Account Abstraction - Improving web3 UX to the fullest
ETHCluj Meetup·Wed, Oct 9, 2024, 12:00 AM
In this video presenters Adegbenga Ogungbeje & Gabi Vasile discuss Account Abstraction and dive into the evolution of blockchain user interactions. Account Abstraction enhances user experience by enabling programmable account behaviours beyond the limitations of traditional wallet addresses. By embedding smart contract capabilities directly into user accounts, this approach allows for customizable security measures, automated transactions, gas-less transactions and more, delivering a seamless web2-like experience for web3 applications. We also touch upon several key EIPs and ERCs related to Account Abstraction and explore the ultimate goals of this innovative concept.
Transcript
hey everyone today we have two fresh speakers Ben and Gabby uh guys thanks a lot for volunteering to do this talk so uh we're always looking for passionate speakers so uh their presentation is about account abstraction this topic has been around for a while but um many say that is still crucial for ethereum ux so um that's about it so b or uh actually Gabby uh you go first right uh the first one will be Ben cool okay just everybody if you can hear yes we see your screen yes fantastic so i' would like to welcome everyone to today's discussion on account instruction uh solving web3 ux um to the masses and the topic of account abstraction has been given many kind of phrases some people will say it's is giving people access to self custody some is ux self custody you hear different kind of phrases and monitors there's also a lot of discussions about changing the phrase s account abstraction which you can imagine is a mouthful and uh making it something simpler so just a very simple introduction of my myself I am a CEO and co-founder of a startup called alter rent we can talk later about it and I'm specializing at the moment more in centralized Real Estate Field but also with a strong emphasis on Smart contract security because of the amount of financial investment involved and account abstraction because of the problems of Automation and easy access to anything to do with real estate so I have about six years of solidity development so that's enough about me that's an older picture of me and without the beard that's a cleaner version of me so this is really what we're going to look at today for uh this is some of the projects I'm involved in if anybody later wants to come this is more specific to the account substruction projects I'm writing two books the idea started out writing one book on general account substruction or as Gabby and a lot of people who have doubled into there so much technical knoow needed to safely successfully imp C obstruction and not having to write a technical book side by side with a genu book so if you want interested in writing come and join me you want to write a chapter that's always a great idea I'm also doing some work on whe layers if anybody knows anything about reers the bunders are trying to replace to reers Gabby will go into a little bit more about what bunders are later I won't touch too much on it but I'm trying to introduce account struction to really and the one I'm focusing on the moment is the Wormhole reer most because of the security concerns they've had recently if you've been up to date with what's happening in terms of the hacks within the field and then also my own startup is a ux UI interface for people to access the platform and to help increase functionality for the smart contracts in terms of monetizing their rent deposits so those are three projects so if you want to get involved with me if you want to collaborate if you want to join an open source you're mother welcome so this is the agenda for today we're going to look at an introduction it's going to be very high level and after this we're going to have some subsequent discussions about account abstraction so we're going to gently progress it from high level and then we're going to get a little bit more technical so today is just a very good overview so I do apologize if anybody's quite convers of account obstruction this may not be the best format for you but it's a good reminder concretizing the foundation principles so in introduction we're going to look at the history the history of account of truction is very very critical to understanding where we are today the history is going to be more of the history from an theum basis but it's also going to parallel what was happening side by side as people are trying to implement account of struction into ethereum blockchain and what other blockchains like ail and ZK sync and stet and near have tried to implement won't go too much in depth into but just a little bit of the history and then jagon jagon is going to be just some of the popular terms you come across which may confuse you which may bamboozle you at some point but it just keep rough idea people are talking about the same thing so what is account abstraction just take a moment to think about what is an account we talking an account more from a blockchain perspective and what abstraction means most of us are conversent with what an account is we've either use an externally owned account which is just a big phrase for wallet so if you've used the metamask Ed the rainbow you've used the coinbase Wallet safe wallet Argent and buyer the list goes on and on and on and on you must have used an externally owned account and externally owned account has some very unique features public private key pair so you need a private key you have some kind of seed phrase could be 12 words could be 24 words as the case might be has some kind of nons involved and then some kind of signature model system signature to verify transactions to send transactions so your classic example will be a metham that's an externally owned account smart contracts accounts can be confusing but it simply means just a smart contract and if you've written smart contracts in solid You' me in Viper if you've written in terms of another language like flow or move or an Avil on the Sol blockchain it simply means the logic that is embedded into your smart contract and what functionality it gives now you can see the excellently owned account word is equated to the smart CR Che account so try and think what does that imply well it simply implies that the ultimate goal of account obstruction is to look at the functionality that externally owned account has so let's use MAAC as an example think of the functionality what you can do with it some of it limitations and can we take some of that functionality and put it into a smart contract so if you write some solidity code or some code in Viper it's on the flow blockchain on the move blockchain can you take some of the things I can do my metamask wallet and let my codes do it and that will get all of us thinking we get thinking now because we think what Can I Do by metamask account what are the things I can't do with it what are the limitations of a metamask account what are the limitations of a smart contract all these are critical to understanding why the push for account substraction is coming and the long-term goal just in a nutshell we don't remember anything from this presentation the long-term goal is to eliminate cly owned accounts make them deprecated make them defun make them Obsolete and to move the functionality to something called a smart contract account so let me give you an example that will help you think about it think