New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Smart Accounts need Smart Sessions by Pedro Gomes | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

The world of dapps is evolving and wallets are becoming smarter. This is powered by developments in Smart Accounts which unlock more user-friendly experiences. Learn about how WalletConnect is introducing Smart Sessions and walkthrough all the standards (EIPs, ERCs and CAIPs) that will make the future of wallet UX possible. Speaker(s): Pedro Gomes Skill level: Intermediate Track: Usability Keywords: interoperability Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] thank you thank you thank you and thanks to my fellow Portuguese for pronouncing my name correctly for the first time in a conference so as you heard my name is Pedro Gom I'm the founder and director of the Walla connect foundation and I'm really thrilled to be talking to you more about the future of Walla how we're going to change the experience for users and most importantly how we're going to have Smart accounts use Smart sessions and why why do they even need smart sessions obviously I don't expect people to know what smart accounts are or what smart sessions are and I feel like we need to kind of go on a journey why wallets work in the way they are so let's start with breaking down the lingo like when you think about wallets you might think about the leather wallets in your pockets or you might think about the digital wallet in your phone and you might even think about metamask rainbow zarion trust wallet all of these blockchain wallets but what makes them so different as a blockchain wallet it really comes down to this experience of before we used to log in into applications and now we connect but it's not just the change of the word itself it really changes the the infrastructure and the technology behind it that completely revolutionized what is going to be the future of the internet and all of these applications so you see all of these terms throwing around like dabs and wallets and smart sessions but it all comes down to authentication like authentication means it's the process of proving who you are and what you own and in a short word when user sees authentication it just means that you want to get in like let me in I want to get into the application that I don't really care and if you don't really care you really want to make sure that you do as less clicks as possible like less clicks is more this is our mission for building a great better user experience a wallet is better the less you have to click around but a wallet is also a little bit more insecure if you don't approve everything and that's where the tricky part of balancing convenience and security so why is web 3 different like we talked that there are physical leather wallets uh there are digital wallets in your phones uh why are web three wallets or blockchain wallets any different I like to always bring probably one of my oldest diagrams I've been presenting this diagram for more than 5 years and this kind of explains uh very simply how the infrastructure had changed from web 2 to web 3 before we had a server that was powering your application but these servers um inside have this module that's called authentication um some people even call it identity but this is basically what your login looks like your login lives in the server and blockchain obviously does not have a server and you can't just put login in there so it was cleverly designed that we put the wallet on the user side so as you can see the wallet sits on the bottom no longer in the blockchain and that means that now the wallet is your authentication which is from the app but it has also created the inconvenience of now every time you use an app you need a second app which you know it does have its advantages but it also adds more clicks which is against our mission here so when you think about the wallet it kind of comes down to like credential signing in account and I kind of try to break down here what it looks for different wallets it really doesn't matter like if you have a mobile wallet a browser wallet a hardware device or even if you use a cloud or NPC like they all come down to like something you know something that you are and something that you have and it basically breaks down in credential signing in accounts and you can see here that one thing that they all have in common is this concept of an external account which is going to be important for you to remember that no matter what w you have they all have an external account but before we get into that um I did say that connecting is this new verb that we moved away from the login but we did try to recreate login uh with blockchain and basically didn't work really well until someone came with a standard which is called sign in with ethereum and sign in with ethereum actually is just this uh it's a text message it's actually very simple like when you think about it it just says this website wants to access your account and then we added some parameters that says like you can access this chain for this amount of period and so on and so forth and even throw in some terms and conditions to make it look very familiar but this is actually more familiar because if you do Google login it's the same thing but we're so early into blockchain that we don't have this beautiful UI on the right we have a text message so wallets are slowly adopting signo ethereum to not just be a text message and to actually be like a concise and compact display that allows you to connect and eventually you might even have this like you actually have a s ethereum here I just modified literally the Google one and I put like some ethereum stuff but it in concept it's the same thing it's the exact same thing that s tries to achieve with a difference that you still have to connect to then sign which doesn't feel very great like it's like a twostep to do something that was before a one step so I'm part of this uh Community called the chain agnostic Improvement proposals that and we propos this wallet authenticate which basically tries to bring back uh the login experience and basically that meant that we what if we just don't connect anymore we just like go straight to the signature so if you could just do sign with ethereum like you could actually get this like Google login experience with your wallet and it would be even more secure because when you're signing your wallet and connecting at the same time you're actually verifying ownership of your wallet so this was actually pretty cool and this got us like you know like less clicks is more but is that enough like because at the end of the day most wallets are used for transaction purposes and logging in is just one part of it so yes we reduced connect and sign into a single step but after you log in or you connect with your wallet you still need to perform some transactions and this looks as you know switching to the wallet and everything approving transactions and when you think about signing transactions there's a lot of new on here like the beautiful thing about ethereum is that it's