{"id":18717,"date":"2020-02-25T13:00:00","date_gmt":"2020-02-25T13:00:00","guid":{"rendered":"http:\/\/ci027cfe66a00b26c3"},"modified":"2025-01-27T20:31:05","modified_gmt":"2025-01-27T20:31:05","slug":"what-we-can-learn-about-lightning-from-lntrustchain2-part-1","status":"publish","type":"post","link":"https:\/\/bitcoinmagazine.com\/technical\/what-we-can-learn-about-lightning-from-lntrustchain2-part-1","title":{"rendered":"What We Can Learn About Lightning From #LNTrustChain2: Part 1"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div><p>The first Lightning Network \u201ctorch relay\u201d debuted <a href=\"https:\/\/bitcoinmagazine.com\/articles\/lightning-torchs-bitcoin-payment-is-running-a-worldwide-marathon\">on January 19, 2019<\/a>, to spread adoption of second-layer Bitcoin payment protocol. When it concluded in April 2019, it boasted 278 participants and 56 countries visited. One year later, Hodlonaut, the person behind the torch inception started the <a href=\"https:\/\/twitter.com\/hodlonaut\/status\/1218948271323959298\" target=\"_blank\" rel=\"noopener\">relay again, on January 19, 2020<\/a>. After a few days, however, it was obvious that the new iteration of the torch was different, starting with a high rate of torches being stolen and ending with the chain being \u201ccancelled\u201d by sending the amount through tippin.me to an oblivious Jack Dorsey, CEO of Twitter, who had willingly taken the torch in its 2019 edition.&nbsp;<\/p>\n<p>Because of the way the chain was propagated through Twitter posts, the path of the Lightning Network \u201cTrust Chain\u201d (#LNTrustchain2) is somewhat easy to follow, and the data about specific payment requests (invoices) is available publicly. It can, therefore, provide us with a lot of insight into consumer-related aspects of Lightning Network adoption. Which client agents are being used the most often? Which mobile wallet services? Are custodial wallets prevailing?&nbsp;<\/p>\n<p>Following #LNTrustchain2 provides a perfect opportunity to measure the adoption of the Lightning Network. What other event on this global scale has users from all around the world, from mixed professions, from bitcoin plebs to CEOs, with all of their payment requests openly posted on Twitter?&nbsp;<\/p>\n<p>As a blockchain analyst, I was motivated by professional curiosity and an internal urge to spread knowledge about the anonymity aspects of Bitcoin and the Lightning Network. Several examples provided in this article have been selected specifically to expand public knowledge about the privacy deficiencies of particular solutions. <\/p>\n<p>In Part 1 of this series, I\u2019ll cover an overview of the data I gathered and will explain the methodology of acquiring the dataset. I will then focus on mobile wallets, mostly examining custodial services, but also showing the potential of a new evolution of wallets, including Phoenix and Breez.&nbsp;<\/p>\n<h2>Some Notes on Methodology<\/h2>\n<p>I started my research by gathering all the participants and their respective payment requests or \u201cinvoices.\u201d Out of 159 participants, there were 19 who either transacted on DMs or have since deleted the payment request, so those payment requests weren\u2019t visible for them. That\u2019s good for their privacy, as researchers (like myself) aren\u2019t able to dissect their data. <\/p>\n<p>Every Lightning Network <a href=\"https:\/\/wiki.ion.radar.tech\/tech\/lightning\/invoice#invoice-components\" target=\"_blank\" rel=\"noopener\">payment request<\/a> has the field \u201cnode_id\u201d which points to the owner\u2019s node. Why is this important? For now, let\u2019s consider private node setups, either on some sort of virtual private server (VPS) or through a home environment, mostly in the form of plug-and-play nodes (CASA, Nodl), Raspberry Pi nodes or desktop nodes (Zap).&nbsp;<\/p>\n<p>If the user\u2019s setup isn\u2019t running through Tor (The Onion Router), just the act of publishing the invoice publicly can provide a means for an adversarial entity to know the IP address of a node. No matter if TOR is active or not, an attacker can also use the node ID to collect all the public channels opened by the node owner and, obviously, corresponding bitcoin addresses. With the blockchain analytic tools like <a href=\"https:\/\/en.bitcoin.it\/wiki\/Privacy#Common-input-ownership_heuristic\" target=\"_blank\" rel=\"noopener\">common input clustering<\/a>, even a single public invoice can make one\u2019s full wallet balance visible to an adversary.