about the difference between a horse for transportation and take for example a very old car model that sinking a horse has some advantages over the car and the car has maybe more advantages over the horse but think about how limited they both are in terms of the advantages think about how limited the advantages of the engine of the steering wheel of the tires and if you're somebody into sci-fi you seen Sci-Fi movies you've seen crazy things that car can do there well the new type of smart contract account is looking to make the functionality of our metamask I will sign transactions how we verify transaction we send messages how we store tokens how many kind of signatures the kind of cryptographic signature algorithm we have in there to become like a self driving car so imagine a self-driving car what you can do it that really what the goal is now this slide here very critical take a while to look at it if if you needed to unboard someone today in blockchain eight processes are involved to unboard the person contrast that with for example how easy it is to open an email how easy it is to maybe use your iPhone how easy it is to maybe use your WhatsApp account eight distinct processes and there are perals at every stage of the process and think about three kind of customers you might meet in the blockchain field take for example we have e CL or maybe e bra or e concenter as the case might be or E cry over your friend is Keen to come to one of these events you've been talking about web free all the time how do you get him to sign up for this event if the organizers insist on paying by E what if the organizers insist on paying by usdc what they insist on paying by a chain Ling token how do you get him to sign up for this events these eight processes is what your friend would need to go through just to be able to sign up contrast that we're going to watch a movie at the cinema and how simple it is compared to just going to this event so that's one customer that would have to go through this whole process of extending on the accounts another one could be someone that for example an older mom a grandom and Uncle maybe Facebook is now centralized want to go to decentralized social media so you brought up this great idea for this social decentralized social platform and your mom wants to come on board or your grandma to come with the current blockchain method she have to go through this eight processes just to have access to the blockchain metamask downloads onto the browser extension 12w seed phrase or 24 seed phrase store it somewhere three copies hide it somewhere and so on and so forth and the last customer example you can think about is for example you build an nft B people want to come on board and now you don't want them to make the initial payment for example you bypass the other two processes you say okay I will find a way to make the token payment for you initial token transfer for you because cut gas to come on board still the same processes somebody's got to go through at least six or seven of these processes that's the challenge where we are in terms of we three and why the demand for account substraction is really being pushed so that brings us really nicely into where we are and where we would like to go to all the information in red is the limitations of exteral own account some of them we spoken about and all of us to some degree might have lost some tokens or know somebody's lost tokens lost private Keys lost SE phrase lost account or know somebody who's lost it paid too much cash and had transaction reverted have somebody had their accounts broken through multi if they just set it to one to2 or one to three and so on and so thought in fact in fact from England where I come from there's always a story on the news of somebody that bought 2 BC BTC back in the day or four BTC back in the day when it was for example 10 or 20 or whatever it was he can't remember the private keys he can't remember the seed phrase he's on the last password three times it locks and he's frantically searching for it why because of the limitations of the own account which forces you to have seed phrase forces you a private key pair and forces you to have set Sy s that coupled into the original account so account is looking like a decoupling the coupling of the N abstraction the gas abstraction the key abstraction the signature abstraction and so on and so forth and the list of everything we can remove to have varied functionality imagine if we can have different kind of gas model systems different kind of signature systems different kind of transaction systems limit of transactions we consent limit of transactions per day per week specific days and so on and so forth that's what account of struction is trying to tackle with the smart contract wallet but even in that situation you can still see it has quite a few limitations and some of the limitations we still have is that ER 437 has come very very late now I'm going to tell you something surprising and this is this is the saddest piece of news you hear to today we could have implemented account abstraction into ethereum in 2016 let us sink in Bear REM mind bear mind etherum started in 2015 so we could have had coun stru at the native level but now we're trying to bring it back but it's hard to get dysfunctionality and people have lost nomy people have lost tokens people have lost hope in blockchain web three and all kind of disillusionment so that's the history as you can see I'm not going to go into every EIP maybe some of them are recognizable to some of you guys um there's been a lot of discussions and movements before we came to ERC 437 in the slide you can see it's EIP and does everybody know the distinction between an AIP and an arc well an AIP means you're working to implement at the protocol level which means you have to make changes at the coin infr structure of the blockchain noes changes changes to the original code on the evm and so on and so forth and which means these changes must be adopted by all the nodes so there must be a consensus that's an EIP but AIC means we can work more the application Level and ultimately they have to move account of structure for the three blockchain to the application Level now interestingly some other blockchains like ZK sync stocket and ail have implemented it at the native level but that'll be discussion for another time so now we have these two scenarios ethereum operate operating at the application Level with a 4237 which I'm going to talk a little bit more about later and then other blockchains having it directly like ZK and stocket or already and what it simply means is all remember all those functionality that we're looking for from the externally owned account to transfer to the smart contract account it already has it at the blockchain level you don't need to have anything extra and Implement another kind of interface or protocol for it to be implemented into your smart contract so we've now come to Erp 427 the whole history moves along and in March 2023 ERC 437 was implemented it was released implemented they had a smart contract audit very good audit by open Zeppelin and these were some of the goals they had so obviously to implement account abstraction nons substraction gas abstraction P abstraction signature abstraction and so on and so forth they looked obviously at trying to look at Implement time and gas savings so instead of sending one transaction two transaction three transaction four transactions and we know there's