Bitcoin wallet company Alby has issued a warning regarding a critical flaw in its Alby Hub software. The vulnerability affects versions v1.7.0 through v1.18.5 and could enable an attacker to gain control of a user's Lightning wallet and transfer funds, specifically if the Hub was configured to be accessible from the internet.
The flaw is present in all versions released before August 29, 2025. Versions v1.19.0 and later, including the current release v1.24.0, contain the fix. Alby recommends that users on older builds first disable external access to the Hub's management interface, which is the web page used to control the wallet, before updating to v1.24.0.
Alby has confirmed that one user has been affected by this vulnerability, though it has not specified if any funds were lost. The company has not yet disclosed the technical details of the flaw, stating it will do so later in line with responsible disclosure practices. They also acknowledged researchers who reported other issues addressed in the latest release.
Users are advised to check their Hub's version. If it is v1.18.5 or older, they must prevent external network access to the Hub. For Docker setups, this means publishing the port as 127.0.0.1:8080:8080 instead of 8080:8080. For cloud servers, firewall rules for port 8080 should restrict access to only the user's own address. Following these steps, users should update to v1.24.0. If an affected version was internet-exposed, users should also change their unlock password after updating and contact security@getalby.com.
Alby Hub is designed for private network deployment. The project's documentation now includes a warning against exposing the Hub to the public internet, as the server listens on all network connections rather than being restricted to the local machine. This warning was added in a documentation update on September 7, addressing previous setup guides that did not adequately emphasize this security consideration.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Alby has disclosed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5 that could allow an attacker to take over internet-exposed Lightning wallets. Users are advised to restrict external access to the management interface and update to version v1.24.0 immediately to mitigate the risk.