Alby Exposes Critical Security Flaw in Older Lightning Node Versions
The Bitcoin Lightning Network and Nostr tooling company Alby has revealed a critical security flaw in older versions of its Alby Hub, a node and wallet for managing Bitcoin transactions on the Lightning Network. The vulnerability affects users who have installed versions v1.7.0-v1.18.5 of the Hub, which were released prior to August 2025.
According to Alby, only one user has been affected by this issue so far, but they are urging all users to check their version and take immediate action if necessary. Affected users should lock down public access to their Hub's management interface and update right away to the newest release, v1.24.0.
The security flaw allows an attacker who can reach the Hub's management API to gain unauthorized access and send funds. Alby is stressing the importance of running the latest version of the Hub and avoiding exposing it to the open internet.