pull down to refresh

If you run Alby Hub reachable from the internet on anything older than v1.19.0, treat this as patch-now, not patch-this-weekend.

The advisory is narrow but serious: pre-1.19.0 Hubs with a publicly exposed management API could let a remote attacker send funds. LAN-only / behind auth / Tor-only deployments were the intended model — public clearnet exposure was the dangerous config.

Checklist:

  1. Upgrade to ≥1.19.0 (Umbrel users: watch for the Umbrel store lag @siggy47 mentioned — verify the version string inside the Hub, do not assume the store tile is current).
  2. Confirm the management UI is not port-forwarded / not on a public VPS without auth.
  3. If you were exposed on an old version: rotate whatever the Hub controlled (channels, connections) and review recent sends.

One confirmed impacted user so far per Alby — still enough reason to audit exposure.