# Elod Varga - Revolutionizing Web3 UX with Smart Accounts

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2025-11-09
- Duration: 23:28
- Watch: https://streameth.org/watch/yt-akEuBCIgDI0
- YouTube: https://www.youtube.com/watch?v=akEuBCIgDI0

## Description

Web3 user experience is utterly broken. Learn how Sophon is addressing this challenge with modular smart accounts. This session will cover frictionless onboarding, enhanced security, and the future of decentralized applications.

## Transcript

Hello. Hello. So, uh, first things first, um, I'm part of the Son team. Uh, hands up, who knows what Son is, at least in the crypto space, not the threebody problem Son. All right. So, let me let me just tell you, Son is a ZK stack layer 2 that is fully entertainment focused. And yes, we are trying to gap uh the the broken UX and really get crypto to consumers. Now, for today, I'm going to talk about modular smart accounts because in my belief at least, this is basically the bottleneck about like why crypto is not really usable by my grandma, by my family, by everybody that is actually going to benefit from it. um walk through capabilities about uh like sof account and how we implement smart accounts and then demos and and a little bit of Q&amp;A. Um so the problem that we have here right um there is a lot of friction wallet setups are bad seed phrases are simply something that is too complex for real users to adopt and really to manage gas paying for transactions is usually not something that somebody can actually do when they are onboarded to a chain and yeah this is causing all sorts of user dropouts most in most cases is I've been a pretty avid fan of trying out different layer ones and layer twos just because of the sake of seeing a lot of good tech and a lot of purpose-built tech. Um 99% of the cases the first use is the last use that I do and that that's pretty pretty normal for for anything that that touches new technology right now. The real world impact of this is that yeah, wallets are abandoned. There are low retention rates. You can you can click and scan through a lot of scanners, a lot of explorers. There are millions and millions of wallets, especially smart wallets that are using smart accounts at the back that have either some sort of like dust left behind them, couple of dollars, um that actually account up to a pretty pretty big sum because users just forget them there. It's it's there. It's lost probably forever, but it's there. And then smart accounts aim to fix this. Um then of course uh for the building blocks, um the main real utility of this is that from the point of we want to go to we want to go from from clicking and really approving all sorts of transactions, you want to go to a walletless user experience, right? using biometric login, temporary sessions, pass keys, using your face ID, using everything that uh that the web two world and the used like social login whatever that we have just people getting used to it, right? And you have a smooth onboarding for it. Then of course you have the DRC 7579 standard for modular smart accounts that define onchain structure, different sorts of flavors of of limits, enhanced security, so on and so forth. And then of course uh EIP6963 compliant and also 1119 compliance meaning that all of these smart accounts that I'm going to talk about are super easily discoverable and used in your own wallet kit like ROM X wallet connect Rainbow Kit Connect kit so on and so forth. Now how is this done? Um here what you can see is basically the three building blocks of uh smart modular smart account modules. You have the validator module that is encompassing everything that is basically managing signers. Then you have the transactional modules that uh handle all sorts of flavors that you can use as a dab developer to ease your users on boarding. And then you have recovery modules. Basically, the ones that that are going to help you out and your users help out uh to not lose access to their smart accounts. Right? Let me quickly go back here because I feel like these slides are a bit outdated. So, uh let me improvise a bit and and think about how should we how should we solve that. Um now when it comes to to validator modules um these are the ones that that you need to use uh when you implement uh smart accounts to actually enable login with Google, login with Apple, login with all the other um real use cases that basically your our fathers and grandparents are used to. um you're going to Facebook, login with email. You're you're going to to some other application, login with with Google. Now, for for accounts, um I'm not entirely sure how many of you are really using that. It's uh it's going to be a step forward. Um now, it's getting implemented in a lot of in a lot of places, but it's still not it right. We are looking into into making that a standard and not rely on storing your seed phrases, splitting them into trees so that so that it's not really like uh discoverable by somebody that is like physically there where your where your uh seed phrases are. Uh exporting and importing uh private keys that is basically like 99% the cause of the 99% of the exploits. Um and then of course the the probably the most important thing is that uh when it comes to validator modules for modular smart accounts you can deploy a smart account with your EOA signer. Meaning that you have a MetaMask wallet, you have a Rabbi wallet, you can do basically create a smart account with it and that smart account is able to do anything that that MetaMask account is able to do without any problems. And of course with all these things now on the transactional module um this is this is probably my favorite utility that uh smart accounts bring. Um it's super super important to consider frictionless user experience especially when it comes to long tenuring um user experiences. take into consideration games for example. A very very very good case study at least for the beginning beginning of this is uh hyperlquid. Uh does anybody know how hyperlquid actually implements um serless trading here? Um let me tell you that they actually developed their own purpose-built layer one for that. So what does that mean is that when you're going on hyperlquid you're signing a message meaning that you are providing access to all your funds and all your actions to the connected account to the hyperlquid layer one and it is able to use that access for their trading engine to do trades on your behalf. It's not your wallet that is actually doing those trades at the back of it. your wallet is practically