A privacy-first, non-upgradable ERC-4337 smart wallet for mobile crypto payments. Tiered security based on transaction value, social recovery via guardians, gasless transactions via paymasters, and hardware-bound passkey (P256/WebAuthn) authentication.
Latest: v0.27.0 β mounts the DVT-repo authoritative BLS validator (0x539B9681β¦) at algId 0x01, replacing airaccount own AAStarBLSAlgorithm (0xAF525A). New validator stack (router 0x01βDVT, 0x08βsession). Existing accounts keep 0xAF525A (non-upgradable); new accounts use the DVT validator + gain its strictly-ascending-nodeIds quorum-fake fix. Inline single-op BLS (batch IAggregator is a future no-break upgrade). Factory (Sepolia): 0xf25621DF4c6100cdfe224054C2b09f2963bF487b. Forge test 900 (cancun + prague). On-chain E2E 31/31 (incl. DVT mount + golden-vector BLS validate()==0) + 4/4 real UserOp. Cross-repo: Seeder CC-10, SDK aastar-sdk#274 (nodeIds sorting).
Latest: v0.26.0 β fixes a HIGH tier-escalation: the ERC-7579 nonce-key validator-module route stamped the tier from the attacker-controlled sig[0], so a Tier-1 module key could claim sig[0]==0x0a and spend at Tier-3. Now capped to Tier-1 (rejects session 0x08, weighted 0x07, and any algId with tier > 1), plus a stale-weight guard in _populateExecAlg. Reuses the v0.25.0 validator stack (only impl + factory redeployed). Factory (Sepolia): 0x2039a9f81e961497237237c37aD5dBEf57C24F24. Forge test 900 (cancun + prague). On-chain E2E 30/30 (views) + 4/4 (real UserOp). Non-breaking. Codex-verified (2 rounds). EIP-170: impl 24,494 B (82 B headroom). Closes #171.
Latest: v0.25.0 β fixes a CRITICAL tier-escalation. A raw 65-byte owner ECDSA sig whose first byte
equalled 0x09/0x0a validated as Tier-1 ECDSA (M1 raw-65 fallthrough) but executed at Tier-2/3, so a
stolen owner ECDSA key could spend at Tier-3 via executeUserOpβexecuteBatch. Fixed at the root: the M1
raw-65 fallback is removed (plain ECDSA is now the explicit 66-byte [0x02][r][s][v]) and a single
_deriveStoredAlgId table drives both validation and execution. Reuses the v0.24.0 validator stack (only
impl + factory redeployed). Factory (Sepolia): 0x2979C772D8465418D3456960Cd15bB20b50E774e. Forge test
895 (cancun + prague). On-chain E2E 30/30 (views) + 4/4 (real UserOp via Pimlico: 0x02 included,
raw-65 rejected). BREAKING: raw 65-byte (unprefixed) ECDSA UserOp sigs no longer accepted (new accounts
only) β SDK companion aastar-sdk#273. EIP-170: impl 24,408 B (168 B headroom).
v0.24.0 β 2026-07-03: five-fix security-hardening batch (guardian front-run, weighted-config
escalation, self-call escalation, revert-free validateUserOp, storage-parity CI). Factory
0xD00bFa573B42C9cB046877032742e7961e986631. See CHANGELOG.md.
Latest: v0.23.0 β adds isValidOwnerAuth(bytes32 userOpHash, bytes calldata ownerAuth) (issue #159):
an ERC-1271-style view the DVT and any relayer eth_call to verify "did the owner authorize this userOp",
so owner authorization is never re-implemented off-chain (no drift). ownerAuth = [tag] || payload β tag
0x01 = ECDSA personal_sign(userOpHash), tag 0x02 = WebAuthn assertion over the owner passkey; success
magic 0xa0cf00cf, fail-closed. Unblocks device-passkey Tier-3 gasless DVT authorization. Hosted in
AirAccountExtension (main account had only 222 B EIP-170 headroom), reached via fallback.
Factory (Sepolia): 0xc5095E3B3b248007ef69E09F81F75612fBE629ce. Forge test 882 pass. On-chain E2E 4/4.
