We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker who could reach the Hub's management API to gain unauthorized access and send funds.
Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected.
As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.
What you should do:
- Check your installed version. If you run an affected version, restrict public access to your Hub's management interface and update immediately to v1.24.0, the latest release.
- If you run an affected version which was accessible from the internet update your unlock password after the update. Contact security@getalby.com, we're happy to help
- If you are not affected by this issue. We still recommend updating to the latest version (v1.24.0) now, as it includes additional security improvements and other enhancements.
We will publish full details at a later date, following responsible disclosure practices.
Additionally we want to thank Bitcoin Team Red, Project Loupe and other researchers who reported several issues, which have been fixed in the latest release.
Our general security recommendations:
- Always run the latest version. Alby Hub notifies you when updates are available — please don't ignore these notifications.
- Avoid exposing Alby Hub to the public internet. We recommend running it behind a firewall or within a private network. Thanks to NWC (Nostr Wallet Connect), Alby Hub's core communication protocol, your Hub does not need to be publicly reachable — it works perfectly on private servers or systems like Umbrel.
If you have any questions, please reach out to us. We're happy to help.
Possibly off topic- One thing I have noticed, and I'm sure @Alby is monitoring this post, regarding Umbrel is that there is often a really long delay before Alby updates reach Umbrel. That is probably an Umbrel thing, and it doesn't effect this issue.
If Alby says "update now" and you cannot "update now" because of the platform you use, then it does affect this issue.
Maybe this gave me a false sense of security?
why false, what do you mean?
Well, I don't audit Alby Hub so I can't tell you for sure, but in general, if you have lnaddr / lnurlp exposed, even through tor, then you're potentially still exposed? If you only have NWC and no listeners whatsoever, then maybe you're good.
But don't take my word for it please, because I haven't checked.
NWC is providing a limited communication protocol between apps and a wallet through relays. This the wallet itself does not need (and should not be) publicly accessible for it to be used by any apps and doing things like lnaddr/lnurlp.
A LNURL just needs a NWC permission to create an invoice.
it's another layer.
Thanks for coming over!
So if someone has a 3rd party distribution like Umbrel or Start9, and it takes a while for them to get an update, the thing to make sure is that:
correct?
it's an umbrel thing. Umbrel is releasing the Alby Hub in their store.
Start9 is exactly the same. I guess they like to test everything before releasing.
I think the same is true with Alby Hub and LND, LDK etc.
Was ~security too expensive?
I know it’s an annoying question (wHy diDn’T yOu pOsT iN mY tErrItOrY??) but yeah, why not? I’m interested, haha. The game theory of territories doesn’t make sense when the most important topics then aren’t posted there, but still end up in ~bitcoin.
Yes. And I’ve noticed from my own experience that posts I publish just in ~security don’t get much traction. When I cross-post, it ends up getting pretty expensive if I include him.
Interesting, thank you. This is very valuable feedback. I’m not sure yet what I’ll do with it, though.
Maybe there’s more feedback from others?
You should think about how often a post will be exclusive to ~security.
If that's uncommon, then you need to think about what the total cost of posts will be that are cross-posted with it and how likely someone is to recoup their sats.
For me, the ~econ fees had to come down because those posts often also include other territories, but ~Stacker_Sports was fine because those are usually solo.
Oh, interesting, I think that’s exactly what I’ve been thinking about with @ctfbot_
I post my write-ups there because it's where it belongs, never noticed 100sats was expensive, maybe because I don't post new items enough and in enough Territories to compare 🤔
It really depends on your goals.
If you want ~security to be a place stackers subscribe to for PSAs, then you need minimal post fees, i.e. 5 sats, slightly higher comment fees and curate posts hard through zaps in both ways. If you want it to be ~privacy "lite" then I'd recommend to just cut it in half.
I want stackers to have a place for anything ~security-related, without spam or moderation necessary on my part.
I want to recoup some of the costs with exclusive ~security events (@ctfbot_) and territory.watch/security to monitor the revenue (still need to update it regularly).
I'll let you know when you're territory is so good, I subscribed.
I'd go with 33 for posts and 3 for comments.
I kinda rushed it out after seeing no one had posted about it.
~security is not too expensive!
No worries and thank you for this additional data point!
I wonder about that a lot. Quite some things posted in ~bitcoin that should clearly be ~econ. Isn't there, like, a moderator who can clean this shit up?!
your wallet is the moderator
I see a good meme opportunity here
I updated!
...also, wasn't at risk, I presume. BUT WHATEVS
This year has been the year I log in just to check what hack is going to ruin my week and or life
optidisconnectinghissnwalletwhilestillfixinglnpubandnotfallingbacktounreviewedalternativestonotgetpwned🚀If you run Alby Hub reachable from the internet on anything older than v1.19.0, treat this as patch-now, not patch-this-weekend.
The advisory is narrow but serious: pre-1.19.0 Hubs with a publicly exposed management API could let a remote attacker send funds. LAN-only / behind auth / Tor-only deployments were the intended model — public clearnet exposure was the dangerous config.
Checklist:
One confirmed impacted user so far per Alby — still enough reason to audit exposure.