Crypto Prices

Critical Vulnerability Discovered in Alby Hub’s Older Versions

20 hours ago
1 min read
6 views

Alby Security Vulnerability Announcement

On September 9, 2026, Alby, a provider of tools for the Bitcoin Lightning Network and Nostr, announced a significant security vulnerability affecting earlier versions of its Alby Hub. The flaw was brought to the public’s attention via X, the social media platform, where the company detailed that Alby Hub versions ranging from 1.7.0 through 1.18.5, which were released prior to August 2025, are susceptible if the Hub is accessible over the internet.

Details of the Vulnerability

The vulnerability carries the risk of unauthorized access through the Hub’s management API, which could potentially allow an intruder to manipulate funds. Alby affirmed that users operating on Alby Hub version 1.19.0 and later are safe from this issue. They expressed their regrets, particularly for any users who have been affected, noting that so far, only one individual reported being compromised by this vulnerability. The company emphasized their dedication to improving security after years of investment into the project.

Recommended Actions for Users

To mitigate the risk, Alby advised users to first verify their installed version of the Hub. If they are on an outdated version, they should immediately restrict public access to the management interface and update to the latest release, v1.24.0. The company also acknowledged the assistance from the Bitcoin Red Team developers, who identified and reported various other concerns that have been rectified in this most recent update. Should affected users have been exposed to the internet, changing their unlock password after updating is also highly recommended.

Related Incident with Boltz

This vulnerability disclosure follows a similar troubling incident involving Boltz, another player within the Lightning Network domain. Boltz facilitates seamless bitcoin transfers between the main blockchain, Lightning Network, and Liquid Network. On August 3, 2026, the platform temporarily removed its swap functionality, revealing it was facing a barrage of AI-assisted attacks that had escalated over time. Their statement highlighted that attackers were able to exploit vulnerabilities faster than Boltz could patch them. After conducting their own AI-enhanced scans, Boltz concluded that it was unsafe to resume swap operations due to continuous targeting by sophisticated groups.

Conclusion and Security Recommendations

Both Alby and Boltz adhere to open-source principles and the philosophy of allowing users to maintain control over their private keys. In light of the recent security challenges, Alby has strongly advised users to operate only with the latest versions of their Hub and to avoid direct exposure to public internet access.

“It is recommended to run the Hub behind a firewall or on a private network,”

emphasizes the Alby team. As the cryptocurrency landscape experiences rapid vulnerabilities discovered by AI, it is crucial for users to remain vigilant and proactive about their security practices.

Popular