No factory/account API change vs v0.22.0.
v0.22.0 (2026-06-30) β Factory Passkey Bootstrap
v0.22.0 β passkey and validator wired atomically at account birth (issue #155).
createAccount now accepts ownerP256X/Y β the WebAuthn passkey is set at first initialize, not via
a separate post-deploy call. validatorRouter is baked into the impl as an immutable; every clone
auto-wires validator at birth β KMS accounts are immediately Tier-2/3 capable.
Security: KMS relay sig domain now covers _getConfigHash(config) (full config), preventing guardian-swap attacks.
Factory (Sepolia): 0x0eb0E7a61d5D9e03bc3578f8C1b0d9f40cc0a5B9. Forge test 865/865 (cancun + prague). E2E 21/21.
SDK breaking change (v0.22.0): createAccount(owner, salt, config, ownerP256X, ownerP256Y, nonce, deadline, ownerSig) (8 params).
Pass bytes32(0) for ownerP256X/Y to skip passkey; "0x" for ownerSig for direct mode.
v0.21.0 (2026-06-29) β WebAuthn-native cumulative algIds
v0.21.0 β adds ALG_CUMULATIVE_T2_WA (0x09) and ALG_CUMULATIVE_T3_WA (0x0a): WebAuthn P-256
owner sig can now participate in Tier-2/3 cumulative multi-sig flows. Factory: 0x3891c6543af966B11F772448228c7eC1906EF382. E2E 14/14.
v0.20.3 (2026-06-28) β gasless self-call for tier/weight config
v0.20.3 β gasless self-call for tier/weight config. setTierLimits, setWeightConfig,
modifyTierLimitsWithGuardians, modifyTierLimitsWithMixedGuardians now accept msg.sender == address(this).
Factory: 0x78775786dc6B1CD2f6631Ab59C2BE86B1a1e585e. Forge test 845/845.
v0.20.2 (2026-06-27) β P-256 mixed-sig module governance
v0.20.2 β P-256 / WebAuthn passkey guardian support for installModule / uninstallModule /
setModuleInstallTimelock / proposeModuleInstall. Factory: 0xe9ea2D29F2De1be80BEdb8A284ad4f98e6dAb6a1.
v0.20.0 (2026-06-20) β P-256/WebAuthn guardian support
v0.20.0 β P-256 / WebAuthn (passkey) guardian support. Closes #119: guardian slots
now accept passkeys (Touch ID / Face ID) alongside ECDSA EOAs, with full social recovery
(propose / approve / execute / cancel) via real WebAuthn assertions verified through the EIP-7212
precompile. Also relocates the cold recovery path into AirAccountExtension (frees V7 runtime from
11 B β 1,258 B under EIP-170) and merges the ECDSA + P-256 paths onto shared core helpers.
Hardened across a multi-round adversarial Codex challenge (P-256: 5 rounds; release-holistic:
R1 2M+2L β R2 1M+1L β R3 1L β final 1H+1M β SHIP) plus an independent clestons re-review (APPROVED).
Forge test 844/0/0 with --ffi (incl. 4 real-passkey E2E tests using OpenZeppelin
P256.verifySolidity β genuine secp256r1, no mock). See CHANGELOG.md,
RELEASE.md, and docs/p256-guardian-spec.md.
Integrator note (breaking): the 4 ECDSA recovery selectors (
proposeRecovery/approveRecovery/executeRecovery/cancelRecovery) are no longer on the V7 ABI surface β call them against the account address (selector + semantics unchanged; routed via fallbackβdelegatecall). Recovery event topic0 changed (newguardianIdxfield). TheREMOVE_GUARDIANsigning payload changed to bind(nonce, index, guardianAddr, p256X, p256Y). See the SDK migration issue.
