Imagine opening your Bitcoin wallet and discovering that everything still belongs to you, but you cannot get it out in time.
Your keys work. Your signatures are valid. The software can produce the transactions needed to defend your balance.
There is just one problem: millions of other people need to do the same thing, and the blockchain cannot fit everyone before the relevant deadlines expire.
That is a possible failure scenario for systems that depend on time-sensitive settlement. It is also a question that an impressive transactions-per-second number cannot answer.
For years, Bitcoin’s scaling debate has encouraged us to picture success as a network processing more payments for more people at lower cost. Lightning helps make that possible. Other constructions promise to take the idea further, sharing blockchain resources across larger groups of users.
But every time we celebrate another million people moving off-chain, we should ask what happens if they need the chain again.
Together. Under pressure. At the same time, their counterparties have stopped cooperating.
The transaction you need in a crisis may matter more than the million payments you made before.
On September 15, 2026, Bitcoin researcher John Law introduced ** a proposal called Depots**. It aims to support billions of users through shared funding, probabilistic Lightning channels, and financial penalties for destructive behavior. Its ambition is to keep emergency blockchain usage small even when cooperation breaks down.
The idea deserves attention. So does the price it asks users to pay.
Because a system that preserves an economic incentive to cooperate is offering a different kind of protection from a system that lets every individual recover a known balance independently.
That distinction could shape Bitcoin’s next great scaling argument.
Start with what you actually own.
If you hold a conventional Bitcoin output under your sole control, congestion can make spending expensive or slow. Your coins generally do not become somebody else’s merely because you waited. The fee market can make a small output uneconomic to spend, but a standard output has no counterparty waiting for a channel dispute window to expire.
An off-chain arrangement can introduce additional conditions. You may need current channel information, monitoring, a sequence of transactions, and action within a particular window.
Lightning’s on-chain rules explicitly deal with commitment transactions, revoked states, payment timeouts, and penalties. Those mechanisms provide a way to enforce agreements when a peer will not cooperate. Their effectiveness depends on getting the necessary transactions confirmed.
This does not mean an unavailable Lightning peer automatically steals your money. An outage can simply produce delay. Different failures trigger different recovery paths, and different paths have different deadlines.
It means that “I have the keys” can be the beginning of the security explanation rather than the whole explanation.
Think about the difference between owning a house outright and holding an enforceable claim that requires you to submit certain documents before a deadline. Both can involve real ownership rights. But the practical demands are different, particularly if everyone needs the same office on the same afternoon.
Bitcoin replaces that office with an open network. It still has a finite amount of settlement capacity.
A valid transaction does not come with a reservation in the next block.
To avoid a catastrophic 500,000-troop invasion of Iran, Trump is launching a high-stakes backdoor war in Yemen. Here is the untold masterplan.
The arithmetic is less forgiving than the marketing.
Bitcoin limits block weight to four million weight units, equivalent to roughly one million virtual bytes before allowing for overhead. A virtual byte is the fee-accounting unit used to compare transactions with different mixtures of ordinary and witness data.
Consider a deliberately simplified example. Suppose each independent emergency claim requires 300 virtual bytes. Assume every available block is devoted to those claims, ignore overhead, and use a ten-minute average block interval.
These are illustrative calculations, not measurements of Lightning’s exit capacity. Actual claims can require different transaction sizes, shared transaction components, and multiple steps. Real users would also compete with other Bitcoin activity.
The example isolates one point: small individual demands become enormous when enough people must act at once.
A 300-byte claim feels almost weightless. One hundred million of them require months of the entire chain’s capacity under these assumptions.
If a security window is much shorter, increasing the fee cannot make the missing blocks appear. Higher fees can improve one claimant’s position in the queue. They cannot guarantee that the entire queue fits.
That is why an individual wallet’s successful recovery test tells us only part of the story. The harder test asks whether recovery still works when other wallets are trying to recover too.
Developers have been thinking about this for years. In September 2023, Anthony Towns described ** the “thundering herd” problem** in a discussion of scaling Lightning with covenants. An arrangement that needs very little blockchain activity while everyone cooperates can require millions of transactions if its operator stops cooperating. Extending the recovery window can help, but can also tie up capital for longer.
There is a practical insight here that deserves much wider attention: a service’s popularity changes the consequences of its failure.