Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
- ID
- 22719
- Status
- summarized
- Published
- 09 Sep 2026, 6:43 PM
- Fetched
- 09 Sep 2026, 7:43 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 09 Sep 2026, 7:45 PM
- Tags
- Audience
- developers
What happened
Alby Hub, a self-hosted Bitcoin Lightning wallet, disclosed a critical flaw affecting versions v1.7.0 through v1.18.5 that could let attackers take over internet-exposed instances and send funds. The fix shipped in v1.19.0 (August 29, 2025); current release is v1.24.0. At least one user was affected, though Alby did not confirm any financial loss.
Why it matters
If you self-host Alby Hub and exposed its management interface (port 8080) to the internet, you must immediately restrict access to 127.0.0.1 or your own IP, update to v1.24.0, change your unlock password, and contact security@getalby.com. For everyone else, this is a niche crypto-wallet vulnerability with no direct impact on typical AI/ML, SaaS, or general developer workflows.
Discussion angle
Brief mention only: the broader lesson about not exposing self-hosted management interfaces to the public internet, using 127.0.0.1 binding in Docker rather than 0.0.0.0 — a pattern applicable to any self-hosted tool, not just Alby.