Prior: v0.19.0-beta.2 β #42 Gnosis Safe community guardian + #67 KMS cross-version verification (no new Solidity logic).
| WS | PR | What |
|---|---|---|
| WS-A | #99 | Guardian-signed hash hardening β module-management nonce + version epoch in the signed domain (#75/#84). Defeats stale-signature replay across installs. |
| WS-B | #98 | ForceExit TOCTOU β re-verify approvers are still guardians at executeForceExit; loud _readGuardians (#70/#77). |
| WS-C | #101 | Session-key cap (50/account) + sliding-window velocity limiter (#83/#57). |
| WS-D | #102 | Optional module-install timelock β owner+2-guardian bypass, proposal bound to auth config, immutable executeAfter, cap + expiry (#58/KI-6). |
| WS-E | #107 | Gas optimizations (#82/#81/#80/#79) + factory EIP-3860 fix β implementation injected as ctor arg 1, factory initcode 49,134 β 13,324 bytes. |
| WS-F | #103/#108 | E2E completeness + v0.18 on-chain scaffolds (phases 13-16); strict revert-selector assertions; phase-16 validateUserOp msg.sender fix (#90). |
| WS-G | #100 | P256 low-S malleability guard (#78) + ERC-1271 EIP-712 NatSpec + constructor error tests (#76/#74). |
| WS-A2 | #105 | #45 CRITICAL β BLS algorithm recomputes the message point on-chain from userOpHash (RFC 9380 hash_to_curve); removes caller-supplied messagePoint/mpSig from every BLS payload. Single-op and batch-aggregator paths both bound to userOpHash. Aggregator is a single Safe-owned (Ownable2Step) protocol value; set-once validator. |
| CI | #106 | Dedicated bls-binding-prague job β runs the #45 crypto tests under EIP-2537 (Prague). |
β οΈ #45 Fix 2 (DVT node authorization) is out of scope for v0.18 and tracked forYetAnotherAA-Validator. Fix 1 (this release) stops replay of old BLS approvals; it does NOT stop a freshly forged unauthorized DVT approval. The BLS/DVT tier is only a fully sound security factor once Fix 2 ships. Seedocs/issue45-fix1-yaa-changes.md.
Combined v0.17.2-beta.1 + v0.17.2-beta.2:
- Session-key system unified β deleted
AgentSessionKeyValidator+AirAccountCompositeValidator+TierGuardHook(-7.8 KB combined bytecode). Single enhancedSessionKeyValidatorat validator router algId0x08supports both classic single-target sessions and richer agent-grade controls (velocity,callTargets[],selectorAllowlist[], P256 passkey variant). Backward-compat shims removed. - 8 rounds of Codex adversarial review + David human review on PR #61 + PR #68. All Critical / High / Medium findings fixed:
- BLS infinity-point bypass (per-UserOp + final aggregate checks)
- Aggregator unbound-to-userOps fix (recompute from
userOps[i].signature) - Weighted-sig token tier mismatch (pass resolved algId to
_checkTokenGuard) - 7702 delegate ERC20 inline check (raw
transfer/approveselectors) - ForceExit stale-guardian check (v0.17.2-beta.2)
- AgentRegistry factory-provenance whitelist (H-2)
bindFactorydeployer-only access control- 5-arg shim confused-deputy bypass closed
- ForceExit stale-guardian fix (v0.17.2-beta.2) β
approveForceExitrejects signatures from rotated-out guardians (SignerNoLongerGuardian). One contract redeployed; other 10 keep beta.1 addresses. - Phase 08-12 E2E verified (2026-06-11~12) β 45 new on-chain tests covering multi-account creation, execute variants, session keys, guardian recovery + modules, ERC-4337 UserOp via Pimlico bundler. Full suite: 79/79 PASS, 100% non-deferred ABI coverage.
- Sepolia deploy + Etherscan verify (11/11) + complete deploy runbook
35/36 product scenarios were executed as real transactions on Sepolia and independently challenged by Codex (only the DeFi Uniswap-parser scenario is deferred β Sepolia has no Uniswap; the practical per-asset ERC-20 case is covered). Every transaction is checked at 3 layers β receipt status (incl. negative reverts at status 0x0), on-chain state delta, and a Codex feature challenge β so a green receipt alone never counts as "done".