just providing a permit to their trading engine to do that on your behalf. Now, the biggest problem and why I'm saying is that that this is the the the first very good pilot is that they are positioning themselves in between a centralized exchange and a decentralized exchange, providing the user experience of a of a centralized exchange while still keeping things somewhat on on the blockchain. Now the big caveat here is that you're providing basically full access to whatever you have when you're connecting there or when you're bridging there. And I think that's unwarranted. I'm personally not using it because I'm not okay with providing full access to my account anywhere I go. So that's where session keys are super super helpful. Um when when you're using modular smart accounts, you have a bunch of utilities and a bunch of very granular access rights that you can provide to to users when you are actually creating a session key for them. Meaning that you can specify how much gas that session key can use for that user. Um this is very very useful for example if you're trading on a high frequency uh platform and you know that for example that might generate trades on your behalf on gas spikes. So this could practically drain your your account for yeah your your native token your ET or whatever. Now, if you're specifying a specific upper limit, then you're somewhat defending against it because you're setting the maximum amount that that you feel okay to be to be s to be sold. Uh so that your profits are still fine. And it's like the moment that that uh that amount is used, you're basically done. The session key cannot do anything anymore. Therefore, the automated account is not doing anything afterwards. Uh the session key is consumed and that's it. Besides that, the other very important factor is that you can specify who has uh execution right to use the session key, what wallet address and besides that what smart contract can it call and what specific function and with what parameters. So I like to to explain and to talk about examples because people can relate a bit more uh to them. Let's say that um you're staking on Lido for example and obviously you want your maximum returns and for that obviously they have autoco compounding built into the protocol but what if they they wouldn't have so with a session key without writing any sort of specific logic inside you could actually trigger on your application uh the the access right for an underlying account to trigger only the uh claiming of your fees and your rewards and the autoco compounding feature on the smart account. So that would mean that this session key that that you actually approve when you go to Lido with your smart account can do only these two things and it's automated from there LIDO takes over and it's super cool super right that's that's the only thing that they can do and this way basically LIDO's only thing that they need to do is handle the backend flow of calling these two uh these two functions no need for for specific smart account logic no need for for like very complicated and very secure implementation and all of this is done by simply yeah just doing like providing good design on smart accounts. Now under recovery modules I think this is what this is where the game is really going to change when it comes to to account management. Um, we have two modules that are going to be basically super super useful. The social recovery module is enabling you to register a social login or a pass key to trigger a recovery flow where uh another email or Google account or whatever can actually become the new signer of your account. This is super useful if for example you have your pass key that went into that that you created on a MacBook that just got got spilled, right? You spilled some coffee on it. It's it's unreoverable. So from that moment on, basically your smart account would be gone if you wouldn't have a recovery module or some other signer associated with it. Now with the social recovery module, anybody could just trigger this this recovery and that's it. on the guardian blocker module. Um, this is this is probably uh when it comes to when it comes to sofon our most beloved module itself because we we've been using it for proof of concepts for a lot. Um, when it comes to to uh unrecognized access and exploitation patterns, we have a lot like there are a lot of protocols that can pretty much flag from the get-go if there is a suspicious access to your to your account, right? But what do you do about it? Practically, if it's if it's automated, you as an end user for for your like mundane wallet, you just can't do anything about it because they're they are always going to front you. That's it. like you lost access, somebody got access to it. That's it. That's end of the game there. But with guardian blocker modules, smart accounts are actually bulletproof for this because you can give an EOA uh a specific right to actually close up the recovery, close up the smart account and basically transfer all the funds to a trusted wallet address. So whenever there is for example a a protocol that is monitoring your smart account for for unwanted access you can just trigger a blocker module send all your funds out and that way the hacker is not getting anything. So it's it's super super cool. I feel like smart accounts are going to change a lot about how we are going to to develop decentralized applications or dabs before. Um right now the biggest blocker as I see is the mo the the the friction of how we interact with with blockchain is caused by the the wallets are unwilling to to create the interface that are uh that is useful for for users to actually like encompass all this uh complexity inside. Decentralized applications shouldn't build and and really implement all of this themselves. It should be one modular implementation that can be plug and played into any EVM uh chain because this is specifically EVM from the get-go and then devs can really use it from from the start. I have a little video here. Um, so this is this is an example of little Billy uh our mascot at Sofon providing you a uh uh a cell phone account experience to connect with social accounts and and with EOA wallets. This is from from Sof Home. Uh quite different than than what you're you're expecting with MetaMask, right? And then the the the thing is that the work doesn't stop here. uh accounts themselves are just one of the building blocks for user experience. Uh we at Son are basically providing the whole toolkit for decentralized applications and users to have the best experience