Alby Reveals Critical Hub Vulnerability
Key Takeaways
- Alby says Hub v1.7.0-v1.18.5 had a flaw that only hit 1 known user.
- Lightning Network infrastructure security remains a work in progress. AI-assisted discovery is putting developers on their toes.
- Alby says v1.24.0 puts users back in the driver’s seat with tighter Hub security.
Lightning Project Alby Confirms Critical Flaw in Older Hub Versions
The team disclosed the issue on the social media platform X on Wednesday, stating: “We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet.”
This vulnerability, the official Alby X account wrote, could let an attacker who can reach the Hub’s management API get in without permission and send funds.
Alby continued:
“Alby Hub v1.19.0 (released Aug 29, 2025) or newer are unaffected. As with any incident of this kind, we are deeply sorry — above all for the users affected. To our current knowledge, one user has been impacted and thankfully reported these details. We have poured all our energy and resources of the past years into this project, and an issue like this hits us hard.”
For people who may be affected by the bug, Alby says users should check which version they have installed first thing. Then, if a user is on an affected version, they need to make sure to lock down public access to their Hub’s management interface and update right away to v1.24.0, the newest Alby Hub release. Alby also thanked the Bitcoin Red Team developers who “reported several issues, which have been fixed in the latest release.”
Affected users who were exposed to the internet should also change their unlock password after updating. The news follows the recent issue with Boltz, another Lightning Network-centric protocol that provides a non-custodial bridge. The platform essentially moves bitcoin between the main chain, Lightning Network, and Liquid Network using atomic or submarine swaps, which are HTLC-based. On Aug. 3, 2026, Boltz took swaps offline.
AI-Assisted Attacks Put Lightning Projects Under Pressure
At the time, the company said this wasn’t just one bug, but months of automated, artificial intelligence (AI)-assisted probing, a few contained exploits, and then a sharp acceleration. As they put it in their official statement, attackers “now iterate faster than a team our size can find and patch.”
After running their own AI-assisted scans, the Boltz team said they couldn’t safely turn swaps back on while “multiple resourceful groups” were actively targeting them. The fact of the matter is, AI is discovering bugs across the cryptocurrency ecosystem faster than ever before in history.
Both projects are Lightning-adjacent, open-source, and “you keep the keys” designs. Going forward, Alby’s team stresses that users need to run the latest version of the Hub. The firm also said that users should avoid exposing their Hub to the open and public internet. “We recommend running it behind a firewall or within a private network,” Alby emphasized.