got to be a verification process on ethereum blockchain if you can send a bundle of transactions in a certain time period your transactions go through quicker and obviously you save more gas because if sending one transaction for example approve this or token swap on Arbitrage or Flash loan or yield farming you're going to spend gas every time so that was one of the goals it aimed to look at consensus preservation ande out toies consens preservation we don't need go to theol Talking specific on ethereum blockchain we don't need to change the proof of State consensus the transition from proof of work to Pro we don't need to change it we can just work with the concurrent consensus and then we can work with it but also more interestingly it means it now gives it the leeway if I want to introduce a proof of authority into my d a proof of hack into my dap a pro of reputation into my dap a delegated proof of St into my dap I can work with that and still work with the original proof of stake consensus on eum blockchain obviously decentralization a lot of ethereum is not centralized as you public could reckon lot of discussions about using cloud computing behind the scenes and Lio and how many are running on centralized cloud computing providers there's a lot of discussion about that and he looking at can with the couple things to get through the centralization as opposed to having things and many of you have heard about a lot of the conversations of whals and how even though they started out being centralized decentralized eventually became centralized because you had big parts of Wells coming together and working on a central basis to get the maximum kind of ethereum and Bitcoin and also working with new use cases use cases for example making Atomic transactions having different kind of signatures I'll just give you one use case with the current system we have now if I'm able to hack your account I can drain your whole account and there's not much you can do to stop me I can drain everything an externally owned account if I have access to your private ke or to your seed phase and I can drain everything to your smart contract account if I can get some kind of Access Control contr or front running or re-entrancy attack you know and the Del goes on and on and on and on but imagine if I can introduce logic into my smart contract account where I could say everything the smart contract logic into my account and on Monday the maximum amount that anybody can withdraw even if it's haed is 20 and the final Supply within the account is 1,000 e how secure would that be how much confidence that would give to the general public and the big players to come in as opposed to the current system where if you have 1,000 eat and I get into your account I'm draining everything yeah except you have some white hackers to come in and drain at the same time and and that's the best we can do so that's just one use case of the objective now these are some of the exciting features VC 437 I've already touched on some of them and some of them may shock the wallet recovery how many of us have lost a wallet before technically lost an account I have open the metamask account wherever it is can't remember the seed phrase can't remember the password have1 in there sometime €200 whatever it's in there canot remember for the life of me so the account and the key are synonymous my wallet is the key and the key is the wallet so once I lose my key lost my wallet how to recover wallets through social recovery multi sign transactions I've already talked about it I want to send different kind of transactions for different kind of scenarios so in of having just one particular kind of signature for a particular kind of transaction I can have different kind of signatures the signature currently in place now is the ecdsa which means every time I use an excellent owned account I can only use the ecdsa and the ecdsa is very very backwards in terms of where our current cryptographic algorithm signatures are there stronger ones like schnars like BLS have come along so if for example I set up a system of payments in my company I can say top earners over €100,000 BLS Next Level 50,000 I can say schn signature Next Level I can say okay I can have an ecdsa that will give me a range of signature aggregation I could use for different kind of transaction payments obviously talk about bonding transactions you sending one two three four five transactions just to get one outcome they can bondle that transactions make one single Gas payment that would be a great idea spoke about custom limits you can limit how much could go out from your account on a daily basis if you get hacked or if there's any danger of any kind of situation I can just limit it and that we can Implement through 3437 and that can sponsor transactions so remember the earlier situation I spoke about you have a friend coming to e pluge he ain't got no metamask account he doesn't want to go through the whole rigma Ro of metamask account you can delegate that trans transaction payment to someone else and they pay for him he just pays with Fe and he just comes it doesn't bother about M downloading and SE phas and all that so that's some exciting features these are some Jon you may come across they all mean the same thing they just similat in some ways so you may come across people using the phrase hand abstraction obviously people use the phrase chain abstraction chain abstraction is just looking at how people are working within the blockchain and it's almost working blind they don't know any of the workings behind the blockchain so all the current functionality of having a seed phrase and signing transactions all happening behind the scenes and they're just using like a traditional web 2 login or web3 authorization login to come in and obviously a smart contract wallet it just gives you all the same functionality of multi gasless and sponsor transactions C limits to factor authentication social recovery and so on and so forth and those are some links in case anybody wants to stumble upon any more Jaron so that's me I have a remaining number for now so you can call my remaining number for now um and that's my LinkedIn that's my email and then that's my my Twitter so if you want to have a further discussion any questions feel free to get in touch with me and um that's my presentation so thank you very much for listening thank you Ben that was a nice presentation thanks Ben before we move on um does anybody have questions I I do have one short question so why um I'm not sure I understand why uh as I saw in your presentation that okay so the private key is a single point of failure but why it would be better to have like the web to to factor authentification things um I'm not sure I understand like as as a security reason okay that's a good question the current the current kind of authentication on authorization methods from web 2 are centralized so still a centralized argument so that's a core argument of trying to move away from centralization and decentralization because Google WhatsApp Netflix any system you're you're accessing through that web to system authorization authentication they can access your account Google can shut down your account it's it's no no difficulty so that's more of a centralized decentralized discussion the current problem we have within web three is if you just have one single key to access your account and if it's not a multi and you don't have a range of types of keys of implementation and