Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you run your own node on the Lightning Network using the Alby Hub software, you have had one concrete job since September 9, 2026: check the version number. If it reads anything between v1.7.0 and v1.18.5, and the management interface is reachable from the open internet, an attacker can gain unauthorised access and drain funds, according to the provider. Which puts the answer to the central question right at the top: check the version, close off access from the internet, update to v1.24.0, and change the unlock password afterwards.
Everything else in this article answers the questions that follow from there. Who is actually affected by the flaw, how do you tell that your installation was never exposed in the first place, and why is the fix older than the warning now making the rounds in the trade press.
What Alby Hub is and who actually runs this software
Alby Hub is software that lets you run a node on the Lightning Network yourself. The Lightning Network is a payment layer built on top of Bitcoin that moves small amounts almost instantly and at very low fees: two participants open a payment channel and only the opening and closing of that channel are recorded on the blockchain. A node, in that picture, is the machine that keeps such channels open and forwards payments.
The difference from an ordinary wallet app is decisive in this case. An app on your phone connects to somebody else's service and has no address of its own on the network. Alby Hub, by contrast, is a program that runs permanently, on a small machine at home, on a rented server, or as an application on a desktop computer. And a program that runs permanently has an interface through which it is administered.
That interface is precisely what the September 9 report is about. The people affected are therefore those who settle their bitcoin payments themselves rather than having somebody settle them. For the variant hosted by Alby, none of the reports describes a case.
Which Alby Hub versions are affected: v1.7.0 through v1.18.5
The provider has rated the flaw as critical and drawn a clear line around the affected range: versions v1.7.0 up to and including v1.18.5, all of them releases from before August 2025. From the 1.19 series onwards the flaw is fixed. According to reports so far, exactly one user is confirmed as affected.
A CVE number, the internationally standard identifier for a vulnerability, does not appear in the September 9 reports. The provider has announced that technical details will follow later, as is customary with responsible disclosure: first as many operators as possible should update, then the precise workings of the attack are described. For you that means you cannot yet check the provider's assessment for yourself. The recommended course of action does not depend on it.
One point that tends to get lost in the excitement: the version range alone does not decide the matter. An old release on a machine reachable only within your own home network was, by the provider's description, never exposed. The version number is one half of the check, reachability the other.
Why only a publicly reachable management API is exposed
The management API is the interface through which Alby Hub is administered: opening channels, triggering payments, issuing access for apps. A programming interface of this kind is at heart an address that accepts commands. Sitting behind the front door of your own network, it can only be reached by someone already inside that network. Sitting openly on the internet, it can be reached by anyone who knows or finds the address.
By the provider's account, the flaw only becomes exploitable in that second situation. Anyone who has deliberately made their node reachable from outside, say to operate it from a phone while travelling, belongs to the group at risk. Anyone who only operates it inside the home network does not.
That distinction is why the first recommended measure is not the update but the lock-down. An update takes a few minutes and, if it comes to it, a restart. Taking access off the internet takes one move in the router and works immediately.

