- Alby warned of a critical flaw in Alby Hub versions v1.7.0 through v1.18.5 that could let attackers take over wallets and send funds
- The flaw only affects Hubs reachable from the internet; one user has been affected so far
- Versions v1.19.0 and later are not affected; Alby recommends updating to v1.24.0
- Alby has not disclosed the flaw’s details yet but plans to publish them later
- Documentation changes now warn users against exposing the Hub to the public internet
Bitcoin wallet company Alby has warned of a critical flaw in its self-hosted Lightning wallet, Alby Hub, that could allow an attacker to seize control and drain funds. The flaw affects versions v1.7.0 through v1.18.5, all released before August 2025, and only if the Hub is reachable from the internet.
Alby confirmed one user has been affected but did not disclose whether funds were lost. Versions v1.19.0 and later are not vulnerable, with the fix arriving on August 29, 2025.
The company advises users on older builds to block external access to the Hub’s management interface and update to v1.24.0. Technical details of the vulnerability remain undisclosed, though Alby plans to publish them later under responsible disclosure guidelines.
Alby Hub is designed for private networks, and the project’s documentation now warns against public exposure. A documentation change merged on September 7 acknowledged that setup guides had inaccurately described the server as running on localhost when it actually listens on all network interfaces.
Alby‘s DigitalOcean guide instructs users to keep the server’s public address enabled. Its Hetzner guide shows creating a firewall rule for port 8080 open to any address.
This marks the second known incident involving an exposed Hub. In November 2025, Alby said a user’s Hub was emptied after being left publicly reachable without an unlock password. Following that case, a change to Umbrel’s app placed Alby Hub behind Umbrel’s own login.
Alby has not clarified whether updating alone removes an attacker’s existing access. Users whose Hub ran an affected version while exposed should change their unlock password after updating.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- UK crime agency: Criminals use crypto to launder at scale
- Iran eases currency rules to bypass US sanctions with crypto
- CISA adds N-able N-central static code injection flaw to KEV
- Russia Pushes BRICS to Settle 90% Trade in Local Currencies
- 1Gbits vs OVH vs Hetzner: Which Bare Metal Provider Wins on Price and Performance
