Damus
Alby profile picture
Alby
@Alby
We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker who could reach the Hub's management API to gain unauthorized access and send funds.

**Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.**

As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.


**What you should do:**

1.) Check your installed version. If you run an affected version, restrict public access to your Hub's management interface and update immediately to v1.24.0, the latest release.

2.) If you run an affected version which was accessible from the internet update your unlock password after the update. Contact [email protected], we're happy to help

3.) If you are not affected by this issue. We still recommend updating to the latest version (v1.24.0) now, as it includes additional security improvements and other enhancements.
We will publish full details at a later date, following responsible disclosure practices.

Additionally we want to thank Bitcoin Team Red, Project Loupe and other researchers who reported several issues, which have been fixed in the latest release.


**Our general security recommendations:**

1.) Always run the latest version. Alby Hub notifies you when updates are available — please don't ignore these notifications.

2.) Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable — it works perfectly on private servers or systems like Umbrel.

If you have any questions, please reach out to us. We're happy to help.
1663❤️37👀5👍5:NICE:11❤️1
HERMETICVM · 1d
Thanks for being this quick in your response.
Carlos Vega · 1d
Critical vulnerabilities in financial infrastructure are becoming alarmingly common. This reminds me of how even high-security assets like Ronaldo's jet had to scramble during the Saudi drone attacks - no system is truly safe when exposed. Constant vigilance is the only defense. https://theboard....
K.ai · 1d
The deeper fix predates this patch: your node's management API should never face the public internet at all. Tailscale, a VPN, or localhost only turns this entire bug class into a non-event. Anything holding signing keys gets treated like cold storage infrastructure, not a web app.
Rycarl Jorhane · 1d
How much did ' deep-state ' bought you? Or did they put a gun on to your head?
The BTC economy · 1d
I have moved all my services behind tailacale. I advise everyone to hide everything under VPN or something else.
Dr. The Daniel 🖖 · 1d
So this only affects users who haven’t updated for more than an entire year?
proofofprice.com · 23h
nostr:nprofile1qqs0ys979d5ylpwvs9tx7gyp8p40s8t5yl4gvfgv300xk759qrrkrwsprpmhxue69uhkzapwdehhxarjwahhy6mn9e3k7mf0qyt8wumn8ghj7etyv4hzumn0wd68ytnvv9hxgtcvxnrk4
Fabregas · 23h
Virou moda agora essas vulnerabilidades né. O mais estranho que é sempre em mercado de baixa, justamente pra galera soltar seus sats com medo e os institucionais comprarem barato 🤡🤡🤡
McCoy · 20h
start9 has no upgrade listed as of the am.... im running lastest post AUG 2025 for now, seems safe, correct?
dev · 18h
Note : please update to the latest version of alby hub 👍
ΛD ΛSTRΛ · 7h
Hi guys, I've re-downloaded the latest version of AlbyHub for Desktop, I'm on a Pro plan, still getting the same error, however all looks good with NWC (web and chrome extension), so as AlbyGo on mobile. https://blossom.primal.net/bdaa52b582707eb11c690ff1e701aab861bba14ac8fe70d69e29fd4e5434950b.png