- ~60 real on-chain txs across all 7 signature algIds (ECDSA / P256 / DVT P256+BLS / weighted / combined-T1 / session), tiered verification, ERC-20 per-asset guard, batch, bundler UserOp, session grant/use/scope/velocity/revoke, 2-of-3 social recovery, ERC-7579 modules, ForceExit + TOCTOU, guardian-gated governance, plus the negative/revert cases that prove the guards actually block.
- β DVT combined-signature (cross-repo DVT-program anchor) verified on-chain via EIP-2537: C4 Tier2 P256+BLS Β· C5 Tier3 +Guardian.
- Codex challenge: REAL + FEATURE-MET per tx (RPC receipt + on-chain post-state + negative-revert verification) β every claimed product feature is backed by on-chain evidence.
Docs: E2E plan (36 scenarios, 3-layer verification) Β· E2E test data Β· E2E results + tx records + Codex verdict Β· Release checklist (mandatory E2E + Codex gate).
- CHANGELOG.md β release-by-release feature evolution
- docs/e2e/E2E_RESULTS_v0.18.0-beta.2.md β v0.18 full E2E tx records + business-value/feature mapping + Codex challenge verdict
- docs/deployment-v0.18.md β v0.18 Sepolia deploy record (addresses, wiring, decisions, E2E)
- docs/issue45-fix1-yaa-changes.md β #45 BLSβuserOpHash binding: new wire formats + SDK/DVT changes
- docs/abi/reference.md Β· docs/abi/selectors.md Β· docs/abi/capabilities.md β generated ABI reference (
pnpm gen:abi-docs) - docs/DEPLOYMENT-v0.17.2-beta.1.md β full Sepolia deploy runbook
- docs/DEPLOYMENT-v0.17.2-beta.2.md β beta.2 delta release (ForceExitModule only)
- docs/contracts-inventory-v0.17.2-beta.1.md β 11 contracts Γ 4 wirings Γ algorithm-ID matrix
- docs/security-review-v0.17.2-beta.1.md β Codex rounds 5-8 (pre-release gate)
- docs/abi-coverage-v0.17.2-beta.1.md β 80+ external functions: U (unit) / E (E2E) / deferred classification
- docs/e2e-results-v0.17.2-beta.3.md β Phase 08-12 on-chain result log (45 tests, all PASS)
- docs/tx-analysis-v0.17.2-beta.3.md β TX categories β AirAccount feature mapping + Codex TX verification
- docs/pimlico-bundler-compatibility.md β bundler split-simulation deep-dive (algId / prefund)
- docs/e2e-v0172-beta3-pitfalls-and-results.md β Phase 08-12 pitfalls and lessons learned
- docs/forceexit-design-notes.md β ForceExit subsystem design + accepted residual risks
- docs/known-issues.md β KI-1..KI-15 accepted limitations + auditor notes
- GitHub issue #67 v0.18 roadmap β what's planned next
β οΈ Integrators / SDK: the account is diamond-lite β the agent + weight-governance functions execute via fallback and are absent from the rawout/AAStarAirAccountV7.solABI. Use the mergedabi/AAStarAirAccountV7.full.json(runscripts/build-full-abi.mjs) to encode them. Seedocs/2026-05-26-diamond-lite-migration-impact.md.
β οΈ Not for mainnet yet: this is a beta tag. Mainnet requires paid security audit + bug bounty + KMS/SuperPaymaster/SDK production-ready. See DEPLOYMENT-v0.17.2-beta.1.md Β§1-3 for the full mainnet checklist.