a smart contract blockchain which means you can do everything the disadvantage of being able to do everything is that these transactions can be incredibly complex and understanding what these transactions look like um can be a little daunting and at the end of the day people just like close their eyes and they just like approve you know you let's be honest with ourselves like if it's not transferring a token most people are not actually looking into this and the reason for that is because there's applications out there that we don't know about it so but we also don't want to scare people away and this kind of balancing convenience and security is kind of hard right that's kind of like the magic of building a great wallet where you have to allow people to explore every application that exists and at the same time make sure they're secure and I'm not saying that we haven't done a good job but we still have to continue to focus on doing less clicks is more and at the same time we actually have to give people security and I think this is where we go back to the definition of a wallet that I mentioned it's credentials signing and an accounts and all wallets today have external accounts so that's why we then have the concept of smart accounts technically speaking they're not called smart accounts uh neither are external accounts they're called externally owned accounts most commonly referred as EAS and then we have Smart contract accounts or scas but no honestly like when I have conversation with people we just call it external account and smart account like that's kind of like the easy way so most wallets today like 95 or 99% of the time are external accounts and we're in this process of making the experience experience better by turning them into smart accounts which means that they're going to be more programmable but it also means that like you now have to deploy a smart contract so if you have to deploy a smart contract you're no longer thinking of your wallet as just one key that is managed by your secret recovery phrase you actually have a smart contract and that is like the account that your wallet manages but if you don't have an a key you don't have a signature so how am I actually going want to sign like the whole purpose of this was to sign so what is actually controlling your smart account so there was a standard that was created which is how can we actually validate ownership over contracts because while with signing with theerum was very simple you signed this text message and now I can just verify that the signature matches your address but with a smart contract I don't really know how to validate it so ERC 1271 created like a very simple interface that says is valid signature it like you know sometimes people think like this code things are very complicated but this is literally the whole spec like it's like very long to read but then it's is valid signature is the whole code like and this basically takes a signature and throws a true or false so it basically it's a binary that says yes it is a valid signature so your smart contract is basically saying that this signature was done by someone was authorized to control my account so now we have to get a little on the nitty grid and actually break down what it means to have an account so the same way a wallet is credential signing an account an account then is defined by who is the signer who is the payer and what kind of cryptography is involved um in an external account it's pretty straightforward like you have the same signer you have the same payer and you have the cryptography which on ethereum is scsp 256 K1 and that's it like you don't have an option this is what an external account is on ethereum and this is what your external account is going to do with a smart account actually this is a little bit more flexible now we have a smart contract where we can encode logic that allows you to have more programmability this programmability can be many things but at the core of smart accounts it means that you can have multiple signers multiple signers does not necessarily mean that's a multisig the reason I try to not call it a multisig because there's a preconception about multisig being multi-party and that means oh you have multiple people signing for the smart account therefore this is like a business account no it's not a business account you would have a multiple signatures by using your account in a mobile phone and a desktop that in itself already provides you with like a good reason why you need a smart account because you don't want to move your keys around with different devices or you might even want to do something more complex where you have a secret recovery phrase that you own in a piece of paper for security and then you have like one in your device and one in the desktop and you use like two Factor authentication so this idea of programmability makes for more security and convenience at the same time so we really find the balance here with smart accounts another convenience feature is that we now detached ourselves from the signer always have to pay and what does that mean you know everyone understands here that blockchains have fees and these fees are called gas and in order for you to pay for that gas you have to be both the signature and the payer but what if you could actually have another account pay or maybe even you pay but with a different token with smart accounts you can actually program that information so smart accounts not only allows you to have flexibility of having multiple signers but then it also means that you can have a different payer than the signer and maybe even you don't pay someone else pays and finally the cryptography like the actual cryptographic curves can be infinite well infinite not so much because the more contract logic that you add into your smart contract the higher the gas cost but you get the picture it's way more flexible and if it's more flexible it means that we can actually get a little more creative like I don't know how much you know about cryptography but 256 K1 the curve of ethereum is actually not that popular that's how we like to reinvent the wheel kind of thing we kind of like to use things that nobody else uses but all of your phones actually use uh other crypto caric curves like for example one that's called p256 uh which most people now know today as the curve that's used for pass keys so what if you could actually use pass keys to control your smart account now we're getting really convenient because now I can have pass keys in different devices they all control the SM the same smart account and I don't even need to pay for the gas this is getting a little too good to be true uh but at the end of the day you could imagine that like you would have like multiple wallets and you would interact with multiple apps but they're all under the same blockchain but what if you could just have like one smart account everywhere it just kind of like covered everything that you would touch because you have multiple devices with like multiple signers and you share the gas you can use passies if you want it