Crypto news report · source clearly identified
Alby Hub Critical Vulnerability Disclosed for Versions Prior to August 2025
Alby announced a critical flaw affecting Alby Hub v1.7.0‑v1.18.5 that could allow remote attackers to access the management API and move funds. Users are urged to upgrade to v1.24.0 and restrict public internet exposure.

Alby, a developer of Bitcoin Lightning Network and Nostr tools, disclosed a critical security vulnerability in older releases of its Alby Hub node and wallet software. The flaw affects versions v1.7.0 through v1.18.5, which were released before August 2025.
Vulnerability Details
The issue allows an attacker who can reach the Hub’s management API over the internet to gain unauthorized access and initiate fund transfers. The company confirmed that only one user has reported being impacted.
Versions Affected and Remediation
- Affected: Alby Hub v1.7.0‑v1.18.5 (pre‑August 2025 releases)
- Unaffected: v1.19.0 (released Aug 29 2025) and later
- Recommended action: Verify the installed version, block public access to the management interface, and upgrade immediately to v1.24.0.
- Post‑upgrade: Change the unlock password for any Hub that was previously exposed.
Context Within Lightning Security
The alert follows a recent incident involving Boltz, another Lightning‑adjacent protocol, which halted its swap service after AI‑assisted attacks targeted its infrastructure. Both projects emphasize the growing role of automated AI probing in discovering vulnerabilities across the cryptocurrency ecosystem.
Best Practices Going Forward
Alby advises users to run the latest Hub release and to keep the service behind a firewall or within a private network to prevent internet exposure.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- September 9, 2026, 1:49 PM
- Original headline
- Lightning Security Alert: Alby Reveals Critical Hub Vulnerability