
Alby Warns Older Hub Versions Expose Users to Fund Theft Risk

Alby Warns Older Hub Versions Expose Users to Fund Theft Risk
WEEX View
- The main variable now is whether additional compromised setups emerge beyond the single known case, especially among users who exposed the management interface publicly.
- Market attention should center on patch adoption rather than broad ecosystem fallout. Alby has said versions 1.19.0 and later are not affected, while recommending an immediate move to version 1.24.0 for impacted users.
- For self-custody infrastructure, the incident puts focus on operational security around internet-facing admin tools, password rotation, and whether projects tighten default access controls after vulnerability disclosures.
Alby said a critical vulnerability has been identified in Alby Hub versions 1.7.0 through 1.18.5 that could allow unauthorized fund transfers if the management API is exposed to the public internet, with one user currently known to have been affected.
According to Alby, the vulnerability affects a defined range of older Alby Hub releases, from version 1.7.0 to 1.18.5. The attack condition is specific: the management API must be reachable from the public internet. In that case, an attacker may be able to gain unauthorized access and transfer funds.
Alby said one user is currently known to have been affected. The company did not disclose further details about the loss, the exploit path, or whether more cases are under investigation. It also did not indicate any broader compromise of versions 1.19.0 and above, which it said are not affected by this issue.
As mitigation, Alby urged affected users to restrict public access to the management interface, update immediately to version 1.24.0, and change their unlock password after upgrading. The company also said the latest release fixes multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers.
The disclosure points to a contained but practical security issue rather than a systemwide breakdown. Based on Alby’s statement, the risk depends on deployment configuration, which means exposure is not uniform across all users running the affected versions.
Why It Matters
Security flaws in wallet and node-management infrastructure matter because they can turn routine configuration mistakes into direct fund-loss events. In this case, the issue touches software used to manage bitcoin and Lightning-related activity, where self-custody often leaves users directly responsible for securing admin endpoints.
The disclosure also reinforces how smaller, targeted vulnerabilities can still have outsized importance for user trust. Even without evidence of widespread losses, confirmed unauthorized transfer risk can push operators to review access settings, accelerate upgrades, and demand clearer security defaults from wallet infrastructure providers.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVisa Stablecoin Settlement Run Rate Tops $20 Billion
Visa said its stablecoin settlement run rate now exceeds $20 billion annually, up from $3.5 billion about ten months ago, as it expands stablecoin-linked card programs and launches a revolving credit product with Credit Coop.
VAST Raises About 3 Billion RMB in Series B Financing
AI 3D company VAST said it completed Series B and B+ financing totaling about 3 billion RMB, led by Matrix Partners, and released its Tripo P2.0 model as it expands infrastructure and commercialization.
Tether, Fasanara Capital Launch $400 Million Private Credit Fund
Tether and Fasanara Capital have launched StableFund, a $400 million private credit fund targeting short-term, asset-backed financing for small and medium-sized enterprises, with a goal of attracting $3 billion in third-party institutional capital.
U.S. Bancorp Tests USBDC Stablecoin for Cross-Border Transfers
U.S. Bancorp said it completed a cross-border payment pilot using its USBDC stablecoin on Stellar between institutions in North America and Europe, while testing issuance, redemption, freezing and recovery functions on its internal digital asset platform.