Checking your Alby Hub version: where the number sits and what it tells you
The Alby Hub interface carries an information page showing the version alongside the node backend in use; the release notes for v1.24.0 point to exactly that page. Read the string off there and compare it against the range above. Anything below 1.19 needs updating, regardless of whether your node was ever reachable from outside.
If you have no access to the interface, the installation itself offers a way in: the file name of the downloaded package carries the version, and with a container installation it is written into the image used. If none of these routes gives an unambiguous answer, treat the installation as affected and update.
The checks in the right order
Reachability first, then the version, then the update. That order is not a formality. Update first and you leave access open throughout the download and the restart. Lock down first and you take away the flaw's precondition, then handle the rest at your own pace.
Keep your keys offline: hardware wallets comparedThe fix is a good twelve months older than the warning
This is where the case gets more interesting than a routine call to update. For this article, cryptoticker.io retrieved the project's release overview on September 11, 2026 and evaluated the 40 most recent entries. The result puts the timeline in order.
The last affected release, v1.18.5, was published on July 31, 2025. The first entry of the 1.19 series in that overview is v1.19.1 of August 29, 2025; v1.19.2 followed the same day and v1.19.3 a day later. The current release, v1.24.0, dates from August 14, 2026. Between the first corrected release and the public warning of September 9, 2026 there is therefore a good twelve months.
One observation from the same evaluation belongs here, because it can cause confusion during the check: a standalone release numbered v1.19.0 does not appear in that overview, even though the coverage names it as the first corrected version. So if you search the list for v1.19.0 and come up empty, you have not searched wrong. What matters for you is the current release anyway, not the first corrected one.
cryptoticker.io compiled this evaluation itself on September 11, 2026. Method: retrieval of the project's release overview via the GitHub programming interface, evaluation of the 40 most recent entries by number and publication date. It remains open which code change exactly fixed the flaw, since the technical details have not yet been published. Nor is it possible to establish from outside how many operators are still running an old release today.
The release notes for v1.24.0 also list a series of hardening measures that all point in the same direction: sensitive calls such as access to the recovery words and to the log now require a key with full access; the limit on failed unlock attempts was moved from the individual address to the installation as a whole; the silent acceptance of an empty unlock password inherited from old releases was removed; and a security policy was added to the documentation. Whether any of these changes is connected to the flaw now reported, the provider does not say.
Updating to v1.24.0: these steps in this order
The provider recommends raising the installation to v1.24.0. The routes there differ depending on how you run it, but the pattern stays the same.
- End reachability from the internet before you do anything else.
- Check that you have a backup of the recovery words and the channel data. A node with open payment channels is not a program you can simply reinstall at will.
- Apply the update and restart the installation.
- Look at the information page to see whether the new number is actually there.
- Change the unlock password if the node was ever openly reachable.
A warning that comes from running Lightning nodes in general rather than from this report: restoring a node with open channels from an old backup risks publishing an outdated channel state. That can cost you funds. So read the provider's notes on backups before the update instead of working from memory.
Port forwarding, reverse proxy, tunnel: where reachability actually comes from
Hardly anyone makes their node public by accident. It happens at three typical points, and all three are deliberate decisions that are later forgotten.
The first is port forwarding in the router. It passes requests from the internet through to a device on the home network, and it stays in place until somebody removes it. The second is a web server placed in front, publishing the interface under an address of its own, often set up so the connection runs encrypted. The third is a tunnelling service that builds a connection from outside to inside without anything being changed on the router. The third route in particular is convenient and leaves no trace in the router to remind you later.
If you genuinely need access while out and about, you are better off putting it inside a private network that the phone dials into, rather than placing the management interface openly on the net. And anyone holding meaningful amounts sensibly separates the sum kept ready for everyday payments from the rest, which belongs on a device with no network connection. Which devices qualify and what sets them apart is covered in the hardware wallet comparison.

Changing the unlock password: why the update alone is not enough
The unlock password protects the running installation: without it, the software does not release its keys. The provider explicitly recommends changing it after the update if the installation was openly reachable before, and contacting the provider's security address on any suspicion of an incident.
The thinking behind it is simple. An update closes the door. What it does not undo is that somebody may have walked through that door beforehand and taken a key with them. Raise the version and leave the password as it is, and you have fixed the cause while leaving the possible consequence in place.
The same goes for the access you have granted to individual apps. Go through the list of those connections once after the update and remove anything you no longer use or cannot place.
What happens if you do nothing
Two things should be kept apart. Funds in payment channels are tied to keys that sit on your device; they do not vanish because a report appears, and they do not hang on a deadline either. There is no deadline in this case, unlike with a delisting at an exchange.
The risk is a different one: for as long as an affected release sits openly on the net, the route the provider describes stays open. And the technical details can be expected to be published at some point. From that moment the flaw is reproducible for anyone who cares to look for it. Anyone who has updated by then is out of it.
Run it yourself or have it held for you: what this case says about self-hosting
It would be the wrong conclusion to take from this report that running things yourself is a mistake. A node you run yourself makes you independent of a provider's opening hours, freezes and withdrawal deadlines. The price is the duty to keep software current, and that duty is exactly what has become visible here.
What the case shows is something more modest: the attack surface does not arise from holding the keys, but from being operable remotely. Add convenience and you add attack surface. That equation cannot be configured away, only entered into knowingly.
For most readers, a sober split follows from it. The amount you pay with day to day belongs in a software wallet or in a node that is conveniently reachable. The rest belongs on a device that is not attached to the network and makes nothing operable.
Ledger, BitBox02 and Core Lightning: the fourth wallet incident in four weeks
The case is one in a series. On August 21, 2026, BitBox closed three security holes with firmware 9.26.5; on August 25, Ledger fixed a flaw in its Ethereum app where the display could show something other than what was actually signed; and at the end of August a vulnerability in Core Lightning became known that forced node operators to act. Now Alby Hub joins them.
The cluster is no proof that self-custody has become less safe. It suggests rather that this field is now being searched and disclosed systematically. For you as an operator, one unspectacular habit follows: once a month, check whether a new release exists for every device and every piece of software that holds keys. That costs ten minutes and deals with most such reports before they reach you.
If you want first-hand evidence: the September 9 report is documented at The Hacker News, among other places, and the current release together with its release notes sits in the project's overview for v1.24.0.
Closing the Alby Hub flaw: what to take away
- Check reachability today, then the version. If the management interface is reachable from the internet and a release below 1.19 is running, take it off the net immediately. If you would rather keep your everyday amount in a lean application than in a node of your own, you will find the candidates in the software wallet comparison.
- Update to v1.24.0 and change the unlock password. Back up first, then update, then read the version number back. And separate the amount you move daily from the amount that just sits there; the devices for that are in the hardware wallet comparison.
- Put a monthly update slot in the calendar. Four incidents in four weeks are not an outlier but the normal state of an industry where people are actively looking. Ten minutes a month for every device and program that holds keys, plus a look at the software wallet comparison if you want to replace an application.
(As of September 11, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Core Lightning Security Vulnerability: What Node Operators Must Do Now
- Updated Core Lightning via Docker? How to Check the Security Fix Is Really There
- Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
- Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
- Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 2, 2026 10:31 PM

