We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker who could reach the Hub's management API to gain unauthorized access and send funds.
**Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.**
As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.
**What you should do:**
1.) Check your installed version. If you run an affected version, restrict public access to your Hub's management interface and update immediately to v1.24.0, the latest release.
2.) If you run an affected version which was accessible from the internet update your unlock password after the update. Contact security@getalby.com, we're happy to help
3.) If you are not affected by this issue. We still recommend updating to the latest version (v1.24.0) now, as it includes additional security improvements and other enhancements.
We will publish full details at a later date, following responsible disclosure practices.
Additionally we want to thank Bitcoin Team Red, Project Loupe and other researchers who reported several issues, which have been fixed in the latest release.
**Our general security recommendations:**
1.) Always run the latest version. Alby Hub notifies you when updates are available — please don't ignore these notifications.
2.) Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable — it works perfectly on private servers or systems like Umbrel.
If you have any questions, please reach out to us. We're happy to help.
Login to reply
Replies (16)
Thanks for being this quick in your response.
Stop and start your albyhub eggstr instance will update it to the latest version 🚨
View quoted note →
The deeper fix predates this patch: your node's management API should never face the public internet at all. Tailscale, a VPN, or localhost only turns this entire bug class into a non-event. Anything holding signing keys gets treated like cold storage infrastructure, not a web app.
又一例,AI 进步引发的安全混乱还在继续
View quoted note →
How much did ' deep-state ' bought you? Or did they put a gun on to your head?
Whats this got to do with anything you restarted faggot bot?
I have moved all my services behind tailacale. I advise everyone to hide everything under VPN or something else.
So this only affects users who haven’t updated for more than an entire year?
Virou moda agora essas vulnerabilidades né. O mais estranho que é sempre em mercado de baixa, justamente pra galera soltar seus sats com medo e os institucionais comprarem barato 🤡🤡🤡
start9 has no upgrade listed as of the am.... im running lastest post AUG 2025 for now, seems safe, correct?
Note : please update to the latest version of alby hub 👍
Alby confirm ว่า Alby Hub version v1.7.0 - v1.18.5 มีช่องโหว่
ใครที่เปิด Alby Hub ให้เข้าผ่าน public internet อาจจะโดนโจมตีจากช่องโหว่นี้ได้
Alby แนะนำให้ update เป็น version ล่าสุด (1.24.0)
ใครรัน alby hub อยู่อย่าลืม update เป็น version ล่าสุดกันด้วยนะครับ
#siamstr
View quoted note →
Hi guys, I've re-downloaded the latest version of AlbyHub for Desktop, I'm on a Pro plan, still getting the same error, however all looks good with NWC (web and chrome extension), so as AlbyGo on mobile. 

That's fine. That's a general warning. It will be turned off soon.
Great share thanks, it hadn't really dawned on me that it could be a hack requiring my attention. Thank you, will look into it.