types of signature that means if you lose that key then you're limited and even the difficulties of multis even though multis sounds like a great idea the uptake of multis has not been as po people expected so very few people actually use the multi to access their day-to-day account so even though it's there it's not actually had a great uptake that's why giving you now a range of key access systems so that if you do lose your key and you're not implementing a multi you can use a social recovery system within7 so actually recover your key and have access to your account okay so uh in this situation um for example um yeah the the The Ledger the the way they recovery private keys if we use something like even less safe for example I don't know Google to recover our key isn't this even a bigger point of failure yes yes yes you see so that so from the web to situation is a bigger point of failure if Google goes Rog so that's why say for example has now implemented a web to authorization SDK that is also web through authorization SDK It immedately Go from a centralized to the centralized system so if you failure points of failure with the centralized system you have the fallback save of the centralized system and this an SDK that safe as implemented but long long term we want to try and move away from allowing big institutions big Enterprise to easily access our accounts and maybe in countries where there's a measure of democracy is not a problem but in countries where there are maybe totalitarian systems is really problematic because they can take control of the systems and easily access your account and that can be a problem if I can read your emails on a daily basis it's problematic thank you for explanation you're welcome yeah if there are more questions I can start sharing my screen sure go ahead thanks Ben I really liked the way you presented easy to follow okay just one second okay can everyone see my screen yes okay hi everyone I am Gabel Marian I'm currently an S engineer at B economy and I'm focused on improving web3 user experience through account abstraction I have three years of experience in blockchain development uh with a particular focus on Def applications okay so um than the first thing is let's see what ESC 427 is uh basically ESC 427 is an account obstruction proposal which completely avoids the need for consensus layer protocol changes like Ben also mentioned uh instead of adding new protocol features and changing the the bottom layer transaction type this proposal introduces a new higher um layered SoDo transaction object called the user operation which we will talk about a bit later on um users will send user operation objects into a new separate M Pool and there is this idea of bunders which will package up a set of these um objects which are the user operations into a single transaction by making a call to a special contract and that transaction then will be uh included in a block okay so the main components of 437 uh which I think are the main components there are many other than these but for me it's the smart account wallet uh is the Smart account Factory the entry point bundler user operation and uh pay Master we'll start by talking about U the smart account wallet so the smart account wallet it's a smart contract which aims to do everything an EA can do but much more than that now to support um esc4 37 wallets must Implement a smart contract that is required to have two functions uh the first one is this validate user op which takes an user operation as an input and this function is supposed to verify the signature uh and N of the user operation uh check if it if it can pay the fee and increment the N if the verification succeeds and throw an exception if the verification fails uh just checking is my screen uh visible I had some internet problems earlier so yeah looks good okay all good thank you uh yeah then there's this execute method which also needs to be implemented on the smart contact account uh this will interpret the call data as an instruction for the wallet to take some actions how this function it's like written depends on the smart account provider like each smart account provider has different um different implementation of these smart contract wallets like for example B economy Alchemy kernel all of them have different implementations um once the smart contract um has this logic you can go ahead and Implement other custom features like smart account modules like batch execution of fer Ops different signature schemes and more now having so much freedom of implementation is both good and bad um it's good because you are free to add your own logic and like customize your smart contract however you want but it's bad because um it's the all the smart accounts will not be compatible one with another and especially this has been an issue on Smart account modules where one one one byon module is not compatible with a mod from Alchemy or from safe or from kernel or from other providers um if anyone has any question about that or we can ask questions at the end I think it's better right or however you guys want guys if you have questions just um you you can also post them in the comment section or in the chat okay okay yeah nice all right then let's what is this smart account Factory so the smart account Factory it's a smart contract it's um different for every provider and is responsible of deploying smart Accounts at the counteract your address which can be known before the account is deployed this is the idea of counter factual address is that you know the address of the smart account before it is actually deployed on chain now a smart account will be deployed as soon as it sends the first user operation a deploy transaction will be bashed in the first user operation if the smart account is not yet deployed in order to deploy the smart account um of course the smart account needs some funds to pay for the gas so this is one step Ana needs to take is to pref fundo in order for the smart account to be able to pay for the deployment this is only um viable if the smart account doesn't use a pay Master if the smart account uses a pay Master then the EA doesn't have to be funded uh you can also specify an index when deploying a smart account and this is because we want each EA to be able to have many smart accounts so for example your EA could have a smart account address at index zero and could have another smart account address at index one 2 three and so on the maximum number it's 2 to the power of 256 minus 1 so it's a pretty big uh index now let's see what this antio contract is and this is one of the most important elements of esc4 27 uh this is because this this month this bar contract it's first of all it's a single tone it's only it only exists at one address and it's once uh it it's one entry point per chain so there's no clone of this entry point this is audited by uh many companies and it's a trusted smart contract um yeah this is um yeah as I said this is a consistent address across all the chains um this contract interacts with all the smart accounts to validate and execute the user operations and it also forwards the gas payments to the bonders we will see a bit later how how this is happening I have some diagrams where I'm showing this um the contact provides two main methods it has the handal Ops and handle aggregated Ops uh the handle Ops method will like processes user operations for accounts that do not require uh signature aggregator while the handle aggregated Ops