{"id":"e0bf4e3c-60c9-46f3-a1ee-3e4649696d60","arxiv_id":"2512.11775","paper_version":2,"verdict":"REJECT","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":7,"one_line_summary":"A leaderless multi-party payment channel using jointly funded hyperedges and proposer-chained DAG state reports 94.69% simulated success, but its cross-hyperedge atomicity has a timeout flaw.","lead":"This paper proposes a payment-channel design where groups of users share one jointly funded 'hyperedge,' letting any member pay any other member directly through signed DAG updates. It is worth reading as an attempt to remove routing, rebalancing, and watchtowers from off-chain payments, though the atomicity argument has a timeout flaw and the largest claimed experiment is absent from the paper.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Inter-hyperedge atomicity breaks if H_b's conditional leaf times out after the connector's H_a payment has already finalized; §IV's 'expires safely' does not refund the connector's irreversible forward payment, and no bound on H_a finalization is given to set T_x safely.","rationale":"The reader's weakest_assumption identifies exactly the load-bearing gap I find: inter-hyperedge atomicity is not established because the timeout mechanism in §IV can strand a connector who has already made an irreversible forward payment in H_a. My independent reading confirms this and adds that the paper's own language—'the payment becomes irreversible' once included in a finalized dagroot, versus 'the leaf is revoked' at T_x—makes the contradiction explicit. The multi-hop extension inherits the same problem at every hop, so the headline property of secure, asynchronous atomic settlement without hash-locks or timelocks is not supported. The paper also contains a secondary discrepancy: the abstract claims a 15,000-node full-hyperedge evaluation with 85–95% success, while §VIII describes only a single 150-node hyperedge; this weakens the abstract's empirical claims but is not the main correctness issue. The strongest independent support in the paper is the 100,000-transaction 150-node simulation showing 94.69% intra-hyperedge success, but that does not exercise inter-hyperedge atomicity at all. Because the paper explicitly omits formal atomicity and liveness proofs and provides no code, the timeout interleaving remains a live counterexample. I agree with the reader's REJECT verdict, so no verdict adjustment is needed.","tokens_in":11808,"tokens_out":5605,"duration_ms":52978,"concrete_test":"Build a minimal discrete-event simulator of two hyperedges implementing the exact §IV and §V rules, and force the interleaving: (1) H_b creates the conditional leaf with timeout T_x; (2) u_ab performs the H_a payment and H_a finalizes at time T_x − ε; (3) H_b processes the timeout at T_x; (4) the proof Π_a arrives at H_b at T_x + ε. Assert the connector's net position across both hyperedges after step (4). If H_b has revoked the conditional leaf while H_a's root is already finalized, the claimed atomic-pair invariant is violated. Equivalently, add an assertion to the existing Go simulator that for every inter-hyperedge attempt value_out(H_a) == value_in(H_b) for the connector; if any permitted interleaving fails, the central claim is refuted.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The most load-bearing assumption is that inter-hyperedge atomicity follows from H_b's conditional leaf waiting for proof Π_a of a finalized H_a payment. §IV introduces a timeout T_x to prevent indefinite lockup: 'if the required proof does not arrive before T_x, the leaf is revoked and the transactions until the leaf before this conditional leaf are accepted, ensuring that liquidity remains safely recoverable.' That recovery applies only to the revoked H_b chain. The connector u_ab has already performed an ordinary intra-hyperedge payment in H_a after the conditional leaf is issued; when that payment is included in a finalized dagroot, the paper itself says it becomes irreversible. If H_a finalizes after T_x, or if the proof is merely delayed past T_x, the H_b leaf is revoked and u_ab is left having paid v in H_a with no claim to v+δ in H_b. Thus the stated rule 'either every hop receives its proof and finalizes, or every conditional leaf expires safely' is false as written: expiry is safe for the sender u_b but not for the connector. No upper bound on H_a root finalization time is provided, and under the paper's asynchronous model T_x cannot be chosen to guarantee the proof arrives first. This is not a peripheral implementation detail: the abstract and §IV claim 'secure, asynchronous atomic settlement ... without hash-locks, timelocks, or global coordination,' and the multi-hop extension inherits the same failure at