The easiest way to dismiss a critique of Spark is: then don't use it. This piece is about why that answer does not work. Privacy on the Lightning Network is not a personal setting you control. It is a commons you draw from, and a commons can be degraded by people other than you.
Your anonymity is other people's traffic
Lightning hides you through onion routing: each hop on a payment learns only its immediate neighbors, never the full path. That only protects you if the hops are independent and numerous. Your privacy is, quite literally, the crowd you are mixed into. Shrink the crowd, or let one party sit at many of its intersections, and everyone's privacy drops at once, not just the privacy of that party's customers.
The same insight sits behind every anonymity network: you are anonymous among others. If one observer can see a large fraction of the whole, the math stops working for the entire population inside it.
The 50% observer already exists
In the first conversations that led to these articles, I kept returning to a thought experiment: what if one party could see half the network's payments? It turns out that is not hypothetical. Academic measurement of Lightning found the single most central node positioned to observe close to half of all payments, and the four most central nodes averaged around 72%. Researchers have repeatedly flagged a trend toward centralization, with most payment paths running through the same small set of nodes.
The topology backs this up. By 2026, the top ten Lightning nodes controlled roughly 85% of public capacity, with a capacity Gini coefficient near 0.97, about as concentrated as a network can get. A dominant observer is not a doomsday scenario to guard against. It is the network's current shape. The open question is who occupies that position, and whether anything makes it worse.
How Spark reaches payments that are not "on Spark"
Spark does not have to route your payment to hurt your privacy. It works from the edges, in four ways.
Privacy is bilateral. You can run a hardened, Tor-routed, sovereign node and still lose privacy on half your payments, because the other side is not yours to configure. Pay a Wallet of Satoshi or Cake user and the payment terminates behind Spark's operator, which records the receive: recipient, amount, timestamp. As Spark absorbs more endpoints, a larger share of the average person's counterparties sits behind one observer. You do not get to choose who your counterparty banks with.
The bridge is a correlation pivot. Spark connects to Lightning through its Service Provider model using atomic swaps. Today's Lightning payments carry an identical payment hash across every hop, so the provider node at the Lightning-to-Spark boundary can link the public Lightning leg to the internal Spark transfer. Payments that merely cross Spark become correlatable, even for the party who never opened a Spark wallet.
Predictable endpoints erode destination privacy. Receiver anonymity leans on a router not knowing whether the next hop is the final recipient. When a large share of payments terminates at a handful of known provider endpoints, that guess becomes easy. Concentrated destinations make the whole graph more legible, for everyone.
Cover traffic thins for all. Spark's pitch is that wallets no longer run their own channels or routing. Every wallet that offloads that work is one fewer independent relay and one fewer source of cover traffic. The diversity that Lightning privacy depends on grows more slowly and pools into fewer hands. Even committed pure-Lightning users end up mixed into a smaller, more surveilled crowd than they would be otherwise.
Leakage scales with visibility
An intermediary that sees a lot sees more than routes. An on-path observer can read each routed amount and the timelock deltas, which lets it rule out low-capacity nodes and shrink the sender-and-receiver anonymity set. Large payments fare worst: the bigger the amount, the fewer routes can carry it, and the smaller the anonymity set becomes. The more flows a single party sees, the more incoming-and-outgoing pairs it can match by timing and amount. Deanonymization capability does not grow gently with an observer's share. It compounds.
Put plainly: concentrating the network does not just expose the concentrator's own users. It hands whoever sits at the center a steadily improving correlation engine pointed at everyone else.
The honest caveats
A critique is only as strong as the objections it survives, so here are the real ones.
The 50% and 72% figures come from specific studies and network snapshots. Exact numbers depend on methodology and change over time. Treat them as directionally solid, not as precise constants.
Two claims also need separating. Endpoint concentration, meaning a large share of receivers sitting behind Spark, is clearly happening; Wallet of Satoshi, Cake, and the Breez SDK default all point that way. Whether Spark's providers become the dominant routing hubs for unrelated third-party traffic is structurally plausible, but I cannot pin it down with a hard measurement of Spark's share of total network routing. The first claim carries this piece. The second is a trajectory, not an established fact.
Real forces push the other way as well. Multipart payments and larger-capacity channels enlarge anonymity sets. Point time-locked contracts (PTLCs), if they replace today's hash-based HTLCs, would break the shared-payment-hash correlation the bridge currently exploits. Route blinding helps on the receiving side. None of these erase the receive-side record an operator keeps, but they matter, and a fair piece names them.
The point
You can opt out of Spark. You cannot opt out of a network whose anonymity set has been thinned by everyone else opting in. That is what makes this different from a personal wallet choice, and why "then don't use it" misses the argument.
The observer I once treated as a thought experiment, one party seeing half the payments, is already the network's default shape. Spark did not invent that observer. It gave it a name, a business model, and a growing share of the destinations we all pay into.
