A Critical Flaw in Tor’s Onion Routing System Leaves .onion Addresses Vulnerable to Hijacking
A severe security vulnerability has been discovered in the way Tor, a popular anonymizing browser, handles its onion routing system. The flaw, which affects all versions of Tor prior to 2.4.17-rc, allows attackers to hijack .onion addresses and potentially access sensitive information. This is not just a theoretical risk – thousands of users are already exposed.
The issue lies in the way Tor generates and stores “Tor-format keys,” which are essentially digital fingerprints used to identify .onion sites. When a user accesses an onion site, their browser requests the site’s Tor-format key from its associated server. Normally, this process is secure, but due to a weakness in Tor’s handling of these keys, attackers can recover them even if they don’t have the necessary permissions.
The implications are significant: any website with a .onion address may be compromised, and sensitive information could potentially be accessed by unauthorized parties. According to estimates, over 10,000 websites use .onion addresses, many of which likely host critical infrastructure or store valuable data. Moreover, this vulnerability affects not just individual sites but also the broader Tor network as a whole.
To understand why this flaw matters, it’s essential to grasp how onion routing works. Essentially, when you access an onion site via Tor, your internet traffic is routed through multiple nodes before reaching its final destination. This process obscures both your IP address and the location of the site itself. However, if an attacker can recover a .onion site’s Tor-format key, they can essentially “own” that website – allowing them to intercept or modify data exchanged between users.
The vulnerability has been disclosed to the Tor Project and is currently being addressed in version 2.4.17-rc of the browser. In the meantime, users are advised to exercise extreme caution when accessing .onion sites until a patch is widely available. For those concerned about their site’s security, it’s recommended to implement additional measures such as using secure protocols (HTTPS) and enabling two-factor authentication to limit potential damage.
To mitigate this risk, CyberNews.work advises readers who access or manage .onion sites to review their Tor configurations immediately. This includes keeping the browser up-to-date with the latest patches and implementing robust security measures on both the server-side and client-side.
Source: The Hacker News — 2026-10-09