Alby disclosed a critical vulnerability in its self-hosted Lightning wallet, Alby Hub, that could allow an attacker to take over an internet-exposed wallet and transfer its bitcoin. The flaw affects versions 1.7.0 through 1.18.5; exploitation requires the Hub management web interface to be reachable from the internet. Alby knows of one affected user but has not said whether funds were stolen, and it has not released technical details of the vulnerability.
The issue was fixed in v1.19.0, while Alby recommends upgrading to v1.24.0. Organizations and users running affected exposed instances should immediately restrict external access, change the Hub unlock password, and contact Alby security. Alby also corrected documentation and Docker port-binding defaults after discovering they could imply localhost-only access even though the service listened on all network interfaces, increasing the chance of unintended internet exposure.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Alby added warnings against directly exposing Alby Hub to the public internet, acknowledged prior localhost guidance was inaccurate, and changed Docker configuration to bind port 8080 only to the local machine.
Alby described a separate incident involving a clearnet-accessible Hub that had not completed setup and had no unlock password; an attacker completed its setup and emptied the wallet.
Alby released Alby Hub v1.19.0, the first version containing a fix for the critical vulnerability affecting internet-exposed Hub management interfaces.
Alby disclosed that versions v1.7.0 through v1.18.5 could allow attackers to take over an internet-exposed Alby Hub wallet and transfer bitcoin. The company said it knew of one affected user, did not confirm losses, and withheld technical details pending later responsible disclosure.
Following the separate publicly exposed Hub incident, Umbrel changed its Alby Hub app so users must pass through Umbrel's login protection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.