really would become this like truly Universal account which smart accounts really enable that experience and this is where the terminology account obstruction comes in like account abstraction in a way it's like a mindset it's a framework for you to think about how can we detach As Much from the limitations of the blockchain such that my account can be more programmable more convenient and still secure and this all started about two or 3 years ago with 4237 um which basically its title says account obstruction using alt mle which I don't think we really need to get into that but in the diagram what it means that before remember we had the triangle of the app wallet and blockchain uh things are starting to get more complicated now right because I told you now we have multiple signers so now the signer doesn't necessarily need to be in the wallet so it's its own component and you also are not a payer so now in account abstraction we introduced the concept of a pay master so the pay Master is now the payer the signer is the one who actually does the transaction and the wallet is you know the thing that you actually control so now we have two extra components uh we made the experience much better but we also made everything more complex and in the title you saw that it said account obstruction using an ALT men pool uh that essentially means that there's a pool of transactions that are ready to go into the blockchain and that's the reason called alternative is because it has to go through a bundler you can no longer send transactions directly to the blockchain anyway it this gets really complicated but I promise you that we're working really hard and bringing standardization and we're going to go through this journey of how smart sessions are going to fix that so the first thing you might think is like how do you actually detect uh if a wallet supports smart accounts because your application now has to consider that your wallet doesn't work like most wallets you don't have an EXT external account how do you actually provide that uh identification uh there's this concept of wallet call apis it's a new standard of how we actually going to start interfacing applications with wallets differently and it basically composes into four new methods um the most important of these methods I would say is this one the wallet send calls and this basically changes how we actually think about the wallet sending transactions uh we no longer think about telling the wallet send me an ethereum transaction I'm telling you I want to take these actions and here's a multiple actions and I want you to actually execute them and you as a wallet whether you're a smart account or not you should just be able to do so and this comes with this idea of the introduction of capabilities and this is how you discover if a wallet actually can support smart accounts so the wallet get capabilities actually allows you to detect that oh on this different chains this wallet has the capability of pay master or session Keys like you can add multiple features in there that allow your wallet to say to the application you can actually behave in a more convenient way for your user if you use these features so this is actually quite useful because now we notice that the triangle of the wallet blockchain and app broke down into multiple pieces and the application now has the ability to detect but one thing I did not tell you and I did not show you the spec of the 4337 is that despite the spec being a very very long and complicated spec is actually missing a lot of stuff like it's not telling you um how the wallet supports and which pay Master supports and what is the interface of pay masters and we basically kind of just decided you know the community will figure out one day and that was kind of okay at the beginning like if you go back to 2022 2023 people were building pay masters and sponsoring transactions for everyone but this was also an opportunity for fragmentation where everyone had their own pay master and everyone done something a little different so in 2024 we realized guys we need to stop this uh we need to all agree to do pay masters in the same way and we wrote the standard 7677 which created this part is not really that interesting um I just kind of wanted to give you a picture how a few lines of code can make a big difference of how we can make this world a little bit better by not having pay masters uh capture value of locking users into their pay master and can have all pay masters working the same way it was a very small thing but it made a big difference another thing that we didn't talk is about the actual smart contract design you know like I mentioned before ethereum allows you to do pretty much everything like so what would change because in external accounts every account work the same but with smart contracts that kind of gives a little bit too much flexibility And if every wallet Works slightly different then we're going to have to start having problems we standardize how account obstruction framework works we standardize how the paym works but what about your actual smart contract what can I do with your smart contract accounts so this is where 7579 came in and it provided a very minimal framework for how to create modules and in these modules you can essentially think that we can use the basic like smart contract codes that we all agree is the consensus of what a smart contract account is and then we can all install modules so you can think of these like almost as plugins for your account adding new functionality and becoming this more vibrant ecosystem where everyone adds new features these features could be uh for example recovery like you want to do recovery in interesting ways like where you include uh your family and friends or you can include a third party it could also be features like you know proving different credentials in your modules it could be some features around how you define policies of how you actually manage your account under certain conditions and for me personally the one that I got a little bit more curious about was hm if I can control how my account is used under some policies I'm essentially giving the ability for the smart contract account to manage itself because I say I don't want you to be able to spend this amount of tokens within this window of time and if I can do that I'm starting to think what if we actually had the app actually sign the actual operations on my behalf then if that's going to be the case then we're going to start thinking wait if the app signs on my behalf I no longer have to return to my wallet to approve every transaction and this would actually create the best picture because now I've told you at the beginning that we were able to create sign with etherum in a single click by removing the connect but now I'm telling you that the app itself would be able to sign on my behalf because I have a smart contract account and this is essentially what would be the end goal where you log in once and then you actually have the app do all of the work but it gets a little complicated because um as I told you like