Alby flags critical flaw in older Hub versions that could expose funds
Alby said a critical vulnerability affects Alby Hub versions v1.7.0 through v1.18.5 if the management API is exposed to the public internet, creating a path for unauthorized access and possible fund transfers. The issue was highlighted in a post by Bitcoin News on X, which said Alby had confirmed the flaw. Alby added that one user is currently known to have been affected, while versions v1.19.0 and later are not impacted. The company advised affected users to restrict public access to the management interface, upgrade immediately to v1.24.0, and change their unlock password after updating. Alby also said the latest release fixes multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers.








