Hacking website which uses gorilla/securecookie

“security tool to encode/decode Golang web-frameworks client-side session cookie which use gorilla/secure-cookie or gorilla/sessions, such as Gin, Echo or Iris”

lots of Go web framework using client site session cookie in the official component, such as Gin, Echo, Iris.
hack via secret key leaked