&nbsp;<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2025\/01\/57_image-placeholder-title.png\" title=\"\"><\/figure>\n<p>By taking all 140 publicly visible invoices of the TrustChain2, I was able to draw a doughnut chart of all wallet providers. At least 56 percent of all wallets were used on mobile phones; 48.2 percent of total wallets were custodial, related to the use of either Bluewallet, Wallet of Satoshi or Dropbit. Private nodes accounted for 44 percent of total wallets used through different providers, like eclair mobile, or through some personal Lightning Network nodes (lnd or c-lightning on the backend).&nbsp;<\/p>\n<h2>Custodial Services: There Is a Method to This Madness!&nbsp;<\/h2>\n<p>Andreas Antonopoulos famously says, \u201cNot your keys, not your bitcoin.\u201d Similarly, for the Lightning Network, the adage would be <em>\u201cNot your node, not your sats.\u201d<\/em> When it comes to bitcoin, in 2020, even the worst bitcoin wallets give users the opportunity to back up their wallet seeds. It\u2019s important in terms of the ownership of the coins. For example, if a centralized wallet provider goes down, one\u2019s keys and bitcoin would follow.&nbsp;<\/p>\n<p>The same goes for the Lightning Network. The vast majority of the wallets used in the 2020 torch relay were either related to Wallet of Satoshi, Bluewallet or Dropbit \u2014 all custodial services. By decoding the invoices, we would get the receiver\u2019s node ID as owned by one of these three software providers.&nbsp;<\/p>\n<p>Custodial Lightning Network wallets are using their own node infrastructure to allow their users to interact on the Lightning Network layer (and usually are noncustodial on bitcoin on-chain side). The whole wallet user interface (UI) is just a layer on top of their centralized SQL database processing Lightning Network payments. I would compare using these wallets to writing I Owe You (IOU) statements in the balance book, kept by the wallet provider. Every custodial wallet fully manages its own node infrastructure (usually single node), so all the LN-related actions: opening\/closing channels, requesting payments, sending payments are done on behalf of the users. Knowing the ID of the node (seen in the payment request) can point us to the wallet provider (Wallet of Satoshi, Bluewallet or Dropbit).&nbsp;<\/p>\n<p>What would happen if their nodes were compromised or if their service stopped working? The outcome is easy to predict \u2014 the loss of the funds for their customers. (Dropbit app has already <a href=\"https:\/\/1ml.com\/node\/02a59dd887d4396178325ffb3f54b7fcb9ada9dd0d615caea2f2306d92a3692f6e\/history\" target=\"_blank\" rel=\"noopener\">fallen on hard times<\/a> at the time of writing.)<\/p>\n<p>Using custodial services does have some perks, although they some of them can be also achieved in a noncustodial setup (through private channels). These perks are related to unidentifiable channels and location data. Because custodial wallets use their own nodes for all the users, these users don\u2019t have to worry about protecting their IP addresses or be scared of mistakenly deanonymizing their bitcoin holdings.&nbsp;<\/p>\n<p>Luckily, custodial services don\u2019t have to be the answer to these concerns. With the new features constantly added to Lightning Network protocol <a href=\"https:\/\/github.com\/lightningnetwork\/lightning-rfc\/blob\/master\/00-introduction.md\" target=\"_blank\" rel=\"noopener\">(BOLTs)<\/a>, the new breed of Lightning Network wallets emerged.<\/p>\n<h2>Noncustodial Mobile Wallets: Anonymous and Secure<\/h2>\n<p>The perfect scenario for running a personal Lightning Network mobile wallet would include having a built-in node with private channels opened to the wallet provider\u2019s node. The first part, having your own node on a device, is a crucial component of being self-custodial. Even if any of the neighborhood nodes (with emphasis on the wallet provider\u2019s node) should go down, the node owner could return the funds locked in the payment channel through the force closing this channel. That\u2019s the suggested solution for closing channels where parties either disagree on their states or where one of the parties goes offline.