Some Vulnerabilities of Bitcoin’s Lightning Network

Written By
Erik
First Published
November 9, 2023
Last Updated
September 5, 2024
Estimated Reading Time
6 minutes
Lightning Network
In this article...

As Bitcoin’s Lightning Network usage has shot up even through the bear market – and it’s worth reminding ourselves of the near miracle it is: moving BTC across the world in seconds. – it’s still worth zooming in on the vulnerabilities.

There are still wrinkles to be ironed out. Usability and liquidity are two vulnerabilities of Bitcoin’s Lightning Network.

Before diving into the vulnerabilities and the potential solutions, let’s quickly recap what Lightning is.

Short Background on Lightning

The Lightning Network is a Layer 2 network that operates on a channel-based system. Two parties deposit funds to pay each other. This process saves them from having to wait for block confirmations before they can finalize transactions for goods or services. Even though it is not literally lightning-fast, settlement happens in a few seconds. It’s also cheap: think a penny. 

Wait, isn’t the use case of opening a channel with one user very limited? Well, the person with whom you opened the channel has probably already other open channels. This means you’re only a handful of channels away from any person on earth that uses Lightning. Your payment flashes through a series of channels before it reaches its destination.

In short, the Lightning Network significantly improves Bitcoin’s scalability and transaction speed. 

Some Lightning Usage Data

According to a report by Lightning company River, growth has been 1200% in two years, between August 2021 and August 2023.

Some other data points from the report:

  • In August 2023 the average transaction volume was 2.5 transactions per second. Some of the fastest-growing sectors that use Lightning: social tipping (think Nostr), streaming and gaming.
  • The average Lightning transaction size was around 44.7k satoshis, or $11.84.
  • In August 2023, an estimated $78 million was publicly routed. This is a 546% increase since August 2021 and translates to 900 million dollars in yearly volume.
  • River’s Lightning payment success rate was 99.7% in August 2023 across 308k transactions. 
  • Around 180 companies are Bitcoin Lightning companies (see picture) 
Bitcoin Lightning Companies
Lightning Companies – Map of October 2023. Source: River

Vulnerability #1: Usability

Even though usability is not a vulnerability in the technical sense, I still mention it here. Bad usability might slow down adoption and hence interest from developers to keep improving the protocol. 

A newbie that wants to use Lightning while keeping their own BTC keys, must install software to run their own Lightning node. They must ‘manually’ open a channel with a user to kick off their first transaction. While nowadays this software that allows you to do this (Umbrel, for example) is user-friendly, it’s still not something that the masses will do. Even for companies, it is probably a stretch to run their own nodes.

A much more popular alternative for the average Lightning-curious user is to download a Bitcoin/Lightning wallet app. Wallet of Satoshi, for example, is a mobile app for iOS and Android. BUT. It is a custodial wallet, which means that the app provider holds your funds on your behalf and handles all the technical aspects of the Lightning Network for you. Convenient, but not your keys…

Vulnerability #2: Failed Transactions

The issue that is in part responsible for failed transactions – and failed…

You're missing out on the goods!
Become a Premium Wealth Mastery Subscriber to read the whole article + get weekly investment strategies on crypto, altcoins, NFTs and more

Erik started as a freelance writer around the time Satoshi was brewing on the whitepaper.

As a crypto investor, he is class of 2020. More of a holder than a trader, but never shy to experiment with new protocols.

Discussion on "Some Vulnerabilities of Bitcoin’s Lightning Network"
You must Subscribe or Login to post a comment.
Additional Resources
Wealth Mastery
Subscribe Today!
Join the Wealth Mastery Investor Report

Join the Wealth Mastery Investor Report

By Lark Davis
Privacy Policy

Who we are

Our website address is: https://thewealthmastery.io.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data

Visitor comments may be checked through an automated spam detection service.

Join the Wealth Mastery Investor Report

By Lark Davis