Spark presents itself as self-custodial: instant payments, offline receiving, no Lightning channels to open, and keys held by the user.
However, the mainnet configuration published in the SDKs lists three operators - Lightspark, Breez, and Flashnet - and only two of them are needed to produce the aggregate signature controlling each deposit.
Every Spark deposit funds a Taproot output. The key combines two components: one held by the user and one held by the operators. The operators cannot spend on their own. But the user cannot transact without interacting with them.
Spark repeatedly uses the phrase “only one honest operator is needed.” Yet the published configuration is 2-of-3: two old shares being retained are enough to reconstruct the aggregate component and sign a conflicting spend together with a former owner. The third operator can refuse to participate without preventing anything. Bitcoin Layers classifies this as the protocol’s primary finality risk.
A unilateral exit formally exists in the protocol. But many popular wallets still depend on the operators to obtain the data required to construct it.
Meanwhile, Spark is scaling: Wallet of Satoshi, Primal, Blink, Blitz, Cake Wallet. Freedomia, a no-KYC Visa card, also uses it for Lightning deposits following the suspension of Boltz services.
Spark’s self-custody is therefore heavily conditional: the unilateral exit exists on paper, provided the operators cooperate in giving you the data you need.
naddr1qq3x...
However, the mainnet configuration published in the SDKs lists three operators - Lightspark, Breez, and Flashnet - and only two of them are needed to produce the aggregate signature controlling each deposit.
Every Spark deposit funds a Taproot output. The key combines two components: one held by the user and one held by the operators. The operators cannot spend on their own. But the user cannot transact without interacting with them.
Spark repeatedly uses the phrase “only one honest operator is needed.” Yet the published configuration is 2-of-3: two old shares being retained are enough to reconstruct the aggregate component and sign a conflicting spend together with a former owner. The third operator can refuse to participate without preventing anything. Bitcoin Layers classifies this as the protocol’s primary finality risk.
A unilateral exit formally exists in the protocol. But many popular wallets still depend on the operators to obtain the data required to construct it.
Meanwhile, Spark is scaling: Wallet of Satoshi, Primal, Blink, Blitz, Cake Wallet. Freedomia, a no-KYC Visa card, also uses it for Lightning deposits following the suspension of Boltz services.
Spark’s self-custody is therefore heavily conditional: the unilateral exit exists on paper, provided the operators cooperate in giving you the data you need.
naddr1qq3x...
12❤️3
