The Tor Project has implemented a significant upgrade to its relay encryption protocol, introducing the Counter Galois Onion (CGO) algorithm to replace the longstanding tor1 scheme. This change addresses several security weaknesses in the previous system, including vulnerabilities to tagging attacks, limited forward secrecy, and insufficient tamper detection. CGO introduces a 16-byte authenticator, evolving keys for each cell as it passes through relays, and a tag chaining mechanism that links the integrity of each cell to the next, making it substantially harder for attackers to compromise user anonymity or tamper with traffic undetected.
The upgrade is designed to make the Tor network more resilient against modern interception and traffic analysis attacks, thereby strengthening privacy protections for all users. The new encryption method benefits a wide range of Tor users, from activists and journalists to privacy-conscious individuals and researchers, by ensuring that even if a relay is compromised, the ability to link users to their activities or decrypt past traffic is significantly reduced. The deployment of CGO marks a major step forward in the ongoing effort to maintain Tor as a secure and anonymous communication platform.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The Tor Project started rolling out the Counter Galois Onion relay encryption algorithm for onion services and relay communications. Multiple reports described the change as a network transition to a new encryption method replacing Tor1.
The Tor Project developed a new Counter Galois Onion (CGO) relay encryption design intended to replace the older Tor1 protocol, which was described as vulnerable. This marked the technical introduction of a new encryption approach for Tor relay traffic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.