Vulnerability
Published 2026-09-09
Verified 2026-09-19

Alby Hub critical: internet-exposed Lightning wallets takeover (v1.7.0–v1.18.5)

The Hacker News (9 September 2026) reports Alby warned of a critical flaw in self-hosted Alby Hub (Lightning bitcoin wallet) that could let an attacker take over a wallet and send funds — only where the Hub management interface was reachable from the internet. Affected: v1.7.0 through v1.18.5 (pre-August 2025 builds); fixed from v1.19.0 (first fixed release 29 August 2025); current recommended v1.24.0. Alby says one user affected so far; technical details withheld pending responsible disclosure. Guidance: remove external reachability first (e.g. bind 127.0.0.1), then upgrade; if exposed on an affected build, change unlock password after update and contact security@getalby.com. Primary wire: THN citing Alby; releases: GitHub getAlby/hub.

Product
Alby Hub (self-hosted Lightning wallet)
Versions
Affected v1.7.0–v1.18.5 when internet-exposed; fixed v1.19.0+; recommend v1.24.0
Exploited in Australia?
unknown
Patch to
Stop publishing the Hub management port to the internet, upgrade to v1.19.0+ (prefer v1.24.0), rotate unlock password if previously exposed

Primary: The Hacker News — Alby Hub critical (9 Sep 2026) · Vendor: getAlby/hub releases (v1.24.0 current)

vulnerabilities cloud identity