thehackernews.com 9 Sept 2026, 10:43 UTC

Alby Lightning Wallet Flaw Put Internet-Facing Hubs at Risk

CyberSIXT Evidence Panel Source marked as original reporting

ALBY has disclosed a critical flaw in its Alby Hub self-hosted Lightning Wallet service that could have allowed an attacker to take over a wallet and siphon funds, but only if the Hub was exposed to the internet. The vulnerability affects Hub versions 1.7.0 through 1.18.5 (all released before August 2025). Alby states that one user has been affected so far, though it has not confirmed whether funds were stolen.

Versions 1.19.0 and later are not impacted, with the first fixed release published on 29 August 2025; any Hub updated to a release since then is considered safe.

Alby is advising owners still on older builds to first restrict external access to the Hub’s management interface, then upgrade to version 1.24.0. If your Hub ran an affected version and was internet-exposed, you should change the unlock password after updating and contact security@getalby[.]com. The company has not yet disclosed the exact flaw, but it has pledged full details in line with responsible disclosure.

The incident highlights a broader issue: documentation and setup guides historically allowed, or described, public internet exposure of Hub instances, even though current guidance now warns that the Hub listens on all network interfaces rather than only localhost. Alby’s latest guidance and the security fix aim to prevent unauthorised access for users running older, internet-facing deployments.

View full article

Article by CyberSIXT