Skip to content

List of Lightning Network technical issues, bugs, flaws, and exploits.

License

Notifications You must be signed in to change notification settings

davidshares/Lightning-Network

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

52 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Lightning Network Lightning Network Flaws

WARNING: If you try to use the Lightning Network (LN) you are at HIGH RISK of losing funds and it is not recommended or safe to do at this time or for the foreseeable future.

Below is a chronological list which shows that Lightning Network has been drowning in technical issues, bugs, flaws, critiques, and exploits. It's over-promised tech that doesn't deliver on decentralization and a long ways from being functional and safe for users.

2015

February 28, 2015: Lightning Network whitepaper is officially released

May 26, 2015: Joseph Poon and Tadge Dryja address scalability issues and the Lightning Network

2016

February 28, 2016: One of the first looks and deep dives into theoretical issues with Lightning Network, exploring various subjects such as network semi-decentralized topography, routing problems, liquidity issues, privacy, fees, channel balancing, and DDoS attacks. https://www.coindesk.com/markets/2016/02/28/lightnings-balancing-act-challenges-face-bitcoins-scalability-savior/

2017

June 26, 2017: Mathematical Proof That the Lightning Network Cannot Be a Decentralized Bitcoin Scaling Solution https://medium.com/@jonaldfyookball/mathematical-proof-that-the-lightning-network-cannot-be-a-decentralized-bitcoin-scaling-solution-1b8147650800

December 15, 2017: How The Banks Bought Bitcoin (The truth about the lightning network) https://www.youtube.com/watch?v=UYHFrf5ci_g

2018

January 20, 2018: Lightning Network May Not Solve Bitcoin’s Scaling ‘Trilemma’ https://www.coindesk.com/lightning-network-may-not-solve-bitcoins-scaling-trilemma

February 18, 2018: Rick Falkvinge reacts to the Lightning Network https://www.youtube.com/watch?v=DFZOrtlQXWc

February 21, 2018: Bitcoin Lightning Fraud? Laolu Is Building a ‘Watchtower’ to Fight It https://www.coindesk.com/laolu-building-watchtower-fight-bitcoin-lightning-fraud

March 13, 2018: New form of 51% attack via lightning's revocation system possible? https://lists.linuxfoundation.org/pipermail/lightning-dev/2018-March/001080.html

March 21, 2018: Lightning Network DDoS Sends 20% of Nodes Down https://www.trustnodes.com/2018/03/21/lightning-network-ddos-sends-20-nodes

May 29, 2018: Why The Lightning Network Does not Scale https://www.youtube.com/watch?v=yGrUOLsC9cw

April 11, 2018: How Bitcoin Lightning Channels Work https://www.youtube.com/watch?v=pOZaLbUUZUs

June 21, 2018: The 3 biggest LN flaws plus further critiques https://www.quora.com/What-is-the-biggest-flaw-of-the-Bitcoin-Lightning-network/answer/Marius-Kramer

June 25, 2018: Study finds that the probability of routing $200 on LN between any two nodes is 1% https://diar.co/volume-2-issue-25/

October 10, 2018: Watchtowers (third party services) are introduced as a way to monitor your funds when you can't be online 24/7 so they aren't stolen https://medium.com/@akumaigorodski/watchtower-support-is-coming-to-bitcoin-lightning-wallet-8f969ac206b2

2019

January 17, 2019: 18 Months Away? Latest Lightning Network Study Calls System a 'Small Central Clique' https://news.bitcoin.com/18-months-away-latest-lightning-network-study-calls-system-a-small-central-clique/

February 20, 2019: The current state of Bitcoin companies & dealing with Lightning Network ⚡Highlights: Hard to implement, takes a ton of man hours, with no return on investment. LN adds zero utility. The only reason some companies support it is for marketing reasons.

February 20, 2019: Current requirements to run BTC/LN: 2 hard drives + zfs mirrors, need to run a BTC full node, LN full node + satellite, Watchtower and use a VPN service. And BTC fees are expensive, slow, unreliable.

