Alby said on Sept. 9 that it confirmed a critical vulnerability in older releases of Alby Hub, its Lightning-focused node and wallet software. According to the company, the issue affected Hub versions v1.7.0 through v1.18.5 when the software was publicly reachable from the internet.

The company said an attacker able to access the Hub management API could have gained unauthorized access and sent funds. Alby added that versions v1.19.0 and later are not affected, and said one user is currently known to have been impacted.

What Alby disclosed

The disclosure was published by Alby on X, where the company described the bug as a critical vulnerability in releases issued before August 2025. The affected range spans from v1.7.0 to v1.18.5, while v1.19.0, released on Aug. 29, 2025, was identified as outside the vulnerable set.

Alby said the risk applied when a Hub instance was publicly accessible from the open internet. In that setup, a party that could reach the management API might be able to enter without authorization and move funds.

Known impact and response

Alby said that, to its current knowledge, one user was affected and that the user reported the details. The company apologized for the incident and said the issue had been hard on the team given the resources invested in the project over the past years.

The company also said it had addressed issues reported by the Bitcoin Red Team developers in the latest release. It pointed affected users to v1.24.0 as the current version to install.

Recommended actions for exposed users

Users were urged to first verify which version of Alby Hub they are running. If the installation falls within the affected range, Alby said they should restrict or remove public access to the Hub management interface and then update to v1.24.0.

For users whose Hub had been exposed to the internet, Alby also advised changing the unlock password after updating. More broadly, the company said Hub instances should not be left open to the public internet and are better placed behind a firewall or on a private network.

Broader pressure on Lightning infrastructure

The disclosure arrives amid wider security pressure on Lightning-related services. The source article links the incident to the Boltz attack in August 2026, when the non-custodial swap protocol took swaps offline following what was described as an AI-driven attack.

The same report said AI-assisted probing is allowing attackers to test systems and uncover bugs more quickly, increasing the pace at which development teams must identify and fix weaknesses across crypto infrastructure.

What happens next

The immediate confirmed next step is operational rather than legal or regulatory: users on older Hub versions need to check their installations, upgrade if necessary, and ensure management access is not exposed publicly. Based on Alby’s disclosure, v1.24.0 is the release the company recommends for those remediating the issue.

Alby’s guidance also suggests a longer-term security posture for self-hosted Lightning tools: stay current on software updates, limit internet exposure, and use network protections such as firewalls or private environments to reduce the attack surface.

Source: news.bitcoin.com