Securing Lightning Channels against Rational Miners
Lukas Aumayr, Zeta Avarikioti, Matteo Maffei, Subhra Mazumdar
Abstract
Payment channel networks (e.g., the Lightning Network in Bitcoin) constitute one of the most popular scalability solutions for blockchains. Their safety relies on parties being online to detect fraud attempts on-chain and being able to timely react by publishing certain transactions on-chain. However, a cheating party may bribe miners in order to censor those transactions, resulting in loss of funds for the cheated party: these attacks are known in the literature as timelock bribing attacks. In this work, we present the first channel construction that does not require parties to be online and, at the same time, is resistant to timelock bribing attacks. We start by proving for the first time that Lightning channels are secure against timelock bribing attacks in the presence of rational channel parties under the assumption that these parties constantly monitor the mempool and never deplete the channel in one direction. The latter underscores the importance of keeping a coin reserve in each channel as implemented in the Lightning Network, albeit for different reasons. We show, however, that the security of the Lightning Network against Byzantine channel parties does not carry over to a setting in which miners are rational and accept timelock bribes. Next, we introduce CRAB, the first Lightning-compatible channel construction that provides security against Byzantine channel parties and rational miners. CRAB leverages miners' incentives to safeguard the channel, thereby also forgoing the unrealistic assumption of channel parties constantly monitoring the mempool. Finally, we show how our construction can be refined to eliminate the major assumption behind payment channels, i.e., the need for online participation. To that end, we present Sleepy CRAB the first provably secure channel construction under rational miners that enables participants to go offline indefinitely. We also provide a proof-of-concept implementation of Sleepy CRAB and evaluate its cost in Bitcoin, thereby demonstrating its practicality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d2f0b5ff-3c9f-4a13-a129-4c85bf4dbde8Cited by top-tier papers4
- Scalable Off-Chain AuctionsMohsen Minaei, Ranjit Kumaresan, Andrew Beams, Pedro Moreno-Sanchez et al.NDSS 2026 · 3 citations
- Elastic Restaking Networks: United we fall, (partially) divided we standRoi Bar Zur, Ittay EyalCCS 2025
- On the Atomicity and Efficiency of Blockchain Payment ChannelsDi Wu, Shoupeng Ren, Yuman Bai, Lipeng He et al.USENIX Security 2025
- Ark: Offchain Transaction Batching in BitcoinPim Keer, Matteo Maffei, Marco Argentieri, Andrew Camilleri et al.CCS 2026
Builds on14
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- General State Channel NetworksStefan Dziembowski, Sebastian Faust, Kristina HostákováCCS 2018 · 249 citations
- Perun: Virtual Payment Hubs over CryptocurrenciesStefan Dziembowski, Lisa Eckey, Sebastian Faust, Daniel MalinowskiS&P 2019 · 222 citations
- A Tale of Two Worlds: Assessing the Vulnerability of Enclave Shielding RuntimesJo Van Bulck, David F. Oswald, Eduard Marin, Abdulla Aldoseri et al.CCS 2019 · 159 citations
Related papers
- Thora: Atomic and Privacy-Preserving Multi-Channel UpdatesLukas Aumayr, Kasra Abbaszadeh, Matteo MaffeiCCS 2022 · 20 citations
- Sleepy Channels: Bi-directional Payment Channels without WatchtowersLukas Aumayr, Sri Aravinda Krishnan Thyagarajan, Giulio Malavolta, Pedro Moreno-Sanchez et al.CCS 2022 · 26 citations
- Blitz: Secure Multi-Hop Payments Without Two-Phase CommitsLukas Aumayr, Pedro Moreno-Sanchez, Aniket Kate, Matteo MaffeiUSENIX Security 2021 · 63 citations
- He-HTLC: Revisiting Incentives in HTLCSarisht Wadhwa, Jannis Stoeter, Fan Zhang, Kartik NayakNDSS 2023
- Payout Races and Congested Channels: A Formal Analysis of Security in the Lightning NetworkBen Weintraub, Satwik Prabhu Kumble, Cristina Nita-Rotaru, Stefanie RoosCCS 2024 · 5 citations
