NG Solution Team
Cybersecurity

Alby Hub Vulnerability in v1.7.0–v1.18.5 Exposes Management API

Alby disclosed a critical vulnerability affecting Alby Hub versions v1.7.0–v1.18.5 that could allow an attacker who can reach the Hub’s management API to gain access without authorization and send funds. The team said the flaw only affected Hubs that were publicly accessible from the internet and that, to their current knowledge, one user has been impacted.

Alby Hub vulnerability and affected versions

Alby announced the issue on X, writing: “We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet.” The company added that “Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.” Alby also apologized to users and said, “As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.”

Alby advised users to first check which Hub version they have installed, to immediately lock down public access to the Hub’s management interface if running an affected version, and to update right away to v1.24.0, the newest Alby Hub release. The company thanked Bitcoin Red Team developers for reporting several issues that have been fixed in the latest release. Alby also recommended that users exposed to the internet change their unlock password after updating and avoid exposing the Hub to the open internet, stating a preference for running it behind a firewall or within a private network.

AI-assisted probing and pressure on Lightning projects

The disclosure follows a recent incident at Boltz, a Lightning-adjacent protocol, which took swaps offline on Aug. 3, 2026 after months of automated, AI-assisted probing and a series of contained exploits. Boltz said attackers “now iterate faster than a team our size can find and patch.” Both Alby and Boltz are open-source, Lightning-adjacent projects that emphasize non-custodial, “you keep the keys” designs, and both incidents highlight growing pressure on Lightning Network infrastructure as AI-assisted discovery accelerates the identification of bugs across the cryptocurrency ecosystem.

Related posts

Could a cybersecurity breach affect 3 million Texas license holders?

Emily Brown

Can specialized AI agents reduce security alert noise?

David Jones

UK airports cyber attack: customer contact and vehicle data accessed

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy