On this page
The central tension in Bitcoin is whether it is digital gold (a store of value settled on a slow, secure base layer) or digital cash (a medium of exchange for everyday payments). Bitcoin's base layer can handle roughly 7 transactions per second — not enough for retail. The is Bitcoin's main answer: a network of off-chain payment channels that lets two parties move value between themselves instantly and nearly for free, settling to the chain only when they're done. Whether Lightning actually works as a payment network for ordinary people is one of the most consequential open questions in crypto.
The problem: Bitcoin can't be cash by itself
Bitcoin's base layer is deliberately inefficient. Every transaction is broadcast to every node, stored forever, and confirmed roughly every 10 minutes. That's the price of decentralization: no single party can be trusted, so everyone must verify everything. It caps throughput at about 7 transactions per second, and makes confirmation times measured in minutes (or hours during fee spikes).
For a store of value that's fine. For a coffee, it isn't. The 2015–2017 scaling fight (see the Block-Size War deep dive) was, at root, about this: do you make the base layer bigger (simpler, but more centralizing) or push small payments off-chain (harder, but preserves the base layer's properties)? Bitcoin chose the latter, and Lightning is the bet that came out of it.
How a payment channel works
A Lightning payment channel is just a 2-of-2 multisig address on Bitcoin, plus a sequence of signed balance statements that the two parties keep between themselves. The simplest case:
- Open. Alice and Bob fund a multisig address with, say, 5 BTC total. This is one on-chain transaction.
- Update (off-chain). Whenever Alice pays Bob (or vice versa), they sign a new balance statement — “Alice 4 / Bob 1” then “Alice 3 / Bob 2” — and invalidate the old one by exchanging revocation secrets: each party hands over the data that would let the other punish them for broadcasting a stale state. None of this touches the chain.
- Close. Either party can broadcast the latest signed balance to the chain to settle up. That's a second on-chain transaction. In between open and close, the two of them can make as many payments as they want, instantly and nearly for free.
The clever part is the security model. Because each update is signed by both parties and time-locked, a dishonest party who tries to broadcast an old balance can be punished: the other party can submit a “revocation” transaction that takes all of the cheater's channel funds. The threat of losing everything keeps both honest.
Routing: how a network of channels works
A single channel only lets Alice pay Bob. The Lightning trick is routing: if Alice has a channel to Bob, and Bob has a channel to Carol, then Alice can pay Carol by routing through Bob — without Bob being able to steal the funds or even know who Alice is paying. This is done with HTLCs (hash-locked, time-locked contracts): a payment is locked to a cryptographic that only the recipient knows the preimage for. Each hop forwards the payment conditional on the same hash; when Carol reveals the preimage to claim her funds, it propagates back the chain, settling each hop in order.
In practice, routing is the hardest problem in Lightning. The network has to find a path of channels with enough liquidity in the right direction, without anyone along the path knowing the full route. The original spec assumed nodes would do source-based routing; real-world routing today is still an active research problem and a major source of failed payments.
The timeline
Tap any event to expand its story.
As Bitcoin blocks fill up, fees and confirmation times rise. The community splits between on-chain scaling (bigger blocks) and off-chain scaling (payment channels). The Lightning paper, published in February 2015, becomes the flagship of the latter camp.
Joseph Poon and Thaddeus Dryja publish "The Bitcoin Lightning Network: Scalable Off-Chain Instant Payments" (a revised draft follows in January 2016). The core idea: a network of bidirectional payment channels, settled on-chain only when opened and closed, secured by Bitcoin’s scripting and time-locks.
The BOLT (Basis of Lightning Technology) specification is developed collaboratively. Implementations follow: lnd (Lightning Labs), c-lightning (Blockstream), and Eclair (ACINQ). The first mainnet channels open in 2018.
El Salvador adopts Bitcoin as legal tender; the government’s Chivo wallet uses Lightning for instant, near-zero-fee transfers. Lightning gets its first country-scale, retail-payment use case — with mixed results.
Researchers document a long-standing vulnerability: attackers can cheaply lock up liquidity in channels across the network, preventing honest payments from routing. Mitigations (reputation, upfront fees) are designed but remain a live problem.
With Taproot (activated 2021) widely supported, Lightning can migrate from HTLCs to PTLCs (Point Time-Lock Contracts), which hide payment hashes and improve privacy. Adoption is gradual.
The hard problems Lightning hasn't solved
Lightning works, in the sense that payments route and settle. But several problems keep it from being a retail-grade payment network:
- Inbound liquidity. To receive payments, you need channels with capacity on your side. A new user with no channels can't receive anything until someone opens a channel toward them. “Lightning Service Providers” try to solve this, but it reintroduces a degree of centralization.
- Channel jamming. Attackers can cheaply lock up liquidity across the network, denying service to honest users. Mitigations (upfront fees, reputation) exist but are not yet widely deployed.
- Custody and UX. Self-custodial Lightning wallets are hard: users must manage channel liquidity, watch for old states, and stay online (or use a “watchtower”). Most retail users use custodial wallets, which reintroduces the trust model Lightning was meant to eliminate.
- Routing reliability. Multi-hop payments frequently fail because of insufficient liquidity along the path. Improvements like trampoline routing and neighbor discovery are incremental.
Lightning's proponents argue that the network is still young, that liquidity and routing are improving rapidly, that custodial wallets are an acceptable on-ramp (the same way custodial exchanges on-ramp users to Bitcoin), and that Lightning's successes — El Salvador's Chivo wallet, Strike, Wallet of Satoshi, podcast tipping — prove the model works for retail. The critics argue that “works with a custodian” is not what Bitcoin promised, and that the unresolved problems (jamming, inbound liquidity, routing) are structural, not growing pains. Both readings have merit. The honest position is that Lightning is a real, working layer-2 with genuine open problems — not a finished payments network, and not a failure.
Lightning vs. the Ethereum L2 approach
Bitcoin and Ethereum took different scaling bets. Bitcoin's is Lightning: state-channel based, peer-to-peer, no global computation off-chain. Ethereum's is rollups (Optimism, Arbitrum, zkSync): a global off-chain computation environment whose results are posted back to the base layer — to be challenged during a fraud-proof window in the optimistic flavors, or verified outright via validity proofs in the ZK flavors. The two approaches have different trade-offs — Lightning is simpler and cheaper per payment but harder to route; rollups are more general (any smart contract) but inherit L1's smart-contract risk. For the Ethereum side of this comparison, see the Ethereum Roadmap deep dive and the Technology module.
Key takeaways
- Lightning is a network of off-chain Bitcoin payment channels. Each channel is a 2-of-2 multisig address plus a series of signed balance statements; only the open and close touch the chain. HTLCs and revocation penalties make cheating financially suicidal.
- Routing lets payments hop across multiple channels to reach a recipient who isn't a direct peer. It's also Lightning's hardest problem: finding a path with enough liquidity in the right direction, privately, is unsolved in general.
- Real-world use (El Salvador's Chivo wallet, Strike, podcast tipping) shows Lightning can deliver instant near-free retail payments. But it often does so via custodial wallets, which reintroduce the trust model Lightning was built to remove.
- The structural open problems are inbound liquidity, channel jamming, routing reliability, and self-custody UX. None is fully solved; mitigations exist but are unevenly deployed.
- Lightning is Bitcoin's answer to “digital cash”. Whether it succeeds as a payments network for ordinary people is one of the most consequential open questions in crypto. For the opposing scaling bet, see the Block-Size War deep dive.