| # | Capability | What you can do |
|---|---|---|
| 1 | WebAuthn / Passkey login | Fingerprint/face/PIN = account. No password/seed. P-256 verified onchain via EIP-7212 |
| 2 | Tiered multisig | Single WebAuthn (<$100) β dual-factor (<$1K) β multi-sig (>$1K). Onchain $-gated |
| 3 | Session Key + Agent | One SessionKeyValidator for both classic and agent modes: velocity / callTargets / selectorAllowlist / P256 passkey. Agent never holds owner rights |
| 4 | ERC-8004 Agent economy | Official Identity / Reputation / Validation registries + factory-provenance whitelist |
| 5 | Social Recovery (3-2-48h) | 3 guardians, 2-of-3 threshold, 48h timelock. cancelRecovery is 2-of-3 vote (NOT owner) |
| 6 | ForceExit emergency drain | L2βL1 bridge withdrawal (Optimism / Arbitrum). beta.2 stale-guardian hardened |
| 7 | EIP-7702 EOA upgrade | AirAccountDelegate makes an existing EOA an AirAccount via one type-4 tx |
| 8 | ERC-4337 v0.7 + ERC-7579 modular | Standard paymaster, modular validator/executor/hook. SuperPaymaster plug-and-play |
Bytecode-budget detail: see "Diamond-lite" note in the warning above. SDK consumers use the merged abi/AAStarAirAccountV7.full.json and see zero behavioural difference.
import { AirAccount, SuperPaymaster } from '@aastar/sdk';
// 1. Create account (WebAuthn β P-256 keys in TEE)
const account = await AirAccount.create({ provider: 'webauthn', chain: 'sepolia' });
// 2. Send gasless tx (pay gas in community xPNTs, not ETH)
const tx = await SuperPaymaster.sendGasless({
account, to: contractAddress, data: callData, paymentToken: 'xPNTs',
});
// 3. Grant a velocity-rate-limited session key to a dApp
await account.installModule({
type: 'session-key',
policy: {
duration: 3600,
callTargets: [dapp],
selectorAllowlist: ['0xa9059cbb'],
velocity: { window: 3600, max: parseEther('0.1') },
},
});
// 4. Set 3 social-recovery guardians
await account.setGuardians([guardianA, guardianB, guardianC]);
// 5. (Optional) Install ForceExit for L2βL1 emergency drain
await account.installModule({
type: 'force-exit',
destinationL1: ownerEOA,
amount: parseEther('0.5'),
});ABIs + Sepolia addresses sync to @aastar/core@0.18.x via the SDK feat/v0.18-contracts branch. Use pnpm, viem (project conventions).
Cos72 (v0.19 PoC target β MushroomDAO community OS)
β email register β community identity β gasless governance / tasks
SuperPaymaster v5.3.3-beta.2 (Sepolia testnet β gasless w/ community tokens)
β ERC-4337 standard paymaster
AirAccount v0.18 (this release) βββ you are here
β TEE-signed userOps
KMS v0.18.x (production β kms.aastar.io)
All four layers ERC-4337 v0.7 standard, plug-in compatible.
| Layer | State |
|---|---|
| KMS | β
Production (kms.aastar.io), TEE-attested |
| AirAccount (this release) | β Sepolia v0.18, full stack redeployed + wired |
| SuperPaymaster | β Sepolia Testnet Live (v5.3.3-beta.2, security-hardened beta) β mainnet pending external audit |
| AAStar SDK | β
v0.18 sync in flight (SDK feat/v0.18-contracts) |
| Cos72 | β³ v0.19 PoC target |
Announcement copy for socials (Twitter / Discord / Blog): see docs/announcements/ β three ready-to-publish formats.
forge build
forge test --summary # 799 tests (cancun)
# #45 BLSβuserOpHash binding tests need EIP-2537 (Prague):
forge test --evm-version prague --match-contract "HashToG2GoldenTest|BLSReplayBindingTest|AAStarBLSAggregatorTest" -vv # 22 tests
# v0.18 on-chain E2E (Sepolia) β phases 13-16 (WS-A/B/C/G)
pnpm tsx scripts/e2e-v0172/13-ws-a-module-nonce.ts # Phase 13: module-nonce replay defence
pnpm tsx scripts/e2e-v0172/14-ws-b-forceexit-toctou.ts # Phase 14: ForceExit approver TOCTOU
pnpm tsx scripts/e2e-v0172/15-ws-c-sessionkey-cap-velocity.ts # Phase 15: session-key cap + velocity
pnpm tsx scripts/e2e-v0172/16-ws-g-p256-low-s.ts # Phase 16: P256 low-S guardWhat AirAccount ships and what each contract does. Deploy column: singleton = deployed once per chain (shared); per-account = created on demand; per-factory = created by the Factory; external = not ours, referenced at a known address.