February 22, 2019: Listen to this great talk on the problems and complexities of using HTLC's on the Lightning Network ⚡️, and possible alternatives.

February 23, 2019: 5 Things I Learned Getting Rekt on Lightning Network

February 25, 2019: Lightning Network bank-wallet is "kind of centralized but it has to be this way if you want mass-adoption"

February 28, 2019: Decentralized path routing is still an unsolved problem for Lightning Network (currently "source routing" works at this scale)

February 28, 2019: "Out of the 1,500 orders submitted on the first day using Lightning Network, only around 10 percent were successful" https://breakermag.com/i-ordered-lightning-pizza-and-lived-to-tell-the-tale/

March 1, 2019: Lightning Network has become a complete train wreck. Oh by the way, it's no longer 18 months but YEARS until it's ready for mass-consumption.

March 4, 2019: Lightning users must be online to make a payment, funds must be locked to use, is a honey pot, completion rate deminishes with high value payments, and more https://medium.com/starkware/when-lightning-starks-a90819be37ba

March 17, 2019: TIL that Lightning Network conceptual design and focus to layer 2 scaling for BTC was introduced in February 2013, over 6 years ago (LN whitepaper released February 2015, 4 years ago)

March 21, 2019: Understanding the cost of trapped liquidity in the Lightning Network https://medium.com/@peter_r/understanding-the-cost-of-trapped-liquidity-in-the-lightning-network-part-1-7179a24d5791

March 22, 2019: Lightning Fails to Strike (Again) https://www.youtube.com/watch?v=AzaEd2RQuRw

March 28, 2019: Visualizing HTLCs and the Lightning Network’s Dirty Little Secret https://medium.com/@peter_r/visualizing-htlcs-and-the-lightning-networks-dirty-little-secret-cb9b5773a0

March 29, 2019: Analysis Shows Lightning Network Suffers From Trust Issues Exacerbated by Rising Fees https://news.bitcoin.com/analysis-shows-lightning-network-suffers-form-trust-issues-exacerbated-by-rising-fees/

April 24, 2019: Forget 18 months: it’s now 30-50 years until Lightning Network is ready

May 29, 2019: "PSA: The Lightning Network is being heavily data mined right now. Opening channels allows anyone to cluster your wallet and associate your keys with your IP address."

August 30, 2019: Lightning Network security alert: Security issues have been found in various lightning projects which could cause loss of funds! https://lists.linuxfoundation.org/pipermail/lightning-dev/2019-August/002130.html

September 10, 2019: Lightning Network dev: "We've confirmed instances of the CVE being exploited in the wild. If you’re not on the following versions of either of these implementations then you need to upgrade now to avoid risk of funds loss" https://lists.linuxfoundation.org/pipermail/lightning-dev/2019-September/002148.html

September 27, 2019: Lightning Network Security Vulnerability Full Disclosure: CVE-2019-12998 / CVE-2019-12999 / CVE-2019-13000 https://lists.linuxfoundation.org/pipermail/lightning-dev/2019-September/002174.html

September 28, 2019: Andreas Brekken: "I've been asked quite a bit why I took down the largest Lightning Network node, LN.shitcoin.com. Constant anxiety was the deciding factor. When a channel is created, the receiver of the channel was not required to verify the amount of the funding transaction"

October 21, 2019: Researchers Uncover Bitcoin ‘Attack’ That Could Slow or Stop Lightning Payments https://www.coindesk.com/researchers-uncover-bitcoin-attack-that-could-slow-or-stop-lightning-payments

October 23, 2019: 4 BTC stolen using Lightning Network

2020

January 1, 2020: The Final Word on the Lightning Network https://read.cash/@jonald_fyookball/the-final-word-on-the-lightning-network-de7e259c

January 7, 2020: New paper on Lightning Network simulates lower & higher txn rates and summarize the rates of failed txns in Fig 22….at 7,000 transactions per day one-third of them fail

January 13, 2020: LN users are leaking their blockchain data by using centralized Lightning Network node operators and wallets. 90K LN non-cooperative channel closures were identified https://blog.bitmex.com/lightning-network-part-6-over-60000-non-cooperative-channel-closures/

