
I'll answer in order: That's a great point! The solution is to add a timelock, just like an HTLC. This coin is only spendable with a signature from this pubkey until time T at which point it is redeemable by anyone with only the proofs. So if Alice locks some coins to Bob's pubkey then only Bob can redeem those tokens within the time window. After T, either party can redeem them. Alice has essentially locked herself out until time T. I believe this is the default flow, although I haven't verified it myself. I'd love to try it out if you're interested. I don't understand your point. All cashu mints are lightning nodes. You can transfer the coins with a lightning transaction. The privacy properties of ecash ensure that mints must honor lightning withdrawals for everyone or suffer reputational damage from everyone. Sometimes it's buggy. You can usually recover from your seed phrase to get those tokens back. This will improve in time as the protocol matures. Do you remember the early days of lightning? #reckless Yes, exactly! It is a continuous rug. Further reading: https://gist.github.com/callebtc/ed5228d1d8cbaade0104db5d1cf63939