| Contract | Role | Deploy |
|---|---|---|
AAStarAirAccountV7 |
Non-upgradable ERC-4337 v0.7 account: algId signature routing, tiered verification, social recovery, ERC-7579 module surface, IERC721Receiver. Diamond-lite: routes agent (ERC-8004) + weight-governance selectors to AirAccountExtension via fallback+delegatecall |
per-factory (impl; users are clones) |
AAStarAirAccountBase |
Shared account logic inherited by V7 (signature validation, tiers, recovery, guard enforcement, fallback routing) | abstract (not deployed) |
AirAccountExtension |
Diamond-lite facet (v0.17.1): ERC-8004 agent (identity/reputation/wallet binding) + weighted-signature config governance. Reached via the account's fallback+delegatecall β runs in the account's storage context; split out to keep the account under EIP-170 |
singleton (per impl) |
AAStarAgentStorageLayout |
Shared storage prefix (slots 0β23) inherited by both AAStarAirAccountBase and AirAccountExtension so delegatecall slots align |
abstract (not deployed) |
AAStarAirAccountFactoryV7 |
CREATE2 / EIP-1167 clone factory; config-bound salt (front-run safe); createAccountWithDefaults / createAgentAccount. Agent accounts are authorized post-deploy via the unified SessionKeyValidator.grantSession() (router algId 0x08); the old setAgentSessionKeyValidator default-install machinery was removed in v0.17.2 (no separate agent-session validator) |
singleton |
AAStarGlobalGuard |
Immutable per-account spending guard: daily limits, ERC20 token limits, algorithm whitelist (monotonic tighten-only) | per-account |
AirAccountDelegate |
EIP-7702 path: turn an existing EOA into an AirAccount (guardian rescue, daily limit) | singleton |
| Contract | Role | Deploy |
|---|---|---|
AAStarValidator |
Algorithm router: algId β algorithm address | singleton |
AAStarBLSAlgorithm |
BLS aggregate signature verification (DVT co-sign) | singleton |
AAStarBLSAggregator |
ERC-4337 IAggregator for batched BLS UserOps | singleton |
SessionKeyValidator |
Unified session key validator (algId 0x08): classic single-target sessions + agent-grade controls (velocity, callTargets[], selectorAllowlist[], P256 passkey). Replaced AgentSessionKeyValidator in v0.17.2-beta.1. (AirAccountCompositeValidator was also deleted then, but weighted multisig 0x07 went inline to AAStarAirAccountBase._validateWeightedSignature β not into this validator) |
singleton |
Signature algorithms (algId): ECDSA 0x02, P256/WebAuthn 0x03, Cumulative T2 (P256+BLS) 0x04, Cumulative T3 (P256+BLS+Guardian) 0x05, Combined T1 (P256β§ECDSA) 0x06, Weighted multi-sig 0x07, Session Key 0x08, BLS triple 0x01.
| Contract | Role | Deploy |
|---|---|---|
ForceExitModule |
Guardian-gated L2βL1 force exit (OP Stack / Arbitrum); beta.2 stale-guardian hardened | singleton |
| Contract | Role | Deploy |
|---|---|---|
AgentRegistry |
Maps agent execution wallet β identity; SuperPaymaster setAgentRegistries target |
singleton |
| Contract | Role | Deploy |
|---|---|---|
CalldataParserRegistry |
Routes a target contract β its parser | singleton |
UniswapV3Parser / RailgunParser |
Decode swap/shield calldata so the guard sees real token/amount | singleton |
| Contract | Address | Notes |
|---|---|---|
| EntryPoint v0.7 | 0x0000000071727De22E5E9d8BAf0edAc6f37da032 |
canonical, all chains |
| ERC-8004 Identity / Reputation / Validation | see src/config/ERC8004Addresses.sol |
official "Trustless Agents" registries, deterministic CREATE2 |
Deployment order, wiring, and run commands: see
docs/DEPLOYMENT-v0.17.2-beta.1.md.
