Payout Races and Congested Channels: A Formal Analysis of Security in the Lightning Network
Ben Weintraub, Satwik Prabhu Kumble, Cristina Nita-Rotaru, Stefanie Roos
Abstract
The Lightning Network, a payment channel network with a market cap of over 192M USD, is designed to resolve Bitcoin's scalability issues through fast off-chain transactions. There are multiple Lightning Network client implementations, all of which conform to the same textual specifications known as BOLTs. Several vulnerabilities have been manually discovered, but to-date there have been few works systematically analyzing the security of the Lightning Network. In this work, we take a foundational approach to analyzing the security of the Lightning Network with the help of formal methods. Based on the BOLTs' specifications, we build a detailed formal model of the Lightning Network's single-hop payment protocol and verify it using the Spin model checker. Our model captures both concurrency and error semantics of the payment protocol. We then define several security properties which capture the correct intermediate operation of the protocol, ensuring that the outcome is always certain to both channel peers, and using them we re-discover a known attack previously reported in the literature along with a novel attack, referred to as a Payout Race. A Payout Race consists of a particular sequence of events that can lead to an ambiguity in the protocol in which innocent users can unwittingly lose funds. We confirm the practicality of this attack by reproducing it in a local testbed environment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 323eec3a-e4ed-4598-b233-b8fbf3167273Cited by top-tier papers1
Ask how each one uses itBuilds on20
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- Concurrency and Privacy with Payment-Channel NetworksGiulio Malavolta, Pedro Moreno-Sanchez, Aniket Kate, Matteo Maffei et al.CCS 2017 · 307 citations
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- General State Channel NetworksStefan Dziembowski, Sebastian Faust, Kristina HostákováCCS 2018 · 249 citations
Related papers
- Blitz: Secure Multi-Hop Payments Without Two-Phase CommitsLukas Aumayr, Pedro Moreno-Sanchez, Aniket Kate, Matteo MaffeiUSENIX Security 2021 · 63 citations
- High Throughput Cryptocurrency Routing in Payment Channel NetworksVibhaalakshmi Sivaraman, Shaileshh Bojja Venkatakrishnan, Kathleen Ruan, Parimarjan Negi et al.NSDI 2020 · 61 citations
- Securing Lightning Channels against Rational MinersLukas Aumayr, Zeta Avarikioti, Matteo Maffei, Subhra MazumdarCCS 2024 · 4 citations
- On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by CryptocurrenciesPiyush Kumar Sharma, Devashish Gosain, Claudia DíazNDSS 2023
- Atomic Multi-Channel Updates with Constant Collateral in Bitcoin-Compatible Payment-Channel NetworksChristoph Egger, Pedro Moreno-Sanchez, Matteo MaffeiCCS 2019 · 108 citations