February 13, 2020: 8 Criticisms of Lightning Network https://old.reddit.com/r/btc/comments/f36wck/lightning/fhh2mav/

February 18, 2020: Lightning Network is Vulnerable to Congestion Attacks https://medium.com/blockchains-huji/congestion-attacks-in-payment-channel-networks-b7ac37208389

February 20, 2020: Bitcoin’s Lightning Network Is Growing ‘Increasingly Centralized,’ Researchers Find https://www.coindesk.com/bitcoins-lightning-network-is-growing-increasingly-centralized-researchers-find

August 27, 2020: Flood & Loot: A Systemic Attack On The Lightning Network https://arxiv.org/pdf/2006.08513.pdf

September 2020: LN channels cannot hold more than 483 htlcs at a time, regardless of the channel capacity. Sending 483 micro-payments to yourself and holding on to the htlcs is enough to incapacitate a channel for up to two weeks https://archive.is/ldWRd

October 8, 2020: Lightning Vulnerability Discovered; LND Node Operators Urged to Upgrade ASAP https://www.coindesk.com/lightning-vulnerability-ind-node-operators-upgrade-asap

October 21, 2020: Two Lightning Network CVE's were made public:

October 29, 2020: PSA: High onchain BTC fees have impact for you Lightning Channels: Pre negotiated fees might not be sufficient for your commitment tx to be included in case of force close https://archive.is/ECr4p

2021

February 18, 2021: The Lightning Network (LN) is semi-custodial banking https://old.reddit.com/r/btc/comments/lml76q/the_lightning_network_ln_is_semicustodial_banking/gnwa42b/

February 28, 2021: Congestion Attacks in Payment Channel Networks

March 15, 2021: A recap of events over the last 6 years of Lightning Network https://threadreaderapp.com/thread/1366411780633862147.html

March 26, 2021: Real-life example of a LN user trying to use Lightning but encounters various problems and errors:

March 28, 2021: Real-life example of a LN user trying to use various Lightning mobile wallets and none of them worked (multiple errors for each) https://archive.is/klS2X

April 13, 2021: Video discussion with LN engineer about pros and cons of LN. Tidbits include that LN transactions always require onchain transactions to be finalized/settled (problematic due to high fees), initial payment channels still an issue for new users, using LN service providers is a trust issue, not decentralized, using zero-conf to create channels is highly risky, must be online to use LN, constant backups needed so you don't lose funds, LN needs more forks to work (such as Taproot and El-Too) https://odysee.com/@DigitalCashNetwork:c/Lightning-Network:c

April 21, 2021: Popular Lightning wallet Phoenix had to shut down on-the-fly channel creations and other features due to high BTC transaction fees, which is another example of how poorly LN operates with a high fee base layer. https://archive.ph/RRzvU#high-mempool-size-impacts

September 13, 2021: CoinDesk research covers Lightning Network vulnerabilities and attack vectors such as griefing, eclipse attack, pinning, and floot & loot. https://downloads.coindesk.com/research/Lightning+Network+-+CoinDesk+Research+-+2021.09.pdf

September 20, 2021: Custodial Lightning Network Service Attack Discovered — Hacker Strikes 6 LN Custodians

September 26, 2021: Why the Bitcoin Lightning Network is Satoshi Nakamoto’s Worst Nightmare

October 4, 2021: Three new Lightning Network vulnerabilities were disclosed affecting multiple LN implementations. These vulnerabilities can be exploited in a wide range of attacks, going from fee blackmailing of node operators, burning liquidity of your competing LSPs or even stealing your counterparty channel balance if you avail mining capabilities. Exercise of the vulnerability revealed that a majority of the balance funds can be at loss. CVE-2021-41591/ CVE-2021-41592 / CVE-2021-41593 "Dust HTLC Exposure Considered Harmful." https://lists.linuxfoundation.org/pipermail/lightning-dev/2021-October/003257.html

