Crypto news report · source clearly identified

Alby Hub Critical Vulnerability Disclosed for Versions Prior to August 2025

Alby announced a critical flaw affecting Alby Hub v1.7.0‑v1.18.5 that could allow remote attackers to access the management API and move funds. Users are urged to upgrade to v1.24.0 and restrict public internet exposure.

Alby, a developer of Bitcoin Lightning Network and Nostr tools, disclosed a critical security vulnerability in older releases of its Alby Hub node and wallet software. The flaw affects versions v1.7.0 through v1.18.5, which were released before August 2025.

Vulnerability Details

The issue allows an attacker who can reach the Hub’s management API over the internet to gain unauthorized access and initiate fund transfers. The company confirmed that only one user has reported being impacted.

Versions Affected and Remediation

  • Affected: Alby Hub v1.7.0‑v1.18.5 (pre‑August 2025 releases)
  • Unaffected: v1.19.0 (released Aug 29 2025) and later
  • Recommended action: Verify the installed version, block public access to the management interface, and upgrade immediately to v1.24.0.
  • Post‑upgrade: Change the unlock password for any Hub that was previously exposed.

Context Within Lightning Security

The alert follows a recent incident involving Boltz, another Lightning‑adjacent protocol, which halted its swap service after AI‑assisted attacks targeted its infrastructure. Both projects emphasize the growing role of automated AI probing in discovering vulnerabilities across the cryptocurrency ecosystem.

Best Practices Going Forward

Alby advises users to run the latest Hub release and to keep the service behind a firewall or within a private network to prevent internet exposure.

Source & attribution

News Source

Publisher
Bitcoin.com News
Original date
September 9, 2026, 1:49 PM
Original headline
Lightning Security Alert: Alby Reveals Critical Hub Vulnerability
View original report ↗