Alby has disclosed a critical vulnerability in its self-hosted Lightning Bitcoin wallet, Alby Hub, affecting versions v1.7.0 through v1.18.5, which could allow attackers to take over wallets and drain funds — but only where the Hub was exposed to the internet. At least one user has been affected, and Alby is urging those on older versions to immediately block outside access to the Hub's interface and update to v1.24.0. Full technical details of the flaw have not yet been released, in line with responsible disclosure practices, and users who ran an affected version while internet-exposed are advised to change their unlock password and contact Alby's security team.