We have confirmed a critical vulnerability in Alby Hub v1.7.0βv1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker who could reach the Hub's management API to gain unauthorized access and send funds.
**Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.**
As with any incident of this kind, we are deeply sorry β above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.
**What you should do:**
1.) Check your installed version. If you run an affected version, restrict public access to your Hub's management interface and update immediately to v1.24.0, the latest release.
2.) If you run an affected version which was accessible from the internet update your unlock password after the update. Contact
[email protected], we're happy to help
3.) If you are not affected by this issue. We still recommend updating to the latest version (v1.24.0) now, as it includes additional security improvements and other enhancements.
We will publish full details at a later date, following responsible disclosure practices.
Additionally we want to thank Bitcoin Team Red, Project Loupe and other researchers who reported several issues, which have been fixed in the latest release.
**Our general security recommendations:**
1.) Always run the latest version. Alby Hub notifies you when updates are available β please don't ignore these notifications.
2.) Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable β it works perfectly on private servers or systems like Umbrel.
If you have any questions, please reach out to us. We're happy to help.