signature stays safe only while that ingredient is secret. With it known, a single unknown is left: the secret signing number. An attacker downloads one public descriptor and solves for it. A reversible step using public values then gives the master key.
This is a master key, not a short-lived one. So the attacker can sign valid descriptors for any future period. Searchlight says the attacker could redirect visitors, or show a copy of the site to capture logins or intercept traffic.
Limits of the flaw
The attacker gains the address, not the machines behind it. Alone, the flaw does not open a site's servers, database or stored user data. Getting user data would take another step, such as phishing or intercepting traffic.
The bug sits only in the Go rewrite. The original OnionBalance and Tor are untouched.
Only sites that keep their master key in Tor's native file format are exposed. The Hacker News reports that GoBalance's own setup tool writes a different, safe format. Some GoBalance sites are therefore not at risk.
The scale is unclear. HugBunter said several markets lost addresses, some already shut down, but named none. One market, Omega, has confirmed it publicly. A note it signed on October 8 blames the GoBalance bug for retiring its old address.
HugBunter also said AI helped find the flaw. That claim is unverified. Attackers said they held Dread's database but gave no evidence. HugBunter said a man-in-the-middle attack could not be fully ruled out. That is why users were told to change passwords.
Questions for your team
The victims here are on the darknet. The pattern is not. Companies port, fork and rewrite software for speed, language or licensing. Each rewrite can drop a duty the old code performed silently.
Ask your security team which security tools in your stack are re-implementations of another tool. Ask who checked that key handling matches the original, not just the features. Ask whether long-lived master keys can be replaced, because a recovered master key can sign valid records for any future period.
Ask how quickly you would hear of a problem like this. On October 9 there was no official fix and no CVE. A researcher outside the project had already released a fix of their own. They also published working code that recovers a master key from one public descriptor. Dread said it would release a patched version. Your response plan cannot wait for a catalogue entry.
A copy that works is not a copy that protects. The half of the key nobody saw was the half that mattered.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Searchlight Cyber.





