"Lightning nodes are dangerous hot wallets", they said.

After 5 years, 15000 nodes and 5 BTC hanging in these poorly-run, amateurish hot wallets exposed to the open internet, not a single attack was noticed. What do we think about that?

#[1] #[2] #[0]

Reply to this note

Please Login to reply.

Discussion

We only have enough time to stack before they find out…

Ok…I will be nice 🤣 and keep my mission on purple/orange pilling the world

💜🫂🤙🏼

I still agree and only keep small balances in lightning wallets.

5 BTC is not incentive enough to bring out big guns to attack 15000 nodes

Total capacity is 5k BTC. 140 million dollarites. Quite a bounty.

If they were in one location like Fort Knox yes but 5K distributed with crumbs across the network not worth the effort.

It’s a really good question. I’d say it’s been really hard for a single attacker to actually steal funds en masse due to lack of single honeypots and isolation of funds in different channels with different counterparties. This might change as amounts get bigger, but the incentive design means payoffs should never be asymmetric like we see if DeFi (tiny effort, huge theft potential).

It’s not as hard to grief a node via channel jamming but the attacker can’t directly steal money, can just enjoy the pleasure of being an asshole for a while. Hence why lower hanging fruit attacks haven’t really been exploited yet.

Someone made perfect system by accident?

But Id quess there is k missing in amount 😁⚡

Just need to find one Umbrel exploit and a large chunk of those will get screwed. (I hope not)

Turns out the biggest risk wasn't some attacker but instead from ourselves running nodes with wumbo channels off of raspberry pi's. Haha

We need mooooore.

It's a micropayments network. Perhaps it's simply not a juicy enough target yet. Best to stay vigilant though. Don't jinx it for crying out loud.

The average node has at most 33M sats in it - likely much less in oubound liquidity it controls.

https://1ml.com/statistics

My guess, it’s not worth the trouble for any competent thief.

LN are not worrying. But reliance on custodian LN wallets are concerning.

As of now LNURL & LN address still cant run without custodian infra

Spitting facts 🔥 you should drop a rap record