Updated
Updated · The Hacker News · Sep 9
Alby Warns v1.7.0-v1.18.5 Flaw Could Let Attackers Drain Bitcoin Wallets
Updated
Updated · The Hacker News · Sep 9

Alby Warns v1.7.0-v1.18.5 Flaw Could Let Attackers Drain Bitcoin Wallets

3 articles · Updated · The Hacker News · Sep 9

Summary

  • One user has been affected by a critical Alby Hub flaw that could let attackers take over a wallet and send funds if the management interface was exposed to the internet.
  • Versions v1.7.0 through v1.18.5 are affected, while v1.19.0 and later are not; Alby told users on older builds to first block outside access, then update to v1.24.0.
  • Port 8080 exposure is central to the risk: Alby says exposed users should change their unlock password after updating, but has not disclosed the bug or whether updating alone removes any attacker access.
  • Documentation changes on Sept. 7 added warnings against putting Alby Hub on the public internet and changed Docker defaults, even as some cloud setup guides still described internet-open configurations on Sept. 9.

Insights

What hidden flaw allowed attackers to drain exposed Alby Hubs, and did victims lose everything?
Are your self-hosted crypto funds truly safe, or is a default port setting inviting hackers?