← All articles

Critical Alby Hub flaw lets attackers drain internet-exposed Bitcoin wallets

Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.

Check
If you run Alby Hub, remove any public internet access to its management interface first, then update to the current release, and check exposed instances for unauthorized access or unexpected outgoing payments.
Affected
Owners of self-hosted Alby Hub Lightning wallets on versions 1.7.0 through 1.18.5 reachable from the internet; an attacker reaching the management interface could take control of the wallet and send bitcoin.
Fix
Update Alby Hub to the current version, keep the wallet's management interface off the public internet behind a VPN or local network, use strong unique credentials, and monitor for unexpected transactions.