Industry News

Critical Flaw in Alby Hub Bitcoin Lightning Node Software: Check Your Version Now

CryptoTicker · 11 Sept 2026
Key Takeaway If your business runs any self-hosted financial or payment software, regularly check version numbers and never leave administrative interfaces exposed directly to the internet.

A security flaw affecting the Alby Hub software, used by people who run their own Bitcoin Lightning Network payment nodes, has been disclosed by the provider. Versions from v1.7.0 through v1.18.5, all released before August 2025, are affected. If the management interface of an affected installation is reachable from the open internet, an attacker could gain unauthorised access and drain funds from the node.

This issue only affects people who self-host their own Lightning node rather than using a wallet app that connects to someone else's service. A self-hosted node runs continuously on a home device, rented server, or desktop, and has an administrative interface that must be properly secured. The provider has rated the flaw as critical, though the fix has actually been available since the 1.19 release series, well before this public warning began circulating. So far, one user has been confirmed as affected.

Affected operators should immediately check their Alby Hub version number, ensure the management interface is not accessible from the internet, upgrade to version v1.24.0 or later, and change the unlock password once updated.

Summarised by CISO AI from CryptoTicker. We link back to every original so you can read it yourself.