Alby confirmed a critical vulnerability affecting Alby Hub versions v1.7.0 through v1.18.5, released before August 2025. When a hub’s management API was reachable from the public internet, attackers could gain unauthorized access and transfer funds. One affected user has been confirmed. Alby advises users to block public access to the management interface, upgrade immediately to v1.24.0, change unlock passwords and avoid exposing hubs online. It recommends using the NWC protocol to run hubs within private networks. Versions v1.19.0 and later, including v1.19.0 released on Aug. 29, 2025, are not affected. Earlier reports said issues identified by Bitcoin Team Red, Project Loupe and other researchers were fixed in the latest release.