Hermes / PTLC

PTLCs: routing with points, not hashes

HTLC routing (demo 14) locked every hop to the same hash. A PTLC locks it to a point T = t·G instead, using a Schnorr adaptor signature: each hop issues a payment as a pre-signature that only becomes valid once the secret scalar t is added, and publishing the finished signature reveals t to the hop behind it. Same idea as a preimage, but it rides inside an ordinary signature: nothing on-chain looks special, and each hop can offset the point so the hops can't be linked. It's what Taproot lets Lightning become.

The route

A
Alice
payer
locked to T
 
B
Bob
router
locked to T
 
C
Carol
payee

Both hops are locked to the same point T. Each is a real Schnorr pre-signature: provably completable by whoever knows the matching t, yet invalid until then.

Make the payment

Carol picks a secret scalar t and publishes only the point T = t·G.
idle: start with Carol's invoice

The point-lock

adaptor point  T = t·G · the invoice
–
secret scalar t  · revealed only by claiming
•••••••• hidden ••••••••

Adaptor-signature flow (Bob→Carol hop)

presigna pre-signature under T; verifies as completable
adapt(t)+ t → a valid 64-byte BIP-340 signature
extractBob subtracts the pre-sig back out → learns t

The completed signature verifies with the exact schnorrVerify from demo 11, so the chain can't tell a PTLC from any other spend.

vs HTLC (demo 14)

HTLC

hash-lock
same payment hash at every hop: linkable; needs a hashlock script.

PTLC

point-lock
a per-hop point + a plain signature: unlinkable, smaller, script-less.
Things to notice

The secret rides in the signature

There's no hashlock and no preimage on-chain, just a normal Schnorr signature. The secret t is the difference between the pre-signature and the finished one, so anyone holding the pre-sig recovers it the instant the payment settles.

Unlinkable hops

Each forwarder can lock its outgoing hop to T + y·G for a random y. The points all differ, so an observer can't tie the hops of one payment together. Then the node peels y back off to learn t.

Built on adaptor signatures

The same primitive powers discreet log contracts, atomic swaps and cross-chain trades: issue a signature "encrypted" under a point, and completing it publishes the point's discrete log. Taproot's Schnorr is what makes it clean.