On September 9, 2026, Bitcoin Lightning Network and Nostr tooling company Alby disclosed a critical security flaw affecting older versions of Alby Hub, a Lightning-centric node and wallet. According to the company, versions v1.7.0 through v1.18.5 contained a vulnerability that occurred when the hub was publicly accessible from the internet.
The issue could allow an unauthorized attacker who reaches the hub's management API to gain entry and send funds. Alby stated that versions v1.19.0 and newer—released starting in late August 2025—are unaffected by the flaw. To the company's current knowledge, one user has been impacted and reported the details.
To address the security issue, Alby advises affected users to check their installed version, secure public access to their management interface by running the software behind a firewall or private network, and update immediately to the newest release, version v1.24.0. Additionally, exposed users are advised to change their unlock password after updating.
The disclosure follows recent security challenges across the Lightning-adjacent ecosystem. On August 3, 2026, non-custodial bridge protocol Boltz temporarily took its bitcoin, Lightning, and Liquid Network swaps offline following months of automated, AI-assisted probing and targeted exploits by resourceful groups.


