Got some professional help from someone of the team: Gas is paid on-chain when a channel is opened, closed or rebalanced. The swaps inside the channel are off-chain state updates, so there's no per-trade gas. "Gas-free trading" is the accurate version, not "gas-free" when you include channel openings/withdrawals. Threat model, short version: • Who signs: you. Your keys and the Lightning/Lithium node run in your browser. Every channel state update is co-signed by both sides, so the hub can't move your balance on its own. Cross-chain swaps are HTLCs: either both legs settle or both refund after the timelock. • Who watches: you while you're online; otherwise watchtowers • What breaks when the browser dies: a swap in flight doesn't settle and falls back to refund after the timelock. Channel funds stay recoverable with your seed plus channel-state backup. The real risk is being offline without watchtower coverage while a counterparty tries to publish an old state. That's the same trade-off as Lightning generally. Happy to go deeper on any of these.