every hop. The paper explicitly states that formal atomicity and liveness proofs are omitted, so this gap is unaddressed.","agreement_with_reader":"agree"},"referee_report":null,"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Two things to know. First, the hyperedge construction is a real novelty: collectively funded UTXOs with proposer-chained DAG leaves and threshold-signed roots give you leaderless, concurrent intra-hyperedge payments, a genuine step beyond coordinator-based MPCs like Perun, Magma, and Thora. Second, the paper's central claim—asynchronous atomic inter-hyperedge settlement without hash-locks or timelocks—does not survive contact with its own timeout rule in §IV, and the evaluation does not support the 15,000-node success rates mentioned in the abstract.\n\nWhat's good: the per-proposer revocation chaining is clean, the symbolic deltas with deferred balance updates make sense, and the proof-of-transfer idea (replacing HTLC preimages with finalized dagroot evidence) is worth exploring. The 150-node simulation shows the mechanics run, and the authors are upfront that formal proofs are omitted. The balance-skewness metric is a nice touch.\n\nThe soft spots are load-bearing. In §IV, a conditional leaf in H_b can carry a timeout T_x. The connector pays in H_a first; that payment becomes irreversible once a dagroot finalizes. If the proof does not arrive in H_b before T_x, the H_b leaf is revoked and the connector is left having paid with no claim. The paper says this \"expires safely\" for everyone, but it is only safe for the sender in H_b, not for the connector. There is no bound on H_a finalization time, and under asynchrony you cannot pick T_x to guarantee the proof arrives first. So the atomicity claim is false as written. This is not a peripheral detail; it is the paper's headline property.\n\nAlso, the abstract (as shown on arXiv) claims 85–95% on a 15,000-node network, but §VIII only describes a 150-node hyperedge. The 94.69% success rate is from a simulator with no adversarial traffic and no code or data, so the comparison in Table I to real PCN measurements is not apples-to-apples. The absence of HTLC-expiry failures is true by construction, not a measured advantage.\n\nWho this is for: researchers working on multi-party channels and off-chain scaling will get something from the construction and from the failure mode I named. It deserves a serious referee—not for acceptance as is, but to force the authors to fix or bound the timeout problem, align claims with the evaluation, and ideally add formal statements. I would not cite it as a working protocol yet, but I would bring it to a reading group.","headline":"Real construction, broken atomicity claim: the §IV timeout rule strands connectors, and the evaluation overstates scale.","tokens_in":12713,"tokens_out":2661,"would_cite":false,"duration_ms":23236,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A hypergraph payment channel moves value across groups without routing or hash-locks.","keywords":["hypergraph","multi-party payment channel","payment channel network","DAG-based state updates","threshold signatures","atomic settlement","off-chain payments","proposer chaining"],"falsifier":"Simulate an inter-hyperedge payment with controlled asymmetric delay between hyperedges: have a connector finalize a payment in Ha, then delay the proof-of-transfer to Hb past the conditional leaf's timeout Tx. If Hb revokes the conditional leaf and the connector is left with an irreversible outgoing payment and no claimable incoming payment, the atomicity claim fails.","tokens_in":11698,"feed_emoji":"⚡","tokens_out":8201,"duration_ms":64995,"temperature":0.7,"pith_summary":"This paper proposes replacing pairwise payment channels with hyperedges—channels jointly funded by many participants—so that any participant can pay any other group member from one pooled balance. State is tracked as a DAG of signed proposals ordered by per-proposer revocation chains, and balances change only when a supermajority-signed dagroot finalizes. For payments between hyperedges, a connector first pays inside one hyperedge and then presents a compact proof-of-transfer to claim funds in another, which the paper argues gives atomic settlement without hash-locks or timelocks. The reported 94.69% success rate on 100,000 simulated transactions across a 150-node hyperedge is attributed to the absence of routing and HTLC failure modes rather than balance sufficiency alone. If correct, the construction would remove liquidity fragmentation, directional lock-up, and watchtower dependence from off-chain payment networks.","feed_headline":"Hyperedge channels hit 94.7% payment success rate","feed_subtitle":"A DAG-based multi-party channel settles payments across