possible on chain from home being the main hub of finding out what's happening and actually interacting with the blockchain to account being the gateway to it and then sen plus being the the API and the incentivization mechanism to actually retain users. All right. And I think uh that's pretty much it because I'm running out of time. Um these are the accounts uh the the account urls and the contract uh repos that that basically hold the magic. Please check them out. And that was it for me. I'm really uh hoping to see you soon on Sofon. &gt;&gt; Thank you so much a lot. And smoother UI makes it easy for us all, right? &gt;&gt; Yes. &gt;&gt; Yeah, of course. &gt;&gt; Well, the thing is, yeah, I have my own Google Drive, so everything is connected through all my devices. So, I know like if I my computer goes away, I it's still going to be alive. So, do you have any questions today from the audience or we can still scan a QR code and go in and ask a question? You made it too easy for people. &gt;&gt; It's supposed to be a beginner type, right? &gt;&gt; Oh, I see. So um the goal here was to to actually define the paradigm and then make sure that everybody follows it. &gt;&gt; So I was a little bit interested about the thing that you said if somebody broke a computer that would be able to to grab out the everything through it even though the computer was not there. What if they don't have anything else connected into it like everybody has today the Google wallet and everything? How would they actually go in and get grab it if only the computer has to access and no no permissions are given? &gt;&gt; So basically you mean that somebody set up no recovery has no access to any sort of like cider or pass key that they had to their smart account and on top of that they didn't actually save any sort of information from their laptop &gt;&gt; like my grandfather. Ooh well well well well um for that of course there are some centralized solutions that we don't like to talk about obviously solution there is a solution because actually all smart accounts are deployed by a factory &gt;&gt; right that actually can do a well admin level access but not to funds only to the recovery module &gt;&gt; well that's still nice because today if you lose the seed phrase you lose your whole wallet That's it. One time. So, we just had a question come in. Can you sign a transaction to send tokens with Google accounts by using Soon? &gt;&gt; Yes, of course you can. So if you're actually deploying a smart account for yourself that can have a Google account, a an Apple account uh X uh basically anything telegram included all social social accounts are included there as a signer because at the end of it what's happening there um it's it's just OOT right um there is there is a a private key generated at the back of O and that O that private key is signing the transaction itself. Now the the the magic that we we just need to do is propagate that signature to the smart account itself. So this is not new technology. It's been around for years and years, right? The the novelty here is that while crypto is pretty new and everybody is kind of like accustomed to to have all this technical depth and complexity, uh users don't really like it and retention rates show this. &gt;&gt; I'm sorry they don't like it. It actually sounds like fun. Just like signing off your will. No. So, do we have any more questions from the audience today? &gt;&gt; What what's your main target for the for Son? &gt;&gt; Yeah. So, Son itself as I said is entertainment focused meaning that we by providing the best user experience we are targeting first any DAP and any developer any builder that is coming from entertainment. let it be gaming to for example we have a very interesting pilot uh that is for example onchain selling onchain tickets now that is a super super cool use case and it's been there since like I don't know probably the first idea came in 2015 nobody actually implemented it in a way that the industry approved now we're seeing the first signs and why because there are tools and people actually got to the point where now we are getting there that like it's kind of okay the industry accepts it and obviously all the standards like NFTs and so on and so forth are very very good for that specific use case. So yeah we are targeting for like basically anything that can use the uh user experience bonus that that provides. Uh, I got a some Well, here's my question. Uh, like a with the EIP 7702 where you're connecting a smart uh contract to a a smart account, I mean to a uh some a contract. &gt;&gt; Yeah. &gt;&gt; Where you're connecting an EOA to a smart contract. That's one way of getting uh some functionality into the EOA the address and then the other way is like the 4337 one which I'm a little more hazy about what how that works. Yeah. So how do you use those two different technologies or protocols or whatever you want to call it to in your product or or how do you see the different use cases for those? &gt;&gt; Yeah. So the thing is that like the name of the game here is granularity. Right? Now when it comes to like your specific use case, you always need to to take a look at like what is your target audience? Is your target audience really like sub susceptible to do financial transactions? Is the volume really or the like amount of funds that that you care about the granularity of access? Right now all these standards are very well defining what that those specific upgrades to the to those smart contract based accounts can do. Uh our goal and and our like job really is to use the best standard based on what the user base is. If the user base cares only about like I want to play a game, right, and I don't want to be interrupted by pop-ups, um then obviously like a simple simple smart account uh uh se 773039 based like uh type uh type signature based validation smart account is perfectly fine. Like you don't need very specific rules of what that smart account can do or what that smart account cannot do by session keys or some other stuff. Now, of course, if it's if it's an institutional trader that needs to to set very specific rules of what, for example, an employee can do from the like actual investment portfolio of that institution. Now, that's another type of game, right? So, yeah, at the end of the day, everything comes back to knowing your user. &gt;&gt; Well, thank you so much, El. And our time is running out and thank you for all the questions. If you have more questions for El, please catch him outside. But for now, give a good hand for him and thank you.
