Alby and Osmosis Scramble to Contain Critical Vulnerabilities
Critical vulnerabilities in Alby's self-hosted Hub software and the Nomic chain have left funds at risk. The issues, disclosed by Alby and Osmosis respectively, highlight distinct risks associated with self-custody tools and cross-chain bridges.
Alby confirmed that its Hub versions v1.7.0 through v1.18.5 are affected by a critical vulnerability. An attacker could gain unauthorized access to exposed nodes and drain funds using the management API interface. Alby emphasized the importance of restricting public access to the Hub, especially if it is directly exposed on the internet.
Osmosis disclosed an exploit targeting the Nomic chain that allowed an attacker to double-spend nBTC and mint false vouchers. The vulnerability was in a custom forwarding mechanism built specifically for Nomic. Osmosis clarified that its own chain and the IBC protocol were not compromised, but the exposure is significant due to the deep integration of nBTC within Osmosis liquidity.
Alby and Osmosis have responded promptly by releasing fixes and freezing affected funds. Alby urged all Hub operators to update their software to v1.24.0 as soon as possible. Osmosis plans to formally seize frozen assets using a governance proposal and draw on community pool BTC to cover any remaining shortfall.