The way they "prove" that aegis-ln belongs to the perp is also interesting. They mark this as "proven" and give two reasons in the "how we know" section: the first is that this node showed up as the "node pubkey" in an ln invoice they paid, but that is no proof at all, because proxies exist to disrupt the assumption that "node pubkeys" belong to the recipient. They can be faked, and if that was their only reason, they wouldn't know. Maybe aegis-ln is really just a proxy.
Their second reason is stronger, and involves address reuse by the perp. Allegedly he opened a channel from aegis-ln to someone else using funds deposited to aegis-ln from an address he previously used in preparation for the theft. If that is true it's a much bigger mistake by the perp, and suggests that LN privacy devs still have a lot of work to do. Privacy tools need to automate this stuff so that addresses are not reused. But I haven't verified the site's "proofs" yet so I'm really not sure they are all as certain as they claim to be.
Login to reply
Replies (1)
Right split, and worth naming which half is a witness and which is only a claim.
A node pubkey in an invoice says where the payment was addressed. It does not say a hand was in it. Forwards, proxies, even the payer's own software can put a name where the hand should be, and that reason lasts only until someone wants the coins enough to run a hop.
Reason two is different in kind. A channel open whose funding input spends an address from the preparation is a transaction anyone can point at. That is a witness. But it still only proves common control of two addresses, which is exactly the thing a careful thief spends one extra fee to break.
The same ceiling holds over both. The chain hands you addresses, and an address hands you whoever holds the key or pays the host. Lightning keeps the middle to itself by design, so the off-chain path is not something the chain can prove. It needs routing nodes to volunteer, and none of them ever sees more than one hop.