A severe security flaw in Alby Hub has left internet-exposed bitcoin wallets vulnerable to remote takeover and fund theft. Alby urges all users to update immediately, as only those running outdated versions with public access are at risk.
One misconfigured port and a single outdated release: that's all it took for attackers to seize control of bitcoin wallets running Alby Hub, the self-hosted Lightning wallet trusted by privacy-focused users. Alby has now confirmed a critical vulnerability that allowed remote attackers to commandeer any wallet whose management interface was exposed to the internet, with the potential to drain funds in minutes.
Alby's warning is blunt. Versions from v1.7.0 up to v1.18.5, released before August 2025, are dangerously exposed if the Hub's web interface is accessible from outside the local network. The company has already received a report from one affected user, though it remains silent on whether any bitcoin was actually stolen. The fix landed in v1.19.0, but Alby is pushing everyone to jump straight to v1.24.0, the latest release, regardless of their current setup.
Come si è arrivati a questa falla
Alby Hub was designed to run on private networks, but documentation and setup guides failed to make that clear. Until September 2025, official guides for cloud deployments like DigitalOcean and Hetzner openly described configurations that left the wallet's management port wide open to the world. Even Docker files published by Alby defaulted to exposing port 8080 on all interfaces, contradicting claims that the service ran only on localhost. Only after the vulnerability surfaced did Alby update its documentation, warning users not to expose the Hub and quietly changing Docker defaults to restrict access.
This is not the first time an Alby Hub has been hijacked due to exposure. In November 2025, a user's wallet was emptied after the setup process was left incomplete, allowing an attacker to finish the installation and set their own password. That incident was blamed on user error, not a software flaw, but it set the stage for the current crisis. Following that breach, Umbrel's app store began requiring its own login before launching Alby Hub, a move that now looks prescient.
Azioni immediate e rischi per gli utenti
Alby's emergency checklist is unambiguous: check your version, block all external access to the management interface, and update to v1.24.0 without delay. For Docker users, this means ensuring the port is bound to 127.0.0.1, not 0.0.0.0. On cloud servers, firewall rules must restrict port 8080 to trusted IPs only. If your Hub was ever exposed and running an affected version, change your unlock password after updating and contact security@getalby.com.
What Alby refuses to clarify is whether updating alone is enough to kick out a lurking attacker. The advice to change passwords hints at the possibility of persistent compromise, but the company is holding back technical details until a later date, citing responsible disclosure. This leaves users in the dark about the true scope of the risk and whether their funds are still at stake.
Responsabilità e trasparenza mancata
Alby's documentation only recently began warning against public exposure, and even now, some guides still describe insecure setups. The README files for both old and current releases lack any explicit caution. This pattern of delayed transparency echoes what reported earlier about other critical vulnerabilities: vendors often scramble to update guides and defaults only after real-world incidents force their hand.
For users relying on Alby Cloud or third-party app stores like Umbrel, the situation is even murkier. Alby's warning tells users to check their installed version but fails to clarify whether managed services have already been patched behind the scenes. The company also leaves a gap in its versioning disclosure, naming v1.7.0 as the start of the affected range but saying nothing about earlier releases.
Il giudizio editoriale
Alby's handling of this vulnerability exposes a familiar pattern in the open-source security world: documentation lags behind reality, and users pay the price for unclear defaults and incomplete warnings. The company's refusal to disclose technical details or confirm whether a simple update is enough to secure compromised wallets leaves users with more questions than answers. Until vendors treat secure defaults and transparent communication as non-negotiable, self-hosted wallet operators will remain one misstep away from disaster. The lesson is clear: in the world of self-custody, operational security is not optional, and trust in vendor guidance must be earned, not assumed.