Threat Intelligence

Critical Flaw in Alby Hub Bitcoin Wallet Software: Update Now if Internet-Exposed

The Hacker News · 9 Sept 2026
Key Takeaway If you run a self-hosted Alby Hub wallet, immediately block internet access to its management interface, update to v1.24.0 or later, and change your unlock password.

Bitcoin wallet provider Alby has disclosed a critical flaw in its self-hosted Alby Hub software that could allow attackers to seize control of a wallet and send its funds elsewhere. The flaw only affects Hubs that owners had made reachable from the internet, and impacts versions v1.7.0 through v1.18.5, all released before August 2025. Alby says one user has been affected so far, though it has not confirmed whether that user lost funds.

The issue was fixed in v1.19.0, released on August 29, 2025, and the current release is v1.24.0. Alby has not disclosed technical details of the flaw, saying it will publish them later in line with responsible disclosure practices. For users still on an older, exposed version, Alby recommends first blocking outside access to the Hub's management interface, then updating to the latest release and changing the unlock password.

Alby Hub is designed to run on a private network, and its documentation was recently updated to clarify that the server listens on all network connections by default, not just the local machine as some earlier guides suggested. This documentation change, along with a fix to the software's Docker configuration, aims to stop future users from unintentionally exposing their wallets to the internet.

bitcoin cryptocurrency vulnerability self-hosted software wallet security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.