If you're on Amethyst, you can tell your client to only connect over a VPN - I think it suggests Orbot, which I got, and here you can see where the option is. It says something different before you turn it on. This way, no relay ever sees my actual IP address. You can see a list of all IPs that looked at your bio - so your security depends on never exposing that. Maybe it isn't a perfect solution, but it probably eliminates 90% of possible exposures. Probably the worst thing you can do is zap someone while not behind a VPN/tor because then your LN address can be correlated with your physical location - IF I'm understanding these things rightly, and to be fair, I'm not the best person to talk about this.
