Alby Hub old versions have critical vulnerability, publicly exposed management API could lead to fund transfer
2026-09-09 08:05
Odaily Planet Daily News Bitcoin News posted on X platform that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 through v1.18.5. If the management API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. Currently, 1 user is known to be affected, and Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public access to the management interface, update to v1.24.0 immediately, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.
