Find notable cyber news and cases, enriched with sources, timelines, and signals.

Alby Hub internet-exposed wallet takeover security flaw

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A critical flaw in Alby Hub could let an attacker take over a wallet and send its funds when the wallet service was reachable from the internet. The affected range covers v1.7.0 through v1.18.5, while v1.19.0 and later are not affected. Alby said one user has been affected so far. Owners still on older builds were told to block outside access and then update to v1.24.0.

Related Happenings

Alby Hub internet-exposed wallet remediation advisory

Advisory/Mitigation
H score37 First: 09.09.2026 13:43 Last: 09.09.2026 13:43 Sources 1

How related: If your Hub ran an affected version and was reachable from the internet, change your unlock password after the update and contact [email protected].

About this happening: Alby told Alby Hub owners on v1.18.5 or older that were reachable from the internet to block outside access, update to v1.24.0, and change the unlock passwor...

Timeline

  1. 09.09.2026 13:43 1 articles · 2h ago

    Alby Hub documentation corrects public-exposure setup guidance

    Technical Analysis Update

    A documentation change merged on September 7 corrected Alby Hub setup guidance after several guides had described the server as running on localhost when it actually listens on all network interfaces. The same change switched the Docker file from publishing port 8080 to every address to publishing it only to the machine itself.

    Show sources
  2. 09.09.2026 13:43 2 articles · 2h ago

    Alby warns of a critical Alby Hub flaw affecting internet-exposed wallets

    Initial Disclosure

    Alby warned that a critical flaw in Alby Hub could let an attacker take over a wallet and send its funds when the Hub was reachable from the internet. Alby said one user has been affected so far, had not disclosed the flaw's technical details, and told exposed owners to block outside access to the management interface before updating to v1.24.0.

    Show sources