Alby Hub Flaw and Nomic Exploit Expose Crypto Users to Financial Risk
Two major security incidents have hit the cryptocurrency space this week, affecting Alby's self-hosted Hub software and Osmosis' Nomic chain. The vulnerabilities have left users at risk of losing funds, with one user already impacted by Alby's flaw.
Alby confirmed that its Hub software, versions v1.7.0 through v1.18.5, contains a critical vulnerability that can be exploited when a user's management API is publicly reachable on the internet. An attacker could gain unauthorized access and drain funds from exposed nodes.
The company credited security researchers at Bitcoin Team Red and Project Loupe for reporting several issues that have since been patched. Alby urged users to update their Hub software to version v1.24.0, which was released on August 29, 2025.
In a separate incident, Osmosis disclosed an exploit on the Nomic chain that allowed an attacker to double-spend nBTC and mint false vouchers. The vulnerability lived in a custom forwarding mechanism built specifically for Nomic.
Osmosis took swift action to contain the damage, freezing both inflows and outflows tied to Nomic and Alloyed BTC. Validators then carried out an emergency upgrade that froze 22.65 BTC sitting in the attacker's address.