Hermes / Lightning

Lightning: trustless payments off the chain

A channel lets two people pay each other thousands of times while the blockchain sees only two transactions: one to open (a 2-of-2 funding output), one to close. In between, the balance is just a commitment transaction each side holds but never broadcasts. To pay, they sign a new one and throw the old away. But nothing physically stops a cheater from broadcasting a stale, more-favourable state. So Lightning makes cheating self-destructive with a revocation key. Publish a revoked state and your counterparty takes everything.

1 · Open the channel (on-chain)

Alice and Bob each put in 0.05 BTC to a single bc1q… address that only their two keys together can spend (a 2-of-2 P2WSH). That funding transaction is the only time the chain hears about them until they close.

funding address  · 2-of-2 (Alice + Bob) · 0.10 BTC
–

2 · Pay off-chain, instantly and for free

Alice 0.050 Bob 0.050
commitment state #0  ·  0 payments  ·  on-chain transactions to open: 1

Each payment mints a fresh pair of commitment transactions and revokes the previous state: Bob hands Alice (and Alice hands Bob) the per-commitment secret for the old state. That reveal is what makes the old state dangerous to publish. No miner, no fee, no waiting: just two signatures swapped over the wire.

3 · Settle

…or someone tries to cheat

Bob can broadcast any revoked commitment he kept. He only profits from one where he was richer than he is now (highlighted), but Alice can punish any of them.

This state's to_local: holds Bob's balance

revocationPubkey  =  hash-weighted sum of Alice's basepoint + Bob's per-commit point
–
delayedPubkey (Bob's, after 144 blocks)
–

Two ways to spend Bob's money: the IF branch (instant, for whoever holds the revocation key) or the ELSE branch (Bob himself, but only after a to_self_delay). That delay is the window in which a cheat gets caught.

The justice math

The revocation private key doesn't exist yet. It can only be assembled from both Alice's revocation-basepoint secret and Bob's per-commitment secret. Bob only reveals the latter when he revokes a state. Make a payment, then broadcast an old state to watch the key snap together.

revocationPriv = r·H(R‖P) + p·H(P‖R)
r = Alice's secret   p = Bob's revealed secret
Things to notice

Revoking = revealing a secret

"Deleting" an old state isn't enough, because you can't prove a deletion. Instead each side hands over the per-commitment secret for the state they're leaving. Now the other party can build the key that punishes its reuse.

Punishment, not detection

A revoked broadcast doesn't just get flagged: the counterparty sweeps the cheater's whole to_local output before the to_self_delay elapses. Rational players never cheat, so the channel stays honest with zero on-chain activity.

Watchtowers

The catch only works if someone is watching while you're offline. A watchtower holds your penalty transactions and broadcasts them if it ever sees a revoked commitment hit the chain. No funds, no trust, just vigilance for hire.