Demo 13 built a channel between two people. But you don't have a channel with everyone; you reach them through others. Alice pays Carol by routing across Bob, with no trust in Bob and no channel between Alice and Carol. The trick is the HTLC: each hop is locked to the same payment hash, so a single preimage (Carol's secret) settles the entire path at once. And decreasing per-hop timelocks mean a middle node can never be left out of pocket.
Bob takes a 0.0001 BTC routing fee: he forwards 0.0100 to Carol but is owed 0.0101 by Alice. He only ever pays out after he can claim what he's owed, so forwarding is risk-free.
The same H locks both hops. Whoever learns R can claim from the hop behind them. So when Carol pulls her payment, she hands Bob the key to pull his.
Two spend paths: the IF branch pays the receiver if they reveal a preimage hashing to H; the ELSE branch refunds the sender after the timeout (OP_CHECKLOCKTIMEVERIFY). Real BOLT-3 wraps this in the channel's revocation machinery (demo 13); the logic is this.
Every hop commits to the same payment hash. Carol's single preimage unlocks the Bob→Carol hop, which reveals it to Bob, who uses it on the Alice→Bob hop. The payment settles backward, atomically: either all hops complete or none do.
Alice→Bob expires later than Bob→Carol. If Carol claims at the last second, Bob still has a window to claim from Alice with the same preimage. Reverse the order and Bob could pay Carol yet be unable to collect, so each hop subtracts a cltv_expiry_delta.
Bob never risks his money: he only forwards a payment he can immediately reclaim, and if Carol vanishes, every HTLC simply times out and each sender is refunded. He isn't trusted; he's incentivised, by the fee, and protected, by the script.