LibraryInteroperability2018Design paperCorpus record
eltoo: A Simplified Update Mechanism for Lightning
Eltoo. Christian Decker, Rusty Russell and Olaoluwa Osuntokun.
Eltoo replaces penalties with a sequence of state numbers. A later state can spend an earlier one. Nothing is confiscated. The latest number wins if it is published in time.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A channel protocol that claims 'no penalty' should say which state number wins, and which opcode the chain actually has.
The five-minute read
The defect
Lightning's original update punishes a stale state by taking the cheater's funds. That binds channels to a penalty key and to watchtowers that must see every old state.
The rule
Eltoo replaces penalties with a sequence of state numbers. A later state can spend an earlier one. Nothing is confiscated. The latest number wins if it is published in time.
How it is put together
States are ordered by a number, not by a punishment transaction. Any later state can attach to an earlier published state. The chain needs a signature rule that respects that number. BIP 118 was the proposed hook.
Where the claim stops
Eltoo was a design, not a mainnet activation.
One action, walked through
- Parties sign a new state with a higher number.
- If an old state is published, the other party publishes a higher one.
- After a timeout, the highest published state settles.
- Which state number beats which?
The argument, unpacked
Why it is still on the desk
A channel protocol that claims 'no penalty' should say which state number wins, and which opcode the chain actually has.
After the text
LN-Symmetry is the later name for this idea. Activation depends on Bitcoin consensus, which is a separate decision.
What has to be true
- Eltoo was a design, not a mainnet activation.
- Without the base-layer opcode, it does not run on Bitcoin.
- It changes watchtower design. It does not remove the need to notice a publication.
What happened after the paper
LN-Symmetry is the later name for this idea. Activation depends on Bitcoin consensus, which is a separate decision.
What to check before you use the idea
- Which state number beats which?
- What opcode does the design require?
- What happens if nobody publishes the higher state in time?
Terms
- State number
- A counter that lets a later update replace an earlier one.
- Symmetry
- Both parties use the same update rule, without a penalty key.
The problem the paper names
Lightning's original update punishes a stale state by taking the cheater's funds. That binds channels to a penalty key and to watchtowers that must see every old state.
What the design proposes
- States are ordered by a number, not by a punishment transaction.
- Any later state can attach to an earlier published state.
- The chain needs a signature rule that respects that number. BIP 118 was the proposed hook.
How the mechanism is specified
- Parties sign a new state with a higher number.
- If an old state is published, the other party publishes a higher one.
- After a timeout, the highest published state settles.
What this page does not treat as proven
- Eltoo was a design, not a mainnet activation.
- Without the base-layer opcode, it does not run on Bitcoin.
- It changes watchtower design. It does not remove the need to notice a publication.
Why a venture studio still reads it
A channel protocol that claims 'no penalty' should say which state number wins, and which opcode the chain actually has.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
