Critical Vulnerability in Older Alby Hub Versions Could Expose Admin API and Lead to Fund Theft
Odaily News: Bitcoin News posted on X that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 to v1.18.5. If the admin API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. It is currently known that one user has been affected. Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public access to the admin interface, update immediately to v1.24.0, and change their unlock password after updating. Several issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.