| Milestone | Status | Factory (Sepolia) | Tests |
|---|---|---|---|
| M1 β ECDSA | β | 0x26Af93f34d6e3c3f08208d1e95811CE7FAcD7E7f |
β |
| M2 β BLS Triple-Sig | β | 0x5Ba18c50E0375Fb84d6D521366069FE9140Afe04 |
β |
| M3 β Security Hardening | β | 0xce4231da69015273819b6aab78d840d62cf206c1 |
β |
| M4 β Cumulative Sigs + Social Recovery | β | 0x914db0a849f55e68a726c72fd02b7114b1176d88 |
β |
| M5 β ERC20 Guard + Guardian Accept | β | 0xd72a236d84be6c388a8bc7deb64afd54704ae385 |
298 |
| M6 β Session Key + Weighted MultiSig + EIP-7702 | β | 0x34282bef82e14af3cc61fecaa60eab91d3a82d46 |
446 |
| M7 β ERC-7579 + Agent Economy + WalletBeat + L2 ForceExit + Railgun | β | 0x9D0735E3096C02eC63356F21d6ef79586280289f |
622 |
| v0.17.2-beta.3 β Security hardening, diamond-lite, Phase 08-12 E2E | β | 0xfc6234bbd6283610659211347c6309904be86b0a |
723 |
| v0.17.2-beta.4 β Bundler-compat algId (executeUserOp + account whitelist) | β | 0x3a9127a5f0b4ca734d54629d0c3ad9f52739c071 |
731 |
| v0.18 β WS-A..G security/gas + #45 BLSβuserOpHash binding + EIP-3860 factory fix | β | 0xB14a870e4f63CA21a7EB753588CC4eBFb429E163 |
799 (+22 prague) |
WalletBeat evaluates wallets across Stage 0, 1, 2. AirAccount is a smart contract account layer β criteria marked π CLIENT are frontend/SDK responsibilities, not contract blockers.
| Stage | # | Criterion | Contract Status | Notes |
|---|---|---|---|---|
| 0 | β | Source code publicly visible | β PASS | GitHub: AAStarCommunity/airaccount-contract (GPL-3.0) |
| 1 | 1 | Security audit (last 12 months) | Internal AI audit; paid external audit (Code4rena) planned pre-mainnet | |
| 1 | 2 | Hardware wallet support (β₯3 makers) | π CLIENT | P256/WebAuthn at contract layer; Ledger/Trezor SDK is frontend work |
| 1 | 3 | Chain verification (L1 light client) | π CLIENT | Frontend RPC provider choice (Helios integration is client work) |
| 1 | 4 | Private transfers (by default) | Railgun calldata parser (M7.11) + OAPD address isolation; not shielded by default | |
| 1 | 5 | Account portability | β PASS | Social recovery (2-of-3 guardian), no platform lock-in, CREATE2 versioned migration |
| 1 | 6 | Own node support (custom RPC) | π CLIENT | Frontend/SDK responsibility |
| 1 | 7 | Free and open source (GPL-3.0) | β PASS | All contracts, tests, scripts open source |
| 1 | 8 | Address resolution (ENS) | π CLIENT | No ENS at contract layer; frontend handles human-readable names |
| 1 | 9 | Browser integration (EIP-1193) | π CLIENT | Provider API is frontend/SDK responsibility |
| 2 | 1 | Bug bounty program | β TODO | Framework designed (M7.7); no live Immunefi program yet |
| 2 | 2 | Address privacy | OAPD reduces cross-DApp correlation; tx amounts remain visible on-chain | |
| 2 | 3 | Multi-address correlation prevention | β PASS | OAPD: deterministic per-DApp accounts via CREATE2 salt β different addresses per app |
| 2 | 4 | Transaction inclusion (L2βL1 force-exit) | β PASS (M7.5) | ForceExitModule: guardian 2-of-3 gated OP Stack + Arbitrum withdrawal; E2E verified OP Sepolia |
| 2 | 5 | Chain configurability | π CLIENT | Multi-chain deployed (Sepolia, OP Sepolia); chain selection is frontend work |
| 2 | 6 | Funding transparency | β UNKNOWN | AAStarCommunity DAO governance in progress |
| 2 | 7 | Fee transparency | Gas costs verifiable on-chain; bundler/paymaster fees are off-chain | |
| 2 | 8 | Chain-specific address (ERC-7828) | β PASS (M7.4) | getChainQualifiedAddress() + getAddressWithChainId() in factory |
| 2 | 9 | Account abstraction (ERC-4337) | β EXCEEDS | Full ERC-4337 + ERC-7579 modules + 7+ signature algorithms (ECDSA/BLS/P256/Weighted/Session/Agent) |
| 2 | 10 | Transaction batching | β PASS | executeBatch() with per-call guard enforcement |
Current position: Stage 0 β achieved. Stage 1 blocked by: (a) paid external security audit, (b) private-by-default transfers. Stage 2 blocked by: (a) live bug bounty, (b) items above are mostly frontend scope. See docs/walletbeat-assessment.md for full analysis.
