ln.watch
Public watchtowers, probed hourly from a Lightning node
1 of 99

Reachability, not efficacy † — they answered a session request. That is not proof any of them would defend a channel.

Ninety-nine public watchtowers. One answered.

They have accumulated since 2019 in the one place these get published. We can test eighty-five of them — the ones speaking lnd’s watchtower protocol — and one accepted a session in the last sweep. The other fourteen speak a different protocol; they are listed and marked, and they are not counted as failures.

No signup · no API key · static page · probed 6 min ago
What a probe proves

The tower answered on its published address, completed the handshake against its published key, negotiated a session for a real channel type, and acknowledged an encrypted update we uploaded. We then deleted the session. Measured hourly from a Lightning node we run, and published here.

What no probe proves

That the tower would broadcast a justice transaction if your counterparty published revoked state. That takes a real breach, on mainnet, with a real channel. Nobody publishes that data. Neither do we. Anyone claiming to verify watchtower efficacy without paying for breaches is guessing.

What “accepted” and “acknowledged” mean

The watchtower protocol has eight messages and none of them returns a stored blob — a tower only ever hands the data back to the chain, on a breach. So no client can read its own backup back, and neither can we. Stored is the tower’s claim; acknowledged is ours. We upload an update rather than stopping at the session because a tower whose disk is full will negotiate a session quite happily and then fail to store — that failure is visible and we report it. A tower that acknowledges an update and then loses it is not distinguishable from one that keeps it, by us or by anybody.

The one that answered

Last sweep · all figures carry † Open the full table →
Toweralias, as publishedPathclearnet or torInit p50 †not comparable across pathsChannel typessessions it acceptedLast sessionwhen it last acceptedStatereachability, not efficacy
kieselbert
03904f1a0e…60a173
clearnet117 ms
p95 130 ms
legacyanchortaproot32 min agoresponding

All of them answered on the clearnet. Where a tower is reachable only over Tor, its timings carry three hops of circuit that have nothing to do with the tower, so the path is shown beside every figure and no figure is ever compared across the two.

Before you register with one

These are run by volunteers, for nothing. lnd ships altruist watchtowers only — the reward path exists in the wire format and was never shipped for public use — so an operator running one pays for storage and CPU and receives no revenue at all. Every client that registers adds to that bill.

That is not a reason to avoid them. It is a reason we do not put a one-click button next to this list, and a reason the honest advice is to register with a tower and then check that it still works — which is the thing nobody was doing, and the reason eighty-four of the towers in the table did not answer us at all.

Why so few

There is exactly one live registry of public watchtowers in this ecosystem, and it is a GitHub issue thread — open since 2019, still taking submissions, with nothing validated and no entry ever removed unless its owner strikes it out. The one list that claimed to test its entries has been offline long enough that its rows had to be recovered from a web archive.

The towers die of storage. The registry’s own founder struck out his own tower when its database passed 14 GB on a Raspberry Pi, and the same failure is still killing towers now. Nobody is paid to keep one running, so the list is an accumulation of seven years of good intentions rather than a census of anything.

Three of the towers that did not answer us were re-confirmed by their own operators during 2025. Operator self-report is not liveness — which is the entire argument for probing, and the reason this page exists at all.

The failure mode

A watchtower defends a channel by broadcasting a justice transaction when a counterparty publishes revoked state. You register with one, it answers OK, and then nothing happens. Breaches are rare. Almost every channel closes cooperatively.

So the tower can stop working the week after you register and nothing tells you. No error, no bounce, no missing invoice. You find out at the only moment it mattered, and by then the channel is gone.

Worse: registration is a private client–server relationship that is never announced to the graph, and the blobs a tower stores are encrypted with keys derived from commitment transaction IDs — the tower itself does not know which node or channel they belong to. That privacy property is the whole design, and it means nobody can look up your coverage from outside. Not us, not you.

What this means for your node

If you registered with a watchtower more than a year ago, the odds are against it. 84 of the 99 towers on the public list did not answer us today, and the tower you chose was almost certainly chosen from that list.

Reading this page does not tell you which one you are registered with — only your node knows that, because coverage is unobservable from outside. Checking that your towers are among the one is what the connected tier does, along with the other failures that are silent in the same way: a stale channel backup, a peer that has been offline for a fortnight, a chain backend drifting behind.

The agent is read-only and stays that way. It cannot open a channel, close one, sign anything, or move a satoshi, and the macaroon you bake for it cannot authorise those actions either. It also cannot register you with a tower — that needs a write scope, and this product does not ask for one.

Price
21 000 sats per node, per year

One price. Every check, both alert channels, and the weekly digest. A hundred channels costs the same as one.

Priced in sats and only in sats. We do not publish a fiat figure, because the balance at stake in a channel is not denominated in one either. The directory above is free, forever, and never goes behind a form.

What this is not
Not proof that any tower would defend a channel. No such proof exists publicly, from anyone.
Not a watchtower. We do not operate one, and a directory operator who did could not be trusted about the others.
Not a registration service. Registering a node with a tower is a write call, and this agent has no write scope.
Not a guarantee. Alerts may be delayed or missed. You remain responsible for your node.