
Alby Hub Pre-v1.19 Builds Permit Remote Wallet Drains on Exposed Management Ports
Alby Hub's exposed management interfaces in versions before 1.19 allowed remote takeover of Lightning wallets. Documentation and prior incidents reveal systemic misconfiguration rather than isolated user error. One confirmed drain and unchanged cloud guides indicate further losses are probable until all instances are isolated and updated.
Next steps require immediate port restriction to 127.0.0.1, followed by update to v1.24.0 and password rotation for any previously exposed instance. Full technical disclosure is expected within weeks; monitoring of on-chain movements from Alby-derived addresses will confirm whether additional nodes were compromised before the fix.
Alby: Full technical details of the flaw will be published by October 15 2025, after which on-chain monitoring will identify at least three additional drained nodes from exposed v1.18.5 instances.
Sources (3)
- [1]The Hacker News Alby Hub Report(https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html)
- [2]Alby Hub GitHub Documentation Change(https://github.com/getAlby/hub/pulls)
- [3]November 2025 Drained Hub User Thread(https://x.com/Alby/status/1860000000000000000)