v0.20.0 is a full stack redeploy (11 contracts + 6 wiring txs) β the first on-chain deployment
carrying P-256 / WebAuthn guardian logic (#119). The account is non-upgradable, so P-256 support
requires a fresh implementation + factory; v0.18/v0.19 addresses do NOT have P-256. Full record
(all addresses, tx hashes, explorer links): docs/DEPLOYMENT-v0.20.0.md.
| Contract | Address |
|---|---|
| EntryPoint v0.7 | 0x0000000071727De22E5E9d8BAf0edAc6f37da032 (canonical) |
| Factory | 0x99C9300d52EDD9f4B7135DEd1811fBa6FFa1DDC6 |
| Implementation | 0xd51db7eB20FF99c8588281CBe1785681Bb17D473 |
| Extension | 0x5529f50811814E0a4966cFC21200DCeF9C3FCb5B |
| Validator Router | 0xfcDfd17a373E037c3F9C8ffE2c781915E7Ae6e11 |
| SessionKeyValidator | 0x6810CfB7c72D16e044a17694fAa8076e517264D0 |
| BLSAlgorithm | 0xAF525A161CB17e0A1b6254ef0B8d8473bdA05174 |
| BLSAggregator | 0x35775df9a4f4dB42Ea0C46118a12dDd0cEc70609 |
| ForceExitModule | 0x3fDe77868b74a7979A40a2293a1CD265fbe66EEc |
| Delegate | 0xd2735E54C5f5f2BF523b8a9ddd0E183624c3f2c0 |
| CalldataParserRegistry | 0x7dEea4544446826601014bD94d0F6432A67496F5 |
| AgentRegistry | 0xbcE1163817EEBA2E07d39424427B10937bF1D121 |
Deployer 0xEcAACb915f7D92e9916f449F7ad42BD0408733c9; blocks 11098656β11098665 (2026-06-20). Source
verification submitted to Sourcify (impl/extension/factory). Deploy: pnpm tsx scripts/deploy-v0.20.ts.
v0.18 is a full stack redeploy (10 contracts + 6 wiring txs). Because the account is non-upgradable, the
WS-A..G + #45 + EIP-3860 changes require a fresh factory + implementation; beta.4 addresses are superseded.
Full runbook, wiring, decisions, and E2E results: docs/deployment-v0.18.md.
| Contract | Address |
|---|---|
| EntryPoint v0.7 | 0x0000000071727De22E5E9d8BAf0edAc6f37da032 (canonical) |
| Factory | 0xB14a870e4f63CA21a7EB753588CC4eBFb429E163 |
| Implementation | 0x1Bc1119e3Ce4B6D158a6eadb31A06FdcE51992cF |
| Extension | 0xB1B3acd47DB89806F8431da3452769f1243b4d56 |
| BLSAlgorithm | 0x2869EEb04218ca666c6373c0