Odaily Planet Daily reports that Bitcoin News posted on X, stating that Alby has confirmed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5; if the management API is exposed to the public internet, attackers may gain unauthorized access and transfer funds. To date, one user has been affected, while Alby Hub v1.19.0 and later versions are unaffected. Alby advises affected users to restrict public internet access to the management interface, immediately update to v1.24.0, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been resolved in the latest version.
Alby Hub v1.7.0 to v1.18.5 vulnerability exposes Management API, risking funds
KuCoinFlashShare
Alby Hub versions v1.7.0 through v1.18.5 are affected by a critical vulnerability that exposes the management API to potential attacks. If unsecured, attackers could access and transfer funds; one user has already been impacted. Alby recommends restricting API access, upgrading to v1.24.0, and changing unlock passwords. The BTC update includes fixes provided by Bitcoin Team Red and Project Loupe. Users are urged to act immediately to secure their assets.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.