ECX Fork of Bitcoin: When the Snapshot at Block 973,728 Really Lands
Layertwo Labs is copying Bitcoin's ledger onto a new chain and crediting every bitcoin with one ECX. Our own measurement shows the three fork stages hang on difficulty periods, and the snapshot reported for October 31 will most likely fall on November 1.
April 17, 2026 10:14 PM

FIBE Berlin 2026 Review: Bitcoin, AI Trading & Tokenization at Europe's Biggest FinTech Conference
FIBE Berlin 2026 brought together the future of finance — from AI-powered crypto portfolios to Bitcoin self-custody and tokenized real-world assets.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 7, 2026 1:27 PM

Liquid Network: Around 4,000 Bitcoin Drained via a Peg-Out, and What L-BTC Holders Must Check Now
Around 4,000 Bitcoin drained out of the Liquid Network federation wallet on September 6, even though no key was stolen. The network is halted and redemption is blocked. Here is what you should check now as an L-BTC holder.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 17, 2026 1:12 AM

Securing BTCPay Server: Why Updating to 2.4.4 Alone Does Not Protect Your Lightning Node
The project behind BTCPay Server reports that bots are probing payment servers whose Lightning interface was exposed by hand. The update to 2.4.4 closes the public default route; a reverse proxy rule you built yourself it does not clear away.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
September 15, 2026 10:36 AM

Bitcoin Core 32.0 Arrives October 10: How to Check Whether Your Node Falls Out of Maintenance
The first release candidate for Bitcoin Core 32.0 has been out since September 14, with the release planned for October 10. With it, the 29 series loses its security updates - and our own count shows that affects 60 percent of reachable nodes.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
September 26, 2026 7:34 AM

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 9, 2026 1:14 PM

OKX Delists GODS, PRCL and DUCK: You Can Still Withdraw the Tokens Until November 7, 2026
OKX ended trading in GODS, PRCL and DUCK in August, but withdrawals stay open until November 7, 2026. What to do in those three months, where the tokens now sit in your account, and why the exchange leaves open what happens to them afterwards.
September 8, 2026 1:16 PM

STPT to AWE Swap: What Happens to Your Tokens on September 21, 2026
On September 21, 2026 the swap window from STPT to AWE closes for good. Only self-custody holders are affected: here is how to check in five minutes, and why your real deadline can fall earlier.
September 5, 2026 10:33 AM

ZIL Withdrawals Frozen: Why Your Zilliqa Balance Is Stuck After the Hard Fork
The Zilliqa hard fork of September 2, 2026 moved the ZIL balances of ten exchanges to new addresses. Three days later, deposits and withdrawals were still halted at the three venues we checked: what that means for your balance, what self-custodians are waiting for, and why the announced compensation is not a decision yet.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
More from CryptoTicker
