Skip to content
News Cybersecurite

Account Abstraction: Smart Wallets and Security

Account abstraction turns an Ethereum wallet into a programmable account. Instead of relying solely on the fixed rules of a traditional private key, a smart account can use multiple signers, social recovery, spending limits, batched payments or a third party to cover gas. ERC-4337 implements this model without changing Ethereum’s consensus through UserOperations, bundlers, paymasters and the EntryPoint contract. The flexibility improves the user experience, but adds code, permissions and service providers. A wallet that is easier to use is therefore not automatically safer.

Stylized Ethereum wallet connected to multiple keys, passkeys and programmable rules
Editorial illustration of a smart account built on account abstraction.

Why traditional Ethereum accounts are reaching their limits

This topic extends the discussion around multisig wallets and protection through multiple keys. An externally owned account, or EOA, traditionally depends on a private key. The same signature authorizes transactions, while the protocol dictates the validation format.

This simplicity provides a clear model, but makes recovery difficult. A lost key cannot be replaced. New users must also hold the native token to pay gas, even when they receive another asset.

A smart account puts validation logic in a contract. It can require two signatures above a certain amount, accept a passkey, limit a session or enable recovery after a delay.

Programmability does not eliminate keys. It makes it possible to organize their roles and replacement according to verifiable rules. Security then depends on the contract and its configuration.

How ERC-4337 works

ERC-4337 describes account abstraction without changes to the consensus layer. The user creates a UserOperation that resembles a transaction, including its destination, data, gas limits, nonce and signature.

This operation enters a separate mempool. Bundlers group multiple UserOperations and then call the EntryPoint contract in an Ethereum transaction. EntryPoint verifies the accounts, collects fees and executes valid actions.

A paymaster can fund gas according to its own rules. An application can therefore sponsor a first operation or accept payment in a token. This convenience introduces a dependency: the paymaster may refuse the request, run out of deposit or apply a restrictive policy.

The bundler does not hold the account’s funds. It handles transmission and initially pays the gas for the bundled transaction, then recovers the amount through the mechanism provided. An outage can delay execution without necessarily putting the assets at risk.

What these accounts make possible

Social recovery allows guardians to approve a key change after a delay. Guardians can be devices, trusted contacts or institutions. A sound configuration prevents a single person from recovering the account alone.

Spending limits can impose a daily cap or restrict certain destinations. A session key can allow a game to execute specific actions for a defined period without requiring a full signature for every click.

Batching combines several actions: an approval, swap and deposit can take place within the same logical operation. This reduces the number of steps, but users still need to understand the overall effect.

Paying gas in a token or through a sponsor makes onboarding easier for beginners. It does not make the transaction free: someone pays, and the cost may appear in a spread, fees or commercial terms.

Smart accounts, multisigs and custodial wallets

A multisig requires several approvals according to a defined rule. A smart account can include this feature and many others. The categories therefore overlap.

A custodial wallet holds users’ keys and may reset access according to its internal procedures. A non-custodial smart account keeps the rules on-chain and the signers under the user’s control, even when an interface or service helps manage them.

Some solutions retain a server key, a recovery service or a mandatory paymaster. They remain programmable but introduce operational trust. Read the actual model rather than relying on the “non-custodial” label.

The best choice depends on the amount, frequency of use, team and ability to maintain backups. A highly complex account may be harder to recover than a simple wallet.

New security risks

A bug in the validation logic could authorize an unsigned operation or lock the account. Modules added after deployment may have powerful permissions. Their audits must cover how they interact with the core.

Upgradability raises another question: who can change the implementation? A compromised administrator key could replace the code. A timelock and multisig reduce this risk without eliminating it.

Bundlers face anti-spam constraints and simulate operations. A UserOperation that is valid for the user may be rejected by a particular infrastructure provider. The ability to switch bundlers improves resilience.

A paymaster can censor an operation or impose limits. If the account holds no ETH and depends entirely on this service, an outage can block an urgent action.