method will handle batches of user operations from multiple aggregators the discussion will focus only on the on the handle Ops method uh the handle UPS function follows up a tool Loop process which is one a verification Loop and the second one it's an execution Loop now what happens in the verification Loop of this handal up method from the entry point is um first create the account if it does not exist so this is what happens when you execute your first user operation on your smart account it will check if your account is not deployed U or it is uh if it's not it will use um a field on the user op which is called init code um if the account does not exist and the init code is empty the call must fail it will also calculate the maximum possible fee the account needs to pay based on validation and call gas limits and quent gas values it will also calculate the fee the account must add to its deposit in the entry point because every smart account needs to deposit some ethereum in the entry point uh in order to in order for the entry point to be able to pay the bundler for the execution now again if the smart account uses a pay Master this the smart account doesn't need to deposit any e the E will be deposited by the pay Master okay next step is to call the validate user up on the account so this is a method from the smart account passing in the user operation the hash and the required fee and then to validate the accounts deposit in the Eng point to check if it's high enough to cover the max possible gas cost okay after this verification Loop uh in the same function so in the same handle UPS method we have an execution Loop um what this does is call it calls the account with the user operations call data and it's up to the account to choose how to pass the call data and what to do with it um after the call we will refund the accounts deposit with the excess gas cost that was pre-charged uh because the gas needed for the user operation is mainly estimated by these 427 INF infrastructure services and most of the times will be bigger than what they actually need and they will return an excess gas back to the smart account after the execution of of all the calls we pay the collected fees from the user operations to the banders um and that's it for the execution Loop this is an execution Loop without the payment St um so yeah we have discussed about a few elements the smart account wallet smart account Factory and entry point and this is a simple diagram on how they work together so you see the first step here is to call the handle ofs method this can be called by either the EA or by the bundler which this is what typically happens the bundler is the one that calls envelopes um it calls you see the the Second Step here it's to call the create using the init code this will only happen if the smart account is not yet deployed so it calls this create method on the factory which will create an account which it will return the account back to the entry point and then the entry point will call the validate user up on the smart account which we check um does the smart account have enough um if deposited for this transaction in order to pay for the gas fee um it will also check is the signature correct so did this EA really sign this user operation so it will recover the address of the signer and check all of these fields um after the validation is done the account needs to deposit the e in the entry point then then uh it will deduct the account deposit which is basically these are some State changes in the smart contract and then eight and N is basically the same thing but for the second account so after this all done we deduct the the gas for each account and this is like the verification Loop and then there's this execution Loop and in the execution Loop what happens is the entry point will call exec method on the smart account after that is executed we refund the account the excess guas and after that we compensate the beneficiary here which is the the bundler um yeah so uh let's talk about the bundler and see what it is so the bundler is a service that tracks user Ops that exist in an alternative mle and as the name suggests bundle them together to send to an ENT Point contract for eventual execution on chain you can think of this bundle as an executor or relayer if you know this term better so essentially what a relayer is it's very high level it just does stuff for you it executes some actions for you um so it will be responsible of calling the entry point and it will initially pay the yes for the user a Bund is like the core structure component that allows account obstruction to work on any evm network without requiring any changes to the protocol uh its purpose is to work with a new mle of user operations and get the transaction included on chain now on the right here you can see this uh very simple flow of a user screaming for help uh so he has this user up and he wants someone to handle it for him and there comes the executor or the bandler or relayer however you want to call it so it will take um the user up from the user it will call the handle up method on the entry point the entry point will call validate up on the smart account wallet after that is done and the user op it's fine the entry point will call execute up on the smart account wallet again and after this is executed the entry point will refund the bundler for his work um and the user is now happy here's another diagram um again very useful you can see here we have a users they are all sending user operations these user operations um are sitting in a mol where they are waiting for a bundler to pick them up the bundler will will create this bundle transaction which is a normal ethereum transaction but contains um contains this user operations bash inside of it and this bundle transaction it's added in ethereum block and an ethereum block can have many bundle transactions yeah so we haven't discussed about what user operation is and how it looks um here it's represented in its core form a so struct um it's a so basically user operation it's a SEO transaction object which is used to execute actions through a smart account um user operations will be sent to the user operation mol as we already mentioned earlier which is a dedicated high level men pool spe specifically for user operations so instead of going to a traditional public men pool that we all know of um this will uh yeah instead of going to mol that host the pending transaction it will go to the user operation M now these bundlers will listen the user operation mol and bundle multiple user operations to together into a classic transaction they first verify the validity of the user operations using the relevant entry point methods which we have already mentioned the bundler then includes that multi-user operation transaction in the next block and they propose it to the network and you can see here what um what the fields on a user operation are uh I can tell you like the center is the Smart account wallet address the N it's for anti-replay protection and it's also used in in the start um when at first time when when the smart account is deployed the init code um it's used only to deploy the smart account and when the smart account is deployed this should be empty the call data is the data to execute it can be whatever um the call guys limit is the limit for the execution phase so like the ex Loop that we have discussed earlier about the verification gas limit is the limit for the verification itself