Alby Hub Security Flaw Exposes Bitcoin Lightning Wallets to Attack

Alby Hub Vulnerability Puts Older Lightning Wallet Versions at Risk
Disclaimer: The information provided is for informational purposes only. All content, including news articles, analysis, opinions, and commentary, does not constitute financial, investment, legal, or trading advice. Cryptocurrency markets are highly volatile and involve significant risk. Readers are strongly encouraged to conduct their own research. CryptoMoonPress is not responsible for any financial losses or damages resulting from reliance on the information.

Alby, a company that builds open-source Bitcoin Lightning Network wallets and tools, has confirmed a major security flaw in earlier versions of Alby Hub, its Bitcoin Lightning wallet on X. The problem affects versions v1.7.0 through v1.18.5, basically anything released before August 2025.

According to Alby, this vulnerability becomes a real risk when the Hub’s management API can be accessed from the public internet. If an attacker can reach that management API, they could break in and send funds without authorization.

Alby’s warning is clear to anyone still using those versions. Alby wants users to upgrade their versions right now. The company says v1.19.0, published on August 29, 2025, and everything newer are safe from this specific vulnerability.

They are telling affected users to update right away, pointing to v1.24.0 as the latest and safest release in their notice. So far, Alby says that only one user has been impacted and reported the problem.

What the Alby Hub Vulnerability Means

The root of the problem is exposure. Older Alby Hub versions can be reached from the open internet. Versions v1.7.0 up to v1.18.5 are at risk if the Hub’s management interface is accessible publicly. This gives the attacker a route to the management API.

This is a big deal because an intruder could send funds without permission. For users using a lightning wallet, the ability to transfer funds without authorization creates a direct financial risk.

Alby acknowledges how serious this is and apologised to users, especially anyone who is affected by the incident. The company says it has put a lot of work into the project, and this incident affected the team a lot.

Alby also plans to share full technical details later, after following responsible disclosure practices. This also suggests that the company has not yet published everything about the problem in the notice.

Which Versions are Affected

The affected range is Alby Hub v1.7.0 to v1.18.5, all releases before August 2025. Alby confirms v1.19.0, released on August 29, 2025, or anything newer is not affected. Still, they recommend everyone upgrade to v1.24.0, which is the latest release.

If you are running an affected version, Alby says you should first restrict public access to the Hub’s management interface and then update to v1.24.0 right away.

There is an extra step if your vulnerable Hub was open to the internet; after updating, change or unlock password. Alby also offers help and you can reach them at security@getalby.com if you need support.

Even if you are not directly affected, updating to v1.24.0 is worth it. Alby says this version has more security improvements and additional enhancements.

Alby’s Security Recommendations

With the immediate update alert, Alby repeats its general security tips for Hub users. Always run the latest version and do not skip update notifications. Avoid exposing Alby Hub to the public internet. Run it behind a firewall or inside a private network instead.

Alby also mentions that you do not need your Hub to be publicly reachable, NWC (Nostr Wallet Connect), the communication protocol at the centre of the system, lets the Hub operate through private servers or platforms like Umbrel.

The security notice also thanks Bitcoin Team Red, Project Loupe, and several other researchers who reported issues that have now been patched.

Alby says it is ready to answer questions and support anyone handling the incident. Their key advice is that if you have a vulnerable version exposed to the internet, then restrict access, install v1.24.0, and change your lock password after the update.

Devanshi Kashyap 150x150

Devanshi Kashyap

Author at cryptomoonpress

Devanshi is a curious learner who enjoys exploring new ideas across crypto, blockchain, and Web3, and expresses that same curiosity...

Niharika Deshpande 150x150 1

Niharika Deshpande

Editor at cryptomoonpress

Niharika Deshpande is a crypto editor and journalist at CryptoMoonPress, with over four years of experience covering cryptocurrency, blockchain, and...

Last updated September 9, 2026
Share on: FB X LinkedIn
Written by Devanshi Kashyap Verified by Niharika Deshpande