Alby, the company behind the Bitcoin Lightning Network and Nostr tooling suite Alby Hub, has disclosed a critical vulnerability affecting older versions of its self-hosted Lightning wallet that could let an attacker take over and drain funds from any instance left reachable from the public internet.
Unauthenticated Access to the Management API
In a disclosure posted September 9, 2026, Alby said it had confirmed a critical flaw in Alby Hub versions 1.7.0 through 1.18.5, released before August 2025, when the Hub is publicly accessible from the internet. According to the company, an attacker who can reach the Hub’s management API over the network can access it without authorization and send funds out of the wallet, effectively draining any exposed node. Alby urged affected users to immediately take internet-exposed instances offline, update to a patched version, and change their unlock password after updating, since the credential itself could have been exposed during the window the Hub was reachable.
Part of a Rough Stretch for Lightning-Adjacent Projects
The disclosure follows a difficult few weeks for Lightning Network-adjacent infrastructure: Boltz, a separate non-custodial bridge that moves bitcoin between the main chain, the Lightning Network and the Liquid Network, took its swap functionality offline on August 3, 2026, after its own security issue, and Bitcoin’s Liquid Network separately suffered a $320 million theft that white-hat hackers later helped partially recover. Security researchers have pointed to the growing use of AI-assisted attack tooling as a factor putting increased pressure on smaller, self-hosted Bitcoin infrastructure projects that lack the security resources of larger custodial platforms.

Leave a Reply