groups without hash-locks, timelocks, or watchtowers.","key_machinery":"The central mechanism is the proposer-chained DAG of dagleaf entries inside a hyperedge, ordered by per-sender revocation secrets: each new leaf carries the hash of the previous secret, and revealing the previous secret revokes the old tip, so no participant can fork another's chain. Finalized checkpoints are threshold-signed dagroots that summarize batches of leaves. Inter-hyperedge settlement uses a proof-of-transfer—a signed transfer leaf sandwiched between two consecutive threshold-signed dagroots—as a replacement for an HTLC preimage, released into a conditional leaf in the destination hyperedge.","core_discovery":"The central discovery is that a collectively funded multi-party channel, modeled as a hyperedge, can support fully concurrent leaderless payments through a DAG whose leaves are per-proposer chains secured by revocation secrets, and whose finalized checkpoints (dagroots) require a supermajority threshold signature. Intra-hyperedge payments only update the sender's and receiver's balances; inter-hyperedge payments couple two independent hyperedges through a conditional leaf in the destination hyperedge that is released only when a proof-of-transfer from the source hyperedge—two consecutive threshold-signed roots plus the signed transfer leaf—is presented. The paper claims this yields secure, a","pith_inferences":["If the timeout-safety gap is closed, the same proof-of-transfer construction could generalize to any pair of state-channel networks, making cross-protocol atomic swaps cheaper than HTLC-based ones.","Because dagroot finalization happens in fixed time windows, payment latency is bounded by the window interval; a natural stress test is whether shortening that interval trades success rate against confirmation latency.","The observed balance skewness stabilising around 0.7 under a random payment model may not hold under adversarial payment distributions; a simulation with a few dominant payers would reveal whether liquidity concentration reintroduces depletion."],"forward_implications":["Because each hyperedge is funded by one on-chain UTXO, a participant can pay any other group member without routing, so liquidity fragmentation across channels is replaced by pooled liquidity.","Intra-hyperedge payments require no leader; concurrent per-proposer chains converge at dagroots, so throughput is not limited by a coordinator.","Inter-hyperedge atomicity is claimed without hash-locks or timelocks, using only proofs-of-transfer; if true, this removes HTLC expiry as a failure source.","The unilateral escape mechanism lets a participant exit via two covenant-linked transactions that automatically reseal the remaining participants, preserving the hyperedge without cooperation.","The empirical 94.69% success rate under heavy load suggests the dominant remaining failure mode is sender balance insufficiency, not network-level failures."],"fun_headline_variants":["Leaderless DAG payments hit 94% success on 150 nodes","Hyperedge channels settle concurrently without watchtowers","COALESCE: 95% success on 15k nodes with no routing","Hyperedge DAG payments: 94% success, zero watchtowers"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"Cross-hyperedge atomicity assumes that a connector's intra-hyperedge payment in the first hyperedge finalizes and its proof-of-transfer arrives in the second hyperedge before that conditional leaf's timeout expires, and the paper, which states that formal atomicity and liveness proofs are omitted, gives no bound showing this always happens.","fun_headline_variants_meta":{"raw":{"variants":["Leaderless DAG payments hit 94% success on 150 nodes","Hyperedge channels settle concurrently without watchtowers","COALESCE: 95% success on 15k nodes with no routing","Hyperedge DAG payments: 94% success, zero watchtowers"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000536,"raw_usage":{"total_tokens":2416,"prompt_tokens":756,"completion_tokens":1660,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":500,"completion_tokens_details":{"reasoning_tokens":1583}},"tokens_in":500,"tokens_out":1660,"duration_ms":10378,"temperature":1.0,"reasoning_tokens":1583,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-03T16:45:47.001313+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Simulate an inter-hyperedge payment with controlled asymmetric delay between hyperedges: have a connector finalize a payment in Ha, then delay the proof-of-transfer to Hb past the conditional leaf's timeout Tx. If Hb revokes the conditional leaf and the connector is left with an irreversible outgoing payment and no claimable incoming payment, the atomicity claim fails.","supporting_citations":[],"review_version":1}