Highlights
- Alby confirmed a critical vulnerability affecting Alby Hub versions v1.7.0 through v1.18.5, released before August 2025.
- The bug lets attackers gain unauthorized access and move funds when the Hub's management API is exposed to the public internet.
- At least one user has been confirmed affected so far.
- Versions v1.19.0 and above, released starting August 29, 2025, are not affected.
Alby, a widely used Bitcoin Lightning Network wallet and node-management service, has confirmed a critical vulnerability in older versions of its self-hosted Alby Hub software. The flaw affects Hub versions v1.7.0 through v1.18.5, all released before August 2025. When a vulnerable Hub's management API is reachable from the public internet, an attacker can exploit the bug to gain unauthorized access and transfer funds out of the wallet. Alby says it has confirmed at least one user affected by the issue so far. Versions v1.19.0 and later, starting from an August 29, 2025 release, are not affected by the flaw.
What Triggers the Vulnerability
The vulnerability specifically requires that a Hub instance's management API be exposed to the public network — a configuration that shouldn't happen under Alby's recommended setup, but one that self-hosted node operators can end up with inadvertently, especially those running Alby Hub on a home server, VPS or Umbrel-style node without carefully restricting network access. Because Alby Hub is designed to give users full self-custody over their Lightning funds, a compromised management API effectively hands an attacker the same level of control a legitimate owner would have, including the ability to move the wallet's balance.
Alby has recommended that any user running an affected version immediately upgrade to the current v1.24.0 release, restrict the Hub's management interface from public network access, and change their unlock password as a precaution even if they don't believe they've been compromised. The company said it will share more technical detail about the vulnerability once responsible-disclosure practices allow, a standard approach meant to avoid publishing exploit details before the broader user base has had a chance to patch.
Related: Core Lightning Tells Node Operators to Patch or Go Offline After AI-Found Bugs
Part of a Wider Pattern in Bitcoin Wallet Security
The disclosure adds to a string of Bitcoin self-custody security incidents in 2026. A firmware bug in Coldcard hardware wallets enabled a $116 million theft earlier this year, and that incident, like Alby's, centered on a specific version range and a narrow but critical attack surface rather than a fundamental flaw in Bitcoin itself. The recurring theme across these disclosures is that self-custody tools — whether hardware wallets or self-hosted Lightning nodes — carry software-level risk that centralized custodians largely abstract away, in exchange for the custody trade-offs users accept when choosing self-hosted infrastructure.
Lightning-specific infrastructure has faced its own recent scrutiny. Core Lightning recently told node operators to patch or take nodes offline after AI-assisted bug hunting surfaced new vulnerabilities, a different implementation than Alby Hub but part of the same broader trend of increasingly systematic vulnerability discovery across Bitcoin's Lightning software stack. As tooling for finding these bugs improves, the pace of disclosures across different Lightning implementations may accelerate before it slows down.
What Alby Hub Users Should Do Now
Anyone running an Alby Hub version between v1.7.0 and v1.18.5 should treat the upgrade to v1.24.0 as urgent, particularly if their instance's management interface has ever been reachable outside a private network. Alby's broader guidance — to run the management API on a private network and access it remotely only through the Nostr Wallet Connect (NWC) protocol rather than direct public exposure — reflects the general best practice for self-hosted Lightning infrastructure going forward. Volunteer security researchers have been racing to audit Bitcoin software more systematically following a string of high-value hacks this year, and further disclosures across other wallet and node software are plausible as that effort continues.
FAQ
Which Alby Hub versions are affected by the vulnerability?
Versions v1.7.0 through v1.18.5, all released before August 2025, are affected. Versions v1.19.0 and later are not.
What does an attacker need to exploit the bug?
The Hub's management API needs to be reachable from the public internet; an attacker can then gain unauthorized access and move funds out of the wallet.
What should I do if I'm running an affected version?
Upgrade immediately to v1.24.0, restrict the management interface from public network access, and change your unlock password.
How many users have been affected so far?
Alby has confirmed at least one affected user as of its announcement, with more technical details to follow after responsible disclosure.