um the prever verification this this is for the bundler is the gas required for the bundler to um validate and to verify the user of chain we have the max superer gas and Max VAR superer gas these are like classic and they are also present in the like normal eum transactions payment data this is to provide the paym address and the paym data um and this is typically empty if the user operation is not sponsored and then the signature of the UA okay let's you uh quickly what is a pay master so account obstruction willn't be complete without the paymaster uh which is essentially a smart contract that will deposit e in the entry point in the same exact way as smart account will do it each a provider has freedom to customize their their pay Master content however they want as long as they follow the I pay Master interface now one of the major challenges of an EA is that the user has to hold eth in order to do anything on chain well with pays ESC 47 allows abstracting the gas payments alog together meaning someone other than the wallet owner can now pay the guess um one phrase I really like to mention when talking about payas is users don't pay AWS fees when they are using web apps so they shouldn't be required to pay any fees when they are using web 3 apps if we really want uh High adoption um how this pay masters work well the main method of the pay Master contract is this validate oops my bad this validate paym user op which takes an user operation user operation hash and a Max cost inputs uh the entry point will call the pay Master methods when pay master in data field is not empty for a user op um the validate pay user recovers the signature from the payman and data and checks if the signed uh if it's signed by the design uh design it signer then if the signator matches it checks for balances in the pay master and if the pay master has enough balance the user op will be sponsored uh one thing that changes now when we are adding a pay master in the entry point flow is that we have a few extra checks so now we call the user validation method on the smart account wallet which was also present earlier but now we also have to call this validate paym up on that paym because the paym needs to check if it has enough e to repay the bundler now for each Loop we call this execute to on the user op sender wallet uh tracking how much gas we use then transfer the e to the bundler to pay for that guess if the user op has a pmas fi then this e comes from the P Master otherwise it will come from the wallet as before um yeah so I will go fast actually into this let's me see yeah there just a few slides left so the erc20 P Master it's very simple it basically allows an smart account to pay the guas in erc20 tokens this is very useful for examples when a user may have 1,000 usdc but he doesn't have any e so he doesn't have funds to pay for even to swap that usdc for example um so yeah the a probity typically uses offchain logic to calculate the token fees um this process involves like obtaining token codes from third party sources like coin market capup and ensuring that the fee covers both the gas cost and the additional charge for the payas service uh the payas contract pays the gas in eth to the bundler so it doesn't pay the bundler in esc20 um but it does receive the equivalent value in the year C20 token bonomi is an example of an a provider that offers both sponsored and esc20 paymaster modes and this is the diagram included in the paymaster so you can see we have um the validate user op so yeah handle UPS then validate user op on account uh then we have this new extra method validate pay Master user op on the pay master and then we deduct the pay Master deposit instead of deducting the account deposit and in the execution Loop um we Call Exec on the account and now we need to also call this post op method on the pay Master which basically does some um like it it updates the states with some last changes like modifying the the balances of the pay Master ID and you know just synchronizing the contract State and then yeah refund the pay master and compensate the the bundler and this is a flow with the paym so as usual the user doesn't know what to do so he asked help from the bundler the bundler will call the handle UPS on the entry point uh the entry point now has an extra step to validate also the pay user um which is a method on the pay Master contract uh the pay Master with uh refund the ethereum if this is valid entry point will call validate top on the smart account wallet if this is fine it will with executing the user op if this is also fine and doesn't revert then the entry point refunds the bundler with the ethereum that was received from the pay Master this time not from the smart account yeah and uh some Last Words some other advantages of ES4 dy7 um it's important to note that a providers like offer more than just sponsor transactions for instance we had by company provide like various modules including a session key validation module batch session validation module which batches multiple user operations with one session key account uh these two modules basically offer a very nice ux because you don't have to sign now every time you do a transaction on your dab so you can pretty much create like a a clone of Unis swap where you just sign one time when you Lo when new login uh we have we start a session and for like one or two hours you can do anything you want without having to sign for your actions and yeah we have other modules as well like social recovery module multi and much more uh modules are great a feature of AA enabling the addition of custom logic to Smart accounts that can be easily enabled disabled or replaced for example a smart account could implement a custom module to enforce daily spending limits like blocking any transaction once the limit set by the user is exceeded this will be a very nice feature which even I will want on my EA now another idea which I will also want on my UA is a module will which will be which will be blocking tokens which you have not allowed to be received in your wallet because I don't know about you guys but I have this problem where I rece receive daily scam tokens and spam tokens and whenever I want to watch U you know my my portfolio or something on on block scan I have a lot and also my transactions I have a lot of incoming transactions with random tokens coming to my uh to my wallet um so yeah this is it I had other slides as well about some eaps but um I think it's enough for now we can do another talk later on maybe next week on whenever you guys want also if anyone has any questions uh please let me know yeah that that would be cool I saw Gabby I saw you on that slide that you skipped past uh so so there's also native account abstraction right uh that this one uh I think so I don't remember the exact VIP number uh 7701 so there was by May or so oh okay yeah um yeah we have like there are a lot of things to talk about there are a lot of vaps Andes which keep coming in and we can't even uh like keep track with all of them uh but 3074 honestly it was a good idea four years ago when it first came out uh but then it got approved and then a lot of discussions were started about it and we found out that it's very unsecure and it's not safe uh and then this guy that worked on it for four years was so happy when it got accepted um but then but then vitalic came in and he proposed the AP 7702 in like a few hours and now 3074 may not be included in the next hard Fork yeah