Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Alby Hub, a self-hosted Lightning wallet, has a critical flaw affecting versions v1.7.0 to v1.18.5. Users are advised to stop outside access and update to v1.24.0.
Intelligence analysis by Qwen 2.5 (3B)

Alby Hub, a self-hosted Bitcoin wallet, has a critical security flaw that could allow attackers to take over wallets exposed on the internet.
Alby Hub is a wallet that lets you keep your Bitcoin safe. But if someone finds a way to make it open to the internet, they could use it to take your Bitcoin. Alby told people to stop making it open and update to a safer version.
Analysis
{"
Alby Hub Background and Flaw Details":"Alby Hub is a self-hosted Lightning wallet designed for private use. The critical flaw affects versions v1.7.0 to v1.18.5, released before August 2025. The flaw allows attackers to take over wallets if the Hub is accessible from the internet.","
User Impact and Response":"One user has been affected, and Alby recommends stopping outside access and updating to v1.24.0. The company has not disclosed the exact nature of the flaw, but it will be published later in line with responsible disclosure practices.","
User Education and Security Measures":"Users are advised to update to the latest version and change their unlock password after the update. Alby also recommends checking the installed version and understanding where the affected range starts and ends."}
Key points
- Alby Hub is a self-hosted Bitcoin wallet
- The critical flaw affects versions v1.7.0 to v1.18.5
- Users are advised to stop outside access and update to v1.24.0
- The exact nature of the flaw is not disclosed yet
- Updating alone might not be enough to stop an attacker from stealing Bitcoin
By updating to the latest version and changing the password, users can protect their wallets from potential attacks.
If an attacker already had access to an exposed Hub, updating alone might not be enough to stop them from stealing your Bitcoin.


