Bitcoin wallet flaw in Alby Hub could have let attackers drain funds
A critical bug in the self-hosted Lightning wallet exposed users who opened their Hub to the internet, though the vendor says there is no sign it was used in the wild.

Key points
- Alby has patched a critical flaw in Alby Hub, a self-hosted Bitcoin Lightning wallet, that could let a remote attacker take over a wallet and send its funds.
- Only users who had made their Hub reachable from the internet were at risk; Hubs running only on a home network were not exposed.
- The bug affects Alby Hub versions v1.7.0 and later, and owners are urged to update immediately.
- Alby says it has no evidence the flaw was exploited before disclosure.
A company that makes Bitcoin wallet software has warned of a serious security hole that could have let strangers on the internet empty a user's wallet.
The company, Alby, builds a product called Alby Hub. It is a self-hosted Lightning wallet, which means the owner runs the software themselves, on their own computer or a small server at home, and it holds their bitcoin directly. There is no bank or exchange in the middle.
That design gives the owner full control. It also means that if the software has a bug, the owner carries the risk.
What went wrong?
Alby found a critical flaw in Alby Hub that could let an attacker take over the wallet and move the money out. The catch: the attacker needed to be able to reach the Hub over the internet.
Many users run Alby Hub only on their home network, where it is not visible to the outside world. Those users were not exposed. The people at risk were those who had deliberately opened up their Hub so they could reach it from anywhere, for example from a phone while travelling.
For those users, an attacker who found the Hub online could have used the flaw to control it as if they were the owner.
The bug affects Alby Hub starting at version v1.7.0. Alby has released a fixed version and is telling every user to update straight away.
Was anyone actually robbed?
Alby says it has no evidence the flaw was used against real users before the fix went out. The company found the problem, patched it, and then disclosed it, first reported by The Hacker News. That is the usual and safer order of events.
Still, absence of evidence is not evidence of absence. Anyone who ran an internet-exposed Hub on an affected version should assume their setup was reachable and act accordingly.
What should Alby Hub owners do now?
Update to the latest version of Alby Hub today. Do not put it off.
After updating, check whether your Hub really needs to be open to the internet. If you only ever use it from home, close that door. If you do need remote access, put the Hub behind a VPN, a private tunnel that only you can enter, rather than exposing it directly.
It is also worth reviewing recent wallet activity for any payment you do not recognise. Lightning payments are fast and, once sent, cannot be called back.
Why this matters beyond Alby
Self-hosted crypto wallets are popular for a good reason. They cut out middlemen and give people direct control of their money. They also shift the security work onto the owner.
A bank would push a fix to its own servers overnight and most customers would never know. With a self-hosted wallet, the fix only helps the people who install it. That is the trade-off of running your own infrastructure, and it is why vendors like Alby lean hard on users to update the moment an advisory lands.
This incident is a reminder that "self-hosted" and "secure by default" are not the same thing. Exposing any wallet, node or admin panel directly to the internet raises the stakes on every bug the software might have, known or not.