and EIP like 7 7702 basically simply put it just it will construct it will transform your EA into a smart contract account just for the time of when you call a transaction so it will transform your UA into a smart contract account by deploying some contract code into your UA at the start of the transaction execution and at the end it resets your EA back to an normal EA this is very interesting yeah we can discuss about it uh whenever you guys want maybe on another uh talk yeah that definitely a cool subject for the next one yeah cool just just want to com what you said you said you refering to Native account abstraction so everything on ERC on ethereum is not native account obstruction there's actually quite a big discussion recently between your advice your advice is one of the co-authors on7 so your kristo gra guy from pemo and dra to Russ and a few others they coauthored ERC 427 and there was a discussion from the ethereum community from a select group group that said why don't we look at implementing it at a protocol level so they are working on a project they're using zks and some other kind of different kind of methodology but nothing is there native but the native account abstraction is either like a ZK sync which means your smart contract gr gives you all the functionality that we spoken about or like a stocket and there also one or two other blockchains that now have native account abstraction but not ethereum MH yeah thanks for clarifying other questions hey guys yeah I'd have one question uh obviously account oftion is something maybe slightly new for some of us in here so I would uh well first of all thank both of you for such a nice presentation on on this uh subject and wanted to ask each one of you what's your favorite account abstraction wallet application and and maybe what you would recommend to start with eventually thank you um sure you mean account obstruction um wallet or DB or whatever project yep pretty much any um yeah I I do like a lot um there is this account instraction wallet um buyer it's called um buyer they have very nice uh ux um also I have uh a nice project which I wanted to quickly demo after the talk um one is a personal project which I'm working on with a friend of mine Gabriel sta he's also here and the other project which I wanted to quickly demo was a a DB I used with account obstruction and I liked it a lot so if you guys have time I can do a quick five minutes demo after this yeah I'll just say in terms of account substraction wallet the pH account obstruction wallet breaks breaks it down into two categories because we have certain smart contract wallets like gab related to like amb like a like the French pronunciation agent that already implemented quite a lot of good functionality that's almost paralleled what we have with we 47 remember sp7 you have the bundler brings transactions together you have the payman sponsor transactions you have the entry point to verify those sponsor transactions you have the user account which means you can get more kind of variables and data into your original transactions some may argue is more like a struct and so on and so forth so you have that category of wallets then you have some wallets which are now implementing server now coming say r47 compatible so from thec47 original boards they're called infinitism they have a wallet called trampoline it's very bad I tried to use that e Paris it just was not compiling it wasn't working well you have unipass unipass have a hardware and a software wallet the these ones are ERC ERC 437 compatible wallets they're slightly different from account substraction wallet because Amer and the agent have not implemented thec 437 they have similarities in terms of functionality so you have uni pass you have safe I don't know why safe decided to have a wallet because they already had similar kind of functionality but at I would say my favorite at this point in time is probably the unipass because they've taken the best of Hardware wallets the best of software wallets they've fused it together and is pro compatible there's others there's others that are there in the pipeline in beta like uh Candice and so on and so forth but would I recommend anybody use them at this point in time and risk your tokens I would probably say no so I'll go with the uni pass one at this point in time but a is it's a pretty good wallet in terms of just general account substraction wallet but it's notc 47 compatible they're trying to make ITC 47 compatible now um I'm not too sure why but yeah thanks so much actually I I saw you mentioning on the ethereum clu telegram group The ire and AR but yeah that's all good advice actually guys uh just a small favor from you to to ask if you can share this thoughts uh I mean your favorite you know uh Wallets on our telegram channel that would be great as well because I think a lot of us can benefit from this uh as for the demo uh that we were just talking about earlier I think this this could be a good topic for one of our uh followup meetups if that feels right for you guys yeah sure okay thank you so much for your answers thank you um okay so you guys are saying to like do the Demos in another call or if it's just a a question of like five minutes or why not but if you want to maybe like go through it a bit in more depth maybe it was just yeah quick demo like five minutes go ahead why not yeah sure okay then maybe we can follow up with uh more in depth if that feels right yeah sure okay yeah so let me actually go to oh no this is good yeah so this is a quick demo like this is called enty this is a project I'm working on with gabrio sea which I mentioned earlier he's also here um and this we are basically very early working on this product uh the end goal is a single point of uh single point app of like managing all your smart accounts from all possible smart account providers you can see here I'm connected with my metamask wallet and I have added or imported or created some smart accounts um and I can easily manage them from here and for example I can go and add a smart account and I can just create a smart account from here or I can go to import and this should search all the smart accounts uh from my eoa like from different providers for example for safe it has found that I have deployed all these smart accounts which are not already here in the in the in this table so I can go ahead and import them for example and for by economy it has also found a smart account so yeah I can go here and I can import them and for example I could go to the smart account page and here we don't have a lot of data because this is on sepolia right now so we can't really read a lot of analytics or anything you can see this smart account does have a user executed so we have a user operation history uh we can easily deposit or withdraw ethereum from the smart account and here at the right side if you have tokens in your smart account they will all show here uh with like percentages of if the to when it's up or down and actions like like receive withdraw um Swap and so on and we also have this page with DBS we right now we only have unisab and liquify and they don't really uh work right now because we have some bug which we have to resolve but the idea is you are connected like you switch to whatever smart account you want and you can interact with any um any D that support smart accounts directly from this platform so you can do swaps you can do anything you want um yeah and this was a quick demo about this and