Alby Hub confirms critical vulnerability in versions v1.7.0 through v1.18.5

  • Alby confirmed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5.
  • One user was affected after public management-API access enabled unauthorized fund transfers.
  • Alby recommends blocking public access, upgrading to v1.24.0 and changing unlock passwords.

Alby confirmed a critical vulnerability affecting Alby Hub versions v1.7.0 through v1.18.5, released before August 2025. When a hub’s management API was reachable from the public internet, attackers could gain unauthorized access and transfer funds. One affected user has been confirmed. Alby advises users to block public access to the management interface, upgrade immediately to v1.24.0, change unlock passwords and avoid exposing hubs online. It recommends using the NWC protocol to run hubs within private networks. Versions v1.19.0 and later, including v1.19.0 released on Aug. 29, 2025, are not affected. Earlier reports said issues identified by Bitcoin Team Red, Project Loupe and other researchers were fixed in the latest release.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.