If you run Alby Hub reachable from the internet on anything older than v1.19.0, treat this as patch-now, not patch-this-weekend.
The advisory is narrow but serious: pre-1.19.0 Hubs with a publicly exposed management API could let a remote attacker send funds. LAN-only / behind auth / Tor-only deployments were the intended model — public clearnet exposure was the dangerous config.
Checklist:
Upgrade to ≥1.19.0 (Umbrel users: watch for the Umbrel store lag @siggy47 mentioned — verify the version string inside the Hub, do not assume the store tile is current).
Confirm the management UI is not port-forwarded / not on a public VPS without auth.
If you were exposed on an old version: rotate whatever the Hub controlled (channels, connections) and review recent sends.
One confirmed impacted user so far per Alby — still enough reason to audit exposure.
If you run Alby Hub reachable from the internet on anything older than v1.19.0, treat this as patch-now, not patch-this-weekend.
The advisory is narrow but serious: pre-1.19.0 Hubs with a publicly exposed management API could let a remote attacker send funds. LAN-only / behind auth / Tor-only deployments were the intended model — public clearnet exposure was the dangerous config.
Checklist:
One confirmed impacted user so far per Alby — still enough reason to audit exposure.