another project which I really like and I want to show you guys is es and this is using the bomy SDK and the B economy infrastructure so I have my EA connected which is this address with 986 at the end but under the hood this project it's using uh account obstruction and my EA is actually using a smart account um so you can see here like this this platform basically allows you to buy parts of nfts um for example there is this or this one this nft here and you buy tickets which are like SP parts of this nft and the more tickets you buy you have a higher chance to win this nft on the lottery and let's say you know I buy this ticket from the nft I have to sign this transaction I don't need any ether in my UA because this transaction is being paid with usdb which is it is it is their esc20 token basically so I don't need e to pay the gas I just need this usdb token and if I quickly go here to my tickets and we go to activity I can see my transaction here right so and if I go to the transaction you can see I paid $ one usdb for the NFD and a very small fee for the guest in usdb and if you go a bit down and you decode this input data you see that the method that was called to do this it's the handle Ops method from the entry point and we have the sender which is our smart account address sorry okay um yeah the N theit code which is ZX call data and so on and we can actually see our smart account here it doesn't have any ethereum it just has this year2 to um so yeah this this was it a quick demo of these two applications thank you guys thanks it would be nice to see what other features will be added to enty I'm really curious um yeah we have a lot a lot of things that we want to add um but we need time and we need uh also some funding maybe because we really want to get this project like to be pretty big and to be as I said the one single entry point to all your smart contracts like manage all your smart contacts from one place currently like safe and pal d there are some projects that um allow you to see some analytics on your smart accounts but they all offer you the view only on safe accounts so you if you have bomy or kernel accounts or other type of accounts it does not see them and you you do not have all these features of like a portfolio page for your smart accounts and stuff like this so yeah if you guys have any feedback any ideas or anything yeah if any if anyone has anything to say you can say now you can ask me or we can discuss later after this one it it might take a bit of time to gather some feedback so we usually do this in another section called ethereum Think Tank where people present their projects so we'll get content so if you want to present the project in there and whatever other ideas you have on how to continue then you probably get good feedback so people are get gaing especially for this to give feedback to projects and to challenge and things like that yeah sure keep in touch for that cool on um back to account abstraction any other questions hello yes I do have a few questions umad regarding the alternative M poool each provider each smart account provider will have its alternative mol or it's a common Mol for all the providers this is a good question um I think it's a common mle for the providers I'm not sure actually um this is very close to the infrastructure team I think it's one meanful for all the the the providers well I'm not entirely sure and do you know if there there is U sorry Alexi there is conversation about having localized M Poes for certain transaction speeds prior to that would serve the purpose of simulation before sending it to the main alternative m one of the reason is to deal with the the type of transactions you're sending and the amount of transactions and the duration of the transaction so if you have some transactions that are similar in nature and you have a constant kind of logic in those transactions on a regular basis if those transactions are always going to the alternative men pole and then you're losing time you're paying a set G and gas cost or sponsored transact or sponsored in terms of the amount of pay there's discussions about having localized mempo so there's a company called block pie block p is pioneering having alternative MOS for transactions with similar kind of L and these transactions will be batched together as one single transaction so take example I have one transaction all for yield farming maybe there six or seven I batch them into one type of transaction I have maybe seven for some kind of token swap patch them into one then we going into a localized meno and then we're just going have one single transaction into the alternative mempo so yes you are correct there is as as Gabby said there is a generic alternative mle but there's discussions and if you wanted to get a bit more information about it the ERC 437 has a developer call group they're up to about 25 series 25 this is call development from the infinitism group so it's the call development they're doing and they will give you discussions about in-depth work where they are so the last time I attended I think it was public series 19 they were activ talking about having localized men pools okay thank you um I need to to research more on on this for sure um and I guess this alternative manool and the bundler are centralized points right for now at least yeah um the bond there's the test feet for bonders there's the test specification all bonders need to pass yeah so the bonders are operating offchain the offchain if you classify offchain as centralized then if that if that's the phrase you want to use we they generally don't say the phrase bondons are centralized but B can simulate transactions offchain before defining transactions go on chain yeah to check if the transaction will go through yes yes yeah but but there is there is a level of decentralization um so I would probably go with hybrids semi decentralized as opposed to just being totally centralized yes they are they are not totally centralized because the validations are done onchain and offchain but if you ask a very Dent guy from web 3 he will say they are centralized and that's why leads native account abstraction in the end uh I share the link in the chat if you guys want to have a look on if you want dive in account obstruction this is the best repository you can find the zoom chat or the uh in the zoom chat yes can I'll also say everyone that there there's a lot of information out there about traction pitched at different level I have a I have a Meetup Group which will be pitching discussions at different levels so there will be definitely technical very technical discussions for individuals who want who are just building directly with for example 6900 or 7702 or as the case might be but also more of tackling it from an executive level level and an investment level than looking at what maybe just generic applications are looking for and how to implement it as the the pros and cons so if anybody wants to come your mother welcome come to the meet up and if there's any topics you would really like to see then we can pitch them and have a conversation about it cool thank you guys so definitely keep in touch and um if there are no other questions then we can call this um Meetup really nice presentation thank you very much thanks everyone for joining and see you next time keep in touch on telegram thank you guys than you everyone Thanks for tuning in bye bye byee byebye
Automatic transcript — names and jargon may be misspelled.