Alby confirms a critical Hub vulnerability in older versions, while a Nomic chain exploit lets an attacker double-spend nBTC on Osmosis.
Two separate security incidents hit the Bitcoin and IBC ecosystems this week. Alby confirmed a critical vulnerability in its self-hosted Hub software that could let an attacker drain funds from exposed nodes.
Around the same time, Osmosis disclosed an exploit on the Nomic chain that allowed a bad actor to double-spend nBTC and mint false vouchers. Both platforms moved quickly to contain the damage and notify users.
The timing of the two disclosures has drawn attention to the distinct risks of self-custody tools and cross-chain bridges.
Alby Hub Vulnerability Exposes Hot Wallets to Attack
Alby said the flaw affects Hub versions v1.7.0 through v1.18.5, all released before August 2025. The bug only becomes exploitable when a user’s management API sits publicly reachable on the internet.
An attacker who reaches that interface could gain unauthorized access and send funds out of the wallet. Alby’s Cloud Hub offering was not affected by this issue.
Additionally, Alby said one user has been impacted so far. The company said it has poured years of work into the project and that an incident like this “hits us hard.”
Alby credited security researchers at Bitcoin Team Red and Project Loupe for reporting several issues that have since been patched. Full technical details will follow later, in line with responsible disclosure practices.
Alby urged anyone running an affected version to restrict public access immediately and update to v1.24.0, the current release issued August 29, 2025. Users whose exposed Hub had internet access should also change their unlock password after updating.
https://t.co/0cMmlwtd7e
— Alby 🐝 (@getAlby) September 9, 2026
Moreover, Alby recommended running the Hub behind a firewall or private network rather than exposing it directly, noting that its NWC protocol does not require public reachability to function.
Community members echoed the update guidance online. Bitcoin commentator Rob Hamilton pointed to the incident as a reminder to keep hot wallet software current rather than delay patches.
Read also – Dogecoin Price Analysis: DOGE Cup and Handle Could Trigger Move to $0.10
Nomic Chain Exploit Lets Attacker Double-Spend nBTC
Osmosis said it became aware of a separate exploit targeting the Nomic chain, the network behind wrapped Bitcoin asset nBTC. The attacker found a way to double-spend nBTC and send falsified vouchers into the Osmosis ecosystem.
Osmosis clarified that its own chain and the IBC protocol were not compromised. The vulnerability instead lived in a custom forwarding mechanism built specifically for Nomic.
The exposure is significant given how deeply nBTC sits inside Osmosis liquidity. Osmosis said 39.84 nBTC of the total minted supply is held within Alloyed BTC, accounting for roughly 36% of that asset’s backing.
Recently, we became aware of an exploit on the Nomic chain. The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic.
39.84 nBTC of the…
— Osmosis 🧪 (@osmosis) September 9, 2026
Alby and Osmosis Respond With Fixes and Fund Freezes
Once the exploit surfaced, Osmosis said its moderation subDAOs froze both inflows and outflows tied to Nomic and Alloyed BTC.
Validators then carried out an emergency upgrade that froze 22.65 BTC sitting in the attacker’s address. Osmosis plans to bring a governance proposal to seize those frozen assets formally.
To cover any remaining shortfall, Osmosis said it will ask governance to draw on BTC held in the community pool. The goal, according to Osmosis, is restoring full backing for Alloyed BTC.
Alby, meanwhile, continues urging every Hub operator to check their version number and apply the latest patch without delay.





Be the first to comment