VMTech
Discuss a project

Alby Hub flaw puts internet-exposed Lightning wallets at risk

Alby Hub flaw puts internet-exposed Lightning wallets at risk

Bitcoin wallet company Alby has disclosed a critical vulnerability in Alby Hub, its self-hosted Lightning wallet, that could allow an attacker to take over a wallet and send its funds when the Hub was reachable from the public internet. The issue affects versions v1.7.0 through v1.18.5, while v1.19.0 and later are not affected. Alby said it knows of one affected user.

The first fixed release, v1.19.0, was published on August 29, 2025. Alby recommends that all users update to v1.24.0, the current release. The company has not disclosed the technical nature of the flaw, saying that fuller details will follow under responsible disclosure practices.

External exposure is the key condition

The warning is limited to Hubs made reachable from outside the owner’s network. Alby Hub is intended to run on a user-controlled computer or server and stores bitcoin, while its management interface is used to operate the wallet. For installations still running v1.18.5 or an older release, Alby says owners should remove outside access to that interface before updating.

For Docker deployments, the company’s guidance is to publish the service as 127.0.0.1:8080:8080, rather than 8080:8080, so that port 8080 is bound only to the local machine. On a cloud server, the firewall rule for port 8080 should permit the owner’s address instead of any address. Users whose affected Hub was publicly accessible are also advised to change the unlock password after updating and contact security@getalby.com.

Documentation changes reveal a deployment risk

Alby’s documentation was amended on September 7 to warn against exposing the Hub to the public internet. The change notes that several setup guides had described the server as running on localhost even though it listened on all network interfaces. The project also changed its Docker configuration from publishing port 8080 on every address to binding it only to the host machine.

Some cloud deployment guides still described internet-accessible setups as of September 9. A DigitalOcean guide instructed users to retain a public address to open Alby Hub in a browser, while a Hetzner guide included a port 8080 firewall rule that could allow any IPv4 or IPv6 address. Those instructions matter because a login-protected interface can still become a high-value target when it is unnecessarily exposed.

What wallet operators should check

Alby has not said whether an update alone removes access an attacker may already have gained, nor has it stated whether the known affected user lost funds. The company’s password-change advice applies specifically to people running an affected version that was exposed online.

For businesses and individuals operating self-hosted Lightning infrastructure, the immediate implication is to inventory installed Alby Hub versions, restrict administrative access to a private network or explicitly trusted addresses, and upgrade older deployments to v1.24.0. Public exposure of wallet controls should be treated as an operational exception requiring deliberate network controls, not as a default deployment setting.

#bitcoinsecurity#lightningwallet#walletsecurity#selfhosting
Open analytics
On the site 0 views
min read 3 09.09.2026
Instagram

Alby Hub flaw puts internet-exposed Lightning wallets at risk

Open the post on Instagram ↗