Alby Hub old versions have critical vulnerability, publicly exposed management API could lead to fund transfer

Cybersecurity
Odaily

Bitcoin News posted on X platform that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 through v1.18.5. If the management API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. Currently, 1 user is known to be affected, and Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public access to the management interface, update to v1.24.0 immediately, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.

AI Insights

Alby Hub disclosed a critical vulnerability in older versions that could let attackers transfer funds if the management API is publicly exposed. This raises security risk for self-custodial Lightning wallet/node users, especially those still on affected versions. However, only one user is known affected and patched versions already exist, so the impact is narrow and mainly hurts confidence in Alby Hub rather than the broader crypto market. Short-term bearish for the Alby Hub/Lightning wallet niche (weak).

Bearish
AI generated informational use. Not financial advice.
152