Alby Hub critical: internet-exposed Lightning wallets takeover (v1.7.0–v1.18.5)
The Hacker News (9 September 2026) reports Alby warned of a critical flaw in self-hosted Alby Hub (Lightning bitcoin wallet) that could let an attacker take over a wallet and send funds — only where the Hub management interface was reachable from the internet. Affected: v1.7.0 through v1.18.5 (pre-August 2025 builds); fixed from v1.19.0 (first fixed release 29 August 2025); current recommended v1.24.0. Alby says one user affected so far; technical details withheld pending responsible disclosure. Guidance: remove external reachability first (e.g. bind 127.0.0.1), then upgrade; if exposed on an affected build, change unlock password after update and contact security@getalby.com. Primary wire: THN citing Alby; releases: GitHub getAlby/hub.
- Product
- Alby Hub (self-hosted Lightning wallet)
- Versions
- Affected v1.7.0–v1.18.5 when internet-exposed; fixed v1.19.0+; recommend v1.24.0
- Exploited in Australia?
- unknown
- Patch to
- Stop publishing the Hub management port to the internet, upgrade to v1.19.0+ (prefer v1.24.0), rotate unlock password if previously exposed
Primary: The Hacker News — Alby Hub critical (9 Sep 2026) · Vendor: getAlby/hub releases (v1.24.0 current)