&nbsp;<\/p>\n<p>What about deanonymizing the bitcoin addresses of a node owner? Both Breez wallet and Phoenix provide a \u201ctricky\u201d feature of allowing their users to create channels only to nodes. And these aren\u2019t just \u201cnormal\u201d Lightning Network payment channels \u2014 these are \u201cprivate\u201d channels. They aren\u2019t being \u201cgossiped\u201d by the Lightning Network protocols; in layman\u2019s terms, their existence isn\u2019t announced to the rest of the network. Even the activity on the bitcoin layer related to publishing commitment transactions isn\u2019t conclusive, leaving potential adversaries <a href=\"https:\/\/blog.bitmex.com\/lightning-network-part-7-proportion-of-public-vs-private-channels\/\" target=\"_blank\" rel=\"noopener\">in doubt<\/a> as to what commitment transactions have taken place.&nbsp;<\/p>\n<p>The core of this feature can be better explained by imagining Alice, the user of Breez or Phoenix. Alice wants to receive the torch payment, so she posts her payment request (invoice) under a previous tweet. Bob sees her invoice and decides to send her the torch. Decoding the request, he sees Alice\u2019s node ID and additional payload, called \u201crouting hints,\u201d with the wallet provider\u2019s respective node ID. The action of sending the payment would route the funds through the wallet provider\u2019s node, which is a one-hop neighbor of Alice\u2019s node and knows the private path.&nbsp;<\/p>\n<p>What would happen if we were to search Alice\u2019s node by ID in any <a href=\"https:\/\/1ml.com\/\" target=\"_blank\" rel=\"noopener\">Lightning Network explorer<\/a>? The result wouldn\u2019t exist, as her node isn\u2019t visible to the rest of the network.<\/p>\n<p>So far, we\u2019ve explored the data gathered from #LNTrustchain2 movement and we\u2019ve described the motivation behind the research. There was a line drawn between custodial and noncustodial Lightning wallets, with a reasoning why specific ways of accessing Lightning Network infrastructure may be dangerous.&nbsp;<\/p>\n<p><a href=\"https:\/\/bitcoinmagazine.com\/articles\/what-we-can-learn-about-lightning-from-lntrustchain2-part-2\">In Part 2<\/a>, we\u2019ll look at the privacy of private node instances and conclude the series with advice on how to take steps in preserving anonymity when using the Lightning Network.<\/p>\n<p><strong>Acknowledgements:<\/strong><\/p>\n<p><em>The author would like to thank <\/em><a href=\"https:\/\/jarretdyrbye.com\/\" target=\"_blank\" rel=\"noopener\"><em>Jarret Dyrbye<\/em><\/a><em> for his helpful comments on the article and dataset gathered. All the data and results gathered are a part of blockchain analysis where the end result is probabilistic and relates to a type of analysis performed on the source.<\/em><\/p>\n<p><em>This is an op ed contribution by Tony Sanak. Views expressed are his own and do not necessarily reflect those of <\/em>Bitcoin Magazine<em> or BTC Inc.<br \/><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The data about specific payment requests from #LNTrustchain2 can provide us with insight into consumer-related aspects of Lightning Network adoption.<\/p>\n","protected":false},"author":3415,"featured_media":3151,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[130,460],"class_list":["post-18717","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technical","tag-lightning","tag-lightning-network"],"author_data":{"id":3415,"name":"Tony Sanak","nicename":"tonysanak","avatar_url":"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2024\/12\/tony-sanak-promo-image-96x96.jpg"},"featured_image_url":"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2024\/11\/image-placeholder-title.jpg","_links":{"self":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts\/18717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/users\/3415"}],"replies":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/comments?post=18717"}],"version-history":[{"count":0,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts\/18717\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/media\/3151"}],"wp:attachment":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/media?parent=18717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/categories?post=18717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/tags?post=18717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}