# GoBalance flaw exposes keys that control vulnerable Tor site addresses

_Published Friday, October 9, 2026 at 6:12 AM EDT · Security · Latest · Tier 2 — Notable_

![GoBalance flaw exposes keys that control vulnerable Tor site addresses — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUJ8xcgqF85kQru4JEuCv6OipwHlff6IEp3r1zhFOY9tYpbwEeWYSqzPTILX4uqM97Cc9ZfNfb3HB4lZbecN48fqKgKryAL60KqqZU4HmdfTMsRYaDcFjNL7aE8vk7G0D_-mqY_B2Jk_3kXMsx2ABpgbWixg1GHZ2l7V0MSzqtEWnYZ_ymkOTf0j8yq2c/s1700-nu-rw-lo-l85-e365/onion.jpg)

Searchlight Cyber disclosed a GoBalance flaw on October 8 that lets attackers recover the key controlling a vulnerable site's .onion address from public information, The Hacker News reports. Attackers can redirect visitors to a site they control, but address takeover does not give them access to the original servers or stored data.

GoBalance drops half of a Tor-format private key when signing a public address record, making the remaining signature sufficient to recover the long-term master key. Only sites using that key format are affected; Tor and the original Onionbalance are unaffected.

There is no official fix. Operators whose keys were exposed must create new addresses because patching cannot revoke a recovered key.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html)

---
Canonical: https://techandbusiness.org/newswire/J_5W0WOnbMcdmRHdBftv-o
Published: 2026-10-09T10:12:11.560Z
Story chronology: 2026-10-08T00:00:00.000Z
Retrieved: 2026-10-09T12:13:58.180Z
Publisher: Tech & Business (techandbusiness.org)