November 3, 2021: Lightning Network channel jamming is when a malicious entity blocks up liquidity in the lightning network, by making a payment to themselves, via third party channels and then never revealing the secret, such that the payment never completes. The main idea behind jamming is occupying the capabilities of routing nodes to forward payments by making fake payments and never finalizing them. For the attack duration, it becomes impossible for routing nodes to forward other (honest) payments. To jam certain channels, an attacker pretends to make a payment to themself via those channels, and never releases the secret on the receiver side. https://blog.bitmex.com/preventing-channel-jamming/

2022

January 9, 2022: A Critical Review of the Lightning Network

February 16, 2022: Lightning Network speed update - as a service, it is hard to choose reliable LN routing peers that forward payments quickly. Plenty of nodes have bad response times and do not maintain proper liquidity in their channels, which makes payments slow. https://blog.lnrouter.app/lightning-payment-speed-2022

February 19, 2022: Sharp-eyed Bitcoin community members discover that Lightning Network developers working for Lightning Labs are part of the World Economic Forum (WEF). The WEF is well known for being a world government sanctioned and banker elite conglomerate that runs the global financial system in a centralized top-down authoritarian way. This discovery helps to shine light on the centralized goals of the Lightning Network.

February 19, 2022: Lightning Network user: "Of my node's last 100,000 forwarded payments, only 932 succeeded." https://twitter.com/fiatjaf/status/1495037429144825860

February 21, 2022: Lightning Network faces many challenges, such as 1) while technically two-party payment channels can exist off-chain forever, in practice they suffer from liquidity depletion bounding their lifetime, 2) two-party payment channels occupy significant block space per user when they get opened/closed, setting a bound on the number of LN users concurrently, and 3) multi-hop trust-minimized routing may cause even more channel closings (in-flight HTLCs leading to onchain claims).

April 4, 2022: Lightning Network -- Fundamental Limitations. Basic arithmetic is used to derive limitations of the Lightning Network (LN) https://www.truthcoin.info/blog/lightning-limitations/

April 8, 2022: Lightning Network developer writes, "Lightning Network is - as of now - UNRELIABLE by design." https://twitter.com/renepickhardt/status/1512324320151977990

May 3, 2022: Short Paper: A Centrality Analysis of the Lightning Network - "Overall, we can deduce that the Lightning Network is highly centralized."

June 30, 2022: Over half of all Lightning Network capacity is controlled by a total of 4 entities. One of the key concerns with a network like Lightning is that it becomes more and more centralized over time, not less (unlike L1). https://twitter.com/sethforprivacy/status/1542477206672359424

August 5, 2022: Lightning Network Dev Confessions - LN does not scale, has bad privacy, large payments don't work, too complicated, liquidity one directional, hard to run a node, etc.

August 10, 2022: University of Illinois researchers have discovered a critical vulnerability in Bitcoin’s most popular second layer scaling protocol, the Lightning Network https://protos.com/researchers-discover-critical-bitcoin-lightning-network-vulnerability/

October 10, 2022: Bug freezes bitcoin inside Lightning Network for hours after a critical validation bug was found https://protos.com/taproot-bug-freezes-bitcoin-inside-lightning-network-for-hours/

October 18, 2022: The Bitcoin Lightning Network SUCKS - Here's Why https://www.youtube.com/watch?v=2kvT0nu8z_4

November 1, 2022: Lightning Network releases emergency update after another critical bug on LND nodes is discovered https://cointelegraph.com/news/lightning-network-releases-emergency-update-after-critical-bug-on-lnd-nodes

2023 and Beyond

Unfortunately, the Lightning Network has been a disappointment since its inception in 2015. It has been an utter failure and has not delivered, and instead has led to centralization and reliance on custodial services and third-party companies. We have decided to stop following the development of the Lightning Network in this repository, as we believe it is a waste of time and resources. We recommend using a more reliable, secure, functional, and decentralized cryptocurrency, such as Bitcoin Cash (BCH), which has been working just fine since the Genesis Block in 2009.


Contributing

If you want to contribute to this list, please see CONTRIBUTING.md.

About

List of Lightning Network technical issues, bugs, flaws, and exploits.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published