Bitcoin Lightning wallet and infrastructure provider Alby has disclosed a critical vulnerability in older versions of its Alby Hub software that could allow attackers to gain unauthorized access to user funds. The company said one user is known to have been affected and urged customers running vulnerable, publicly accessible versions to update immediately.

Alby Hub is a self-hosted Lightning node and wallet provider that lets users manage Bitcoin payments on the Lightning Network without relying on custodial services. The vulnerability affects versions v1.7.0 through v1.18.5, according to the company's announcement on X. Alby recommends upgrading to v1.24.0 or later to patch the flaw.

The vulnerability stems from exposure in the management API layer, which could permit attackers to interact with affected nodes if those nodes were accessible over the public internet. A management API typically handles administrative functions like node configuration and balance queries. Alby's disclosure did not specify the attack vector or provide technical details beyond the affected version range.

The company's guidance prioritizes users who have deployed Hub on publicly routable networks. Alby stated that users running older versions on private or firewalled networks face lower immediate risk but should still patch. The single confirmed incident shows the vulnerability may not have been widely exploited in the wild, though the company's urge for immediate updates indicates the risk is material once a node becomes discoverable.

MSB Intel

Alby Hub operates in a segment of self-hosted Lightning infrastructure providers that include Umbrel, Start9, and myNode. These platforms serve users seeking to avoid custodial intermediaries, but they place the burden of security maintenance on operators. A vulnerability disclosure of this type is routine in open-source and self-hosted software ecosystems, where patching cycles depend on user action rather than centralized deployment.

The vulnerability disclosure occurred roughly three years after a separate critical flaw in Lightning Network implementations emerged across multiple node software vendors in 2023. That incident affected the protocol layer itself; this Alby issue is specific to its own Hub application. One user affected in a known deployment of Alby Hub is a narrow incident surface, but the company's emphasis on public accessibility means the risk scales with network exposure.

Alby has published the patched version and made the upgrade path public. The company did not disclose whether it has notified affected users directly or whether any funds were recovered from the one known incident. Users running Alby Hub must manually download and install the update; there is no automatic patching mechanism in self-hosted environments.