Yeah i think so, i think that ticks all the boxes.

This is like the payjoin equivalent for onchain/offchain swaps.

It's unfortunate that LN nodes in route could correlate it right? But that's still a lot better than status quo onchain/offchain swaps (from what i vaguely remember of submarine swaps as used today, which isn't much).

Reply to this note

Please Login to reply.

Discussion

> It's unfortunate that LN nodes in route could correlate it right?

They get to learn the preimage, and can derive its pubkey, subtract it from every pubkey that spent money recently, and check if the result is a pubkey they know. I think you can fix this by tweaking it twice, and sending your recipient one of the tweaks with your invoice. That way, routing nodes can only untweak one step, which isn't good enough. They would need to learn *both* tweaks to identify the recipient's "real" pubkey.

Yes i think so. Good call.