Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: bitcoin (2 articles)Clear

Critical Alby Hub flaw lets attackers drain internet-exposed Bitcoin wallets

Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.

Check
If you run Alby Hub, remove any public internet access to its management interface first, then update to the current release, and check exposed instances for unauthorized access or unexpected outgoing payments.
Affected
Owners of self-hosted Alby Hub Lightning wallets on versions 1.7.0 through 1.18.5 reachable from the internet; an attacker reaching the management interface could take control of the wallet and send bitcoin.
Fix
Update Alby Hub to the current version, keep the wallet's management interface off the public internet behind a VPN or local network, use strong unique credentials, and monitor for unexpected transactions.

THORChain drained for ~$10.8M in coordinated multi-chain exploit across BTC, ETH, BNB Chain, and Base

On-chain investigator ZachXBT flagged a coordinated exploit against THORChain's cross-chain liquidity pools on May 15, 2026, with PeckShield confirming losses of approximately $10.8 million across four blockchains - around 36.85 BTC plus $7 million in assets from Ethereum, BNB Chain, and Base. The attacker funneled funds into two main addresses (BTC bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37 and ETH 0xd477b69551f49C0519F9B18c55030676138890Bd). THORChain responded with a global emergency halt of trading and signing - a controversial move given the protocol's permissionless positioning. No official post-mortem has been released. The RUNE token dropped 12-14% on the news; the same protocol was previously used by North Korean operators to launder $175 million.

Check
If your organization custodies or trades THORChain liquidity, RUNE, or assets bridged through THORChain in the May 14-15 window, reconcile on-chain balances against the two known exploiter addresses and check for any user funds in affected pools.
Affected
THORChain liquidity providers, aggregators routing through THORChain, custodians holding RUNE, and wallets that bridged BTC, ETH, BNB Chain, or Base assets through the protocol on May 14-15. DeFi exposure is highest for cross-chain aggregator front-ends.
Fix
Block transfers to the two attacker-controlled addresses (BTC bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37 and ETH 0xd477b69551f49C0519F9B18c55030676138890Bd), monitor RUNE deposits to centralized exchanges for laundering attempts, and pause front-end integrations with THORChain until a post-mortem and patched release are published.