the app doesn't really have this concept of how to actually create the transactions for your smart contract account because you might have installed certain modules and those modules have to actually operate very differently uh so we're currently working and the reason it says XXX because it's is really work in progress uh this new API that actually allows you to delegate to the application to prepare the calls and actually generate the signatures independently so we come almost to the end where now we have Smart sessions so you now have a smart account you've been able to log in in a single click you have a pay master that subsidizes your gas and now the application using the previous standard or wallet prepar calls has the ability of signing signatures on your behalf uh because using this API they know exactly how to operate independently uh we basically reduce less clicks is more now the only thing we need to tell to this application is what can you do with this uh smart session and this is where the final standard comes in which is Grant permissions from wallets so the application is able to request permissions the user approves those permissions and those permissions can be encoded as we saw with the Google login as part of the sign with ethereum and then once you return that cont to the application the application can send it directly to the bundler so now we don't even need to have the wallet in the loop and the application is able to use the smart session to operate your uh wallet because you basically said you can only do this much for this amount of time with this amount of tokens and you basically created the rules for the bundler to understand that this app can sign on your behalf with a smart account but there's some concerns about you know if the app actually has control of a signer that controls your wallet uh it can cause some problems I don't know how much you guys know about web security but browsers are not very secure so this is where I also wanted to bring back the concept of pass keys because now your app can generate a pass key for your smart account and control it under the certain permissions that you give and this then looks like you know these pass keys and then your wallet essentially becomes a pass key for that specific app under certain permissions so the only thing that we need to do now is actually upgrade the evm because one thing that the evm has a problem is actually with Computing different crypto curves so if we add the actual curve for passys into the blockchain then we actually would have um even cheaper gas for everyone however this is actually something that's been in progress with some rollups but not necessarily for the so you might think that I'm from wallet connect if the app does everything for the wallet what is actually being connected realistically you've essentially logged in into your app and you've passed on the wallet inside your app it's almost like you have the concept of a mini wallet so we basically have almost like what we had in web 2 but now the authentication lives on the app under certain condition so you might be thinking are we done is this the end game we fixed everything um not really because one thing that I didn't explain is that this only works in the same blockchain and we currently have I forgot the number like 500 rollups or something like it gets really complicated so what if smart sessions could actually function across all chains so I'm going to bring some new lingo into the table and we're going to talk about chain abstraction I'm joking we're not going to talk about chain abstraction but this is the next game right we basically Bally have wallets moving to Smart accounts we now as part of wallet connect we have the ability to introduce smart sessions to make the user experience better and chain abstraction is the next game where bringing interruptable tokens magic spend uh 7702 and like Bridges and solvers and bundlers we can really have the chain abstraction uh improve the experience and then you might think what is the future of wallets like before you just had like apps and wallets through wall connect and now you have like sessions and signs in Pay Master most importantly we want to work on redefining what is the wallet experience for web 3 and making it as convenient and secure as possible but most importantly we want to make sure that less clicks is more and people have the time to really enjoy the benefits of these applications thank you thank you so much Pedro we already have a couple of questions here not sure if we'll be able to cover all of them but let's going to start with the most voted here Pedro is it already possible to use the same account abstraction account oh sorry across all your two if not when do you think it will be possible so it is possible to some extent but as you saw smart accounts are deployed contracts so you actually have to deploy the contract in every L2 that exists so if you have to deploy the smart contract in every L2 that exists that means that you have to manage multiple accounts and it gets really really inconvenient people are working on how you can manage account across multiple chains and I think chain abstraction is the next level I think of chain abstraction as almost like cross-chain smart accounts So eventually very soon another question here wouldn't giving a session to the DAP makes scammer DB's life so much easier well obviously that's a topic for discussion like smart sessions is about 9 months old uh we have done some experimentation how much permission should you have to give to the app that it's convenient for you but it's still makes you secure like The Current Designs currently focus on spending policies and that that has been most of the conversation but in my opinion it should not make it easier uh because you can actually have more control because of smart accounts give you programmability is smart sessions a smart account so smart if smart ches our smart contract is another topic of discussion if you go to the spec of 7715 there's two versions uh there's one that's called session key smart sessions and there's one that's called called session account smart session so there's a little bit of a difference of how people think about it um but yes I guess you could say the easy answer is yes and then one last question do you think of sessions as longlasting or short lived um look when you think about login uh login actually is on average people log in into a website and those sessions are 7 days but what web2 has successfully done is that they can renew those sessions so essentially at every seven days you have the ability to renew the smart session so we don't have this capability of automatically renewing smart sessions today but that's how we envision us kind of inheriting that design from web 2 where smart sessions would be one week old and then you would just renew it automatically without you having to log in every time ped thank you so much that was a great great presentation thank you so much everyone adding so many question

Automatic transcript — names and jargon may be misspelled.