News

Alby warns about older Hubs exposed to the internet

Alby reports a critical flaw in older internet-accessible Hubs. Its updated advice includes removing app connections, and its deployment guides also needed correction.

3 min readWallets
Alby warns about older Hubs exposed to the internet

What happened

A wallet's control panel should not be an open door from the internet. On 9 September 2026, Alby warned that publicly reachable Alby Hub versions v1.7.0 through v1.18.5 contained a critical vulnerability. Someone able to reach the management API, the interface used to control the Hub, could gain unauthorised access and send funds.

Alby said it knew of one affected user. That is the team's reported count, not a complete measurement of the incident. It has not yet published full technical details.

What it changes

Alby's updated advice is specific: restrict public access and upgrade to v1.24.0. If an affected Hub was internet-accessible, change its unlock password and delete app connections after updating. Its security team offers help at [email protected]. Updating alone is not the whole instruction.

The company says v1.19.0 and newer are unaffected by this particular flaw. This is a warning about older installations, not a claim that every current Hub is vulnerable.

The v1.24.0 release, published on 14 August 2026, also includes other security improvements. Its notes list tighter API-key permissions, checks on backup-restore paths, and validation of redirect URLs. Those are separate changes; the release notes do not identify them as the cause of this incident.

What it does not change

Alby Hub connects applications to a user's wallet or Lightning node. Lightning allows payments through channels instead of putting every payment on Bitcoin's blockchain. This advisory concerns access to Hub management, not a demonstrated failure of Bitcoin's consensus rules or the Lightning protocol.

The statement does not establish how much was lost or whether additional affected users will emerge. There is no basis here for inventing a total, an attacker identity, or an exploit sequence.

Context

There is also a documentation problem, acknowledged in Alby's change merged on 7 September. Earlier self-hosting guides described the server as listening on localhost, meaning only the same machine, when it actually listened on all network interfaces.

Listening on every interface does not automatically mean public exposure: routing and firewalls still matter. But the distinction is essential when someone follows a cloud-server guide.

The updated examples bind Docker's published port to the host machine and recommend a private network or VPN for remote access. The change explicitly leaves the server's default listening address and published container image unchanged. It does not repair an existing installation simply because the documentation changed.

Alby's repository explains that applications connect through Nostr Wallet Connect. The advisory says this lets the Hub work without making its management interface publicly reachable. Running your own wallet gives you control. Clear defaults and accurate installation instructions help make that control usable safely.

Newsletter

Bitcoin, without the noise

What happened in Bitcoin, what it actually changes, and the sources so you can check us. One issue at a time, straight to your inbox.

  • One email per issue, never a drip campaign
  • No tracking pixels and no shared addresses
  • Unsubscribe from any issue in one click

Get the next issue

One email per issue, no tracking pixels, and unsubscribe from any of them. We do not share your address. Privacy policy