Social recovery: useful, but plan it carefully

Choose independent guardians that do not share the same device, email account or operator. Three guardians controlled through a single cloud account do not create three separate barriers.

Set a threshold that can withstand a compromise without making recovery impossible. Two out of three may suit an individual in some cases; an organization may require a more structured policy.

Add a delay and a cancellation option. The account holder can then detect a fraudulent recovery attempt. Alerts should be sent through multiple channels.

Test the process with a small account. A procedure that has never been rehearsed may fail when the primary key disappears. Document the steps without storing all the secrets in one place.

Passkeys and modern authentication

A passkey uses a cryptographic key pair linked to a domain or application. It is more resistant to phishing than a password or SMS code. Integrating it into a smart account nevertheless requires validation that is compatible with the chain.

Cloud synchronization simplifies switching devices, but shifts part of the risk to an Apple, Google or password-manager account. A passkey tied only to one device requires a separate backup.

Check whether the wallet allows you to export, add a second authenticator and recover without the company’s involvement. Dependence on a proprietary system can become a problem if the service shuts down.

For significant amounts, combine a passkey, hardware key and multisig rule rather than expecting a single factor to cover every scenario.

Sponsored gas and token payments

The paymaster validates a UserOperation before funding its gas. It may require a service signature, a subscription, a specific token or an authorized action. Its contract must maintain a sufficient deposit with EntryPoint.

An application can offer a few transactions to simplify onboarding. It can also convert one of the user’s tokens to cover fees. Compare the implicit cost with the normal cost of Ethereum gas.

The sponsor should not receive unlimited authorization without justification. Read the permissions and revoke those that are no longer useful with the guide to crypto approvals.

A paymaster outage should not make funds inaccessible. Check whether a standard operation paid in ETH or another paymaster can take over.

Sessions, delegations and spending limits

A session key authorizes a restricted set of actions for a specific period. A game may allow internal movements without exposing the right to transfer funds to an arbitrary address. A business application may limit an employee to certain contracts and a daily amount.

The scope must remain clear before signing: destinations, functions, tokens, cap and expiration date. A vague delegation is almost equivalent to handing over the primary key. Interfaces should display active sessions and allow users to revoke them without depending on the provider that created them.

The nonce and replay-protection rules prevent an authorization that has already been used from being reused. Signatures must also be tied to the chain and EntryPoint, as specified by ERC-4337. Without this context, an operation could have an unexpected effect in another environment.

After testing, revoke the session and confirm the event on a block explorer. This practice reduces the exposure period for a secondary device or gaming application.

How to assess an account abstraction wallet

Identify the account contract, its version and its upgrade mechanism. Review audits, bug bounties and incidents. An audit does not replace an analysis of permissions.

List the signers, guardians, modules, bundlers and paymasters. Ask what happens if each one disappears. Can the account provider be changed through an alternative interface?

Check recovery and delays. A promise such as “no risk of loss” often conceals a third party that can restore access. Understand the exact conditions.

Verify compatibility with the applications you use. Some protocols handle smart accounts, signatures or off-chain messages differently. Test before transferring a large amount.

Migrate without exposing all your funds

First create the smart account using the official documentation. Add recovery methods and test a small transaction. Confirm that you can use a second interface or call the contract directly.

Then transfer a limited amount. Test a swap, an approval, a withdrawal and a simulated recovery. Monitor the bundler’s fees and delays.

Do not delete the old wallet before validating your backups. A gradual migration limits the impact of a configuration bug. For an organization, have the policy approved by several managers.

Account abstraction brings the wallet closer to a programmable account suited to modern use cases. It can reduce onboarding errors, improve recovery and distribute authority. In return, it adds contracts, modules and services. The best configuration does not multiply features: it keeps those that address a specific risk and remains usable when the primary provider goes down.

Sources cited1
BrefCrypto Crypto news from Africa and around the world
Follow us on Google News →
Lydie Musekwa
Author

Lydie Musekwa