pull down to refresh

We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker who could reach the Hub's management API to gain unauthorized access and send funds.
Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.
As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.
What you should do:
  1. Check your installed version. If you run an affected version, restrict public access to your Hub's management interface and update immediately to v1.24.0, the latest release.
  1. If you run an affected version which was accessible from the internet update your unlock password after the update. Contact security@getalby.com, we're happy to help
  2. If you are not affected by this issue. We still recommend updating to the latest version (v1.24.0) now, as it includes additional security improvements and other enhancements.
We will publish full details at a later date, following responsible disclosure practices.
Additionally we want to thank Bitcoin Team Red, Project Loupe and other researchers who reported several issues, which have been fixed in the latest release.
Our general security recommendations:
  1. Always run the latest version. Alby Hub notifies you when updates are available — please don't ignore these notifications.
  2. Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable — it works perfectly on private servers or systems like Umbrel.
If you have any questions, please reach out to us. We're happy to help.
441 sats \ 9 replies \ @siggy47 9 Sep

Possibly off topic- One thing I have noticed, and I'm sure @Alby is monitoring this post, regarding Umbrel is that there is often a really long delay before Alby updates reach Umbrel. That is probably an Umbrel thing, and it doesn't effect this issue.

reply

If Alby says "update now" and you cannot "update now" because of the platform you use, then it does affect this issue.

reply
170 sats \ 4 replies \ @siggy47 9 Sep
  1. Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable — it works perfectly on private servers or systems like Umbrel.

Maybe this gave me a false sense of security?

reply
164 sats \ 0 replies \ @bumi 11h

why false, what do you mean?

reply

Well, I don't audit Alby Hub so I can't tell you for sure, but in general, if you have lnaddr / lnurlp exposed, even through tor, then you're potentially still exposed? If you only have NWC and no listeners whatsoever, then maybe you're good.

But don't take my word for it please, because I haven't checked.

reply
149 sats \ 1 reply \ @bumi 11h

NWC is providing a limited communication protocol between apps and a wallet through relays. This the wallet itself does not need (and should not be) publicly accessible for it to be used by any apps and doing things like lnaddr/lnurlp.
A LNURL just needs a NWC permission to create an invoice.
it's another layer.

reply
123 sats \ 0 replies \ @optimism 11h

Thanks for coming over!

So if someone has a 3rd party distribution like Umbrel or Start9, and it takes a while for them to get an update, the thing to make sure is that:

  1. public access to the management interface is disabled (how?)
  2. in general port 8080 (or whatever is configured as the hub listening port) is firewalled

correct?

reply
39 sats \ 0 replies \ @bumi 11h

it's an umbrel thing. Umbrel is releasing the Alby Hub in their store.

reply
39 sats \ 0 replies \ @OT OP 9 Sep

Start9 is exactly the same. I guess they like to test everything before releasing.

reply
39 sats \ 0 replies \ @ek 9 Sep
That is probably an Umbrel thing

I think the same is true with Alby Hub and LND, LDK etc.

reply
243 sats \ 14 replies \ @ek 9 Sep

Was ~security too expensive?

I know it’s an annoying question (wHy diDn’T yOu pOsT iN mY tErrItOrY??) but yeah, why not? I’m interested, haha. The game theory of territories doesn’t make sense when the most important topics then aren’t posted there, but still end up in ~bitcoin.

reply
Was ~security too expensive?

Yes. And I’ve noticed from my own experience that posts I publish just in ~security don’t get much traction. When I cross-post, it ends up getting pretty expensive if I include him.

reply
3 sats \ 7 replies \ @ek 9 Sep

Interesting, thank you. This is very valuable feedback. I’m not sure yet what I’ll do with it, though.

Maybe there’s more feedback from others?

reply

You should think about how often a post will be exclusive to ~security.

If that's uncommon, then you need to think about what the total cost of posts will be that are cross-posted with it and how likely someone is to recoup their sats.

For me, the ~econ fees had to come down because those posts often also include other territories, but ~Stacker_Sports was fine because those are usually solo.

reply
3 sats \ 0 replies \ @ek 9 Sep
You should think about how often a post will be exclusive to ~security.

Oh, interesting, I think that’s exactly what I’ve been thinking about with @ctfbot_

reply

I post my write-ups there because it's where it belongs, never noticed 100sats was expensive, maybe because I don't post new items enough and in enough Territories to compare 🤔

reply

It really depends on your goals.

If you want ~security to be a place stackers subscribe to for PSAs, then you need minimal post fees, i.e. 5 sats, slightly higher comment fees and curate posts hard through zaps in both ways. If you want it to be ~privacy "lite" then I'd recommend to just cut it in half.

reply
149 sats \ 1 reply \ @ek 9 Sep

I want stackers to have a place for anything ~security-related, without spam or moderation necessary on my part.

I want to recoup some of the costs with exclusive ~security events (@ctfbot_) and territory.watch/security to monitor the revenue (still need to update it regularly).

reply

I'll let you know when you're territory is so good, I subscribed.

reply

I'd go with 33 for posts and 3 for comments.

reply
55 sats \ 1 reply \ @OT OP 9 Sep

I kinda rushed it out after seeing no one had posted about it.

~security is not too expensive!

reply
3 sats \ 0 replies \ @ek 9 Sep

No worries and thank you for this additional data point!

reply
I know it’s an annoying question (wHy diDn’T yOu pOsT iN mY tErrItOrY??)

I wonder about that a lot. Quite some things posted in ~bitcoin that should clearly be ~econ. Isn't there, like, a moderator who can clean this shit up?!

reply
3 sats \ 0 replies \ @ek 9 Sep

your wallet is the moderator

reply
3 sats \ 0 replies \ @ek 9 Sep

I see a good meme opportunity here

reply

I updated!

...also, wasn't at risk, I presume. BUT WHATEVS

reply

This year has been the year I log in just to check what hack is going to ruin my week and or life

reply

optidisconnectinghissnwalletwhilestillfixinglnpubandnotfallingbacktounreviewedalternativestonotgetpwned 🚀

reply
0 sats \ 0 replies \ @b28e57cf12 17h freebie -30 sats

If you run Alby Hub reachable from the internet on anything older than v1.19.0, treat this as patch-now, not patch-this-weekend.

The advisory is narrow but serious: pre-1.19.0 Hubs with a publicly exposed management API could let a remote attacker send funds. LAN-only / behind auth / Tor-only deployments were the intended model — public clearnet exposure was the dangerous config.

Checklist:

  1. Upgrade to ≥1.19.0 (Umbrel users: watch for the Umbrel store lag @siggy47 mentioned — verify the version string inside the Hub, do not assume the store tile is current).
  2. Confirm the management UI is not port-forwarded / not on a public VPS without auth.
  3. If you were exposed on an old version: rotate whatever the Hub controlled (channels, connections) and review recent sends.

One confirmed impacted user so far per Alby — still enough reason to audit exposure.