โ ๏ธ Your seed phrase isn't the only thing worth protecting.
Alby Hub just disclosed a vulnerability that lets attackers drain your wallet without ever touching it.
If its management portal is exposed to the public internet, an attacker can access your wallet and send funds directly.
Hot wallets and nodes carry a risk most people overlook.
Compromise the software, server, or admin interface, and attackers can use the wallet's own signing capabilities to move funds without your seed phrase.
If you're on Alby Hub:
๐ธ Update to the latest version now
๐ธ Keep the management interface off the public internet
๐ธ For long-term or infrequent holdings, a hardware wallet keeps your keys and signing air-gapped
THE BLOCK: Bitcoin Lightning wallet and infrastructure provider Alby has confirmed a critical vulnerability affecting older versions of its Alby Hub software that could allow attackers to gain unauthorized access and send funds.
Alby said one user is known to have been affected and urged users running vulnerable, publicly accessible versions to update immediately.