Alby Hub’s Exposure, Not Just Version, Decides Risk
Alby warned that a critical flaw in Alby Hub could let attackers take over internet-exposed wallets, and said one user has already been affected. The vulnerable releases are v1.7.0 through v1.18.5; builds from v1.19.0 onward are not affected, and the current release is v1.24.0.
The issue sits in the web management interface that controls the wallet. If that page was reachable from the public internet, an attacker who found the flaw could use it to steer the wallet and send funds, so the exposure path matters as much as the version number. Alby has not said whether updating alone removes any access an attacker already had.
For operators, the lasting question is whether the Hub was ever exposed outside the private network. A patched Hub that was publicly reachable may still carry cleanup risk that a version check alone does not answer.