Lightning’s safety depends on timelocks, honesty assumptions, availability, and implementation correctness. Attackers may not need to steal immediately — locking liquidity, probing balances, or racing offline victims can still win.
Why this matters
Builders shipping POS, wallets, or routing services inherit LN’s adversarial reality. Ignoring known classes of griefing and past CVEs is negligence.
Congestion and jamming
Attackers can open paths or hold HTLCs to consume channel capacity, degrading payment success for others. Defenses are an active research and engineering area (limits, reputation, upfront fees, etc.).
Probing
Because routing reveals whether a payment can proceed, adversaries can probe channel balances more than naive privacy marketing suggests. Treat LN privacy as layered and incomplete.
Watchtowers and uptime
Revocation justice requires someone online to notice a breach. Watchtowers outsource detection; they do not remove the need for correct backups and timely justice transactions.
CVEs are part of the curriculum
Multi-implementation incidents (for example the 2019 disclosures affecting major daemons) show that interop + shared assumptions can fail together. Read disclosures for process lessons, not doom.
Common mistakes
- Marketing “Lightning is private” without caveats
- Running routing nodes with no capacity/HTLC metrics
- Skipping patch discipline because “it’s just testnet”