← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Critical Flaw in Alby Hub Bitcoin Wallets Could Allow Remote Takeover

🔄 Updated 42m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Alby Hub versions v1.7.0 to v1.18.5 are affected by a critical flaw.
  • The vulnerability allows wallet takeover if the Hub is internet-exposed.
  • One user has been affected, but it is not confirmed if funds were lost.
  • Users must update to v1.24.0 and restrict external access to the Hub.

Critical Vulnerability Identified

Bitcoin wallet company Alby has issued a warning regarding a critical flaw in its Alby Hub software. The vulnerability affects versions v1.7.0 through v1.18.5 and could enable an attacker to gain control of a user's Lightning wallet and transfer funds, specifically if the Hub was configured to be accessible from the internet.

Affected Versions and Mitigation

The flaw is present in all versions released before August 29, 2025. Versions v1.19.0 and later, including the current release v1.24.0, contain the fix. Alby recommends that users on older builds first disable external access to the Hub's management interface, which is the web page used to control the wallet, before updating to v1.24.0.

Impact and Disclosure

Alby has confirmed that one user has been affected by this vulnerability, though it has not specified if any funds were lost. The company has not yet disclosed the technical details of the flaw, stating it will do so later in line with responsible disclosure practices. They also acknowledged researchers who reported other issues addressed in the latest release.

User Actions Required

Users are advised to check their Hub's version. If it is v1.18.5 or older, they must prevent external network access to the Hub. For Docker setups, this means publishing the port as 127.0.0.1:8080:8080 instead of 8080:8080. For cloud servers, firewall rules for port 8080 should restrict access to only the user's own address. Following these steps, users should update to v1.24.0. If an affected version was internet-exposed, users should also change their unlock password after updating and contact security@getalby.com.

Background on Internet Exposure

Alby Hub is designed for private network deployment. The project's documentation now includes a warning against exposing the Hub to the public internet, as the server listens on all network connections rather than being restricted to the local machine. This warning was added in a documentation update on September 7, addressing previous setup guides that did not adequately emphasize this security consideration.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~22 min · 18 stories · Sep 09

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Alby has disclosed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5 that could allow an attacker to take over internet-exposed Lightning wallets. Users are advised to restrict external access to the management interface and update to version v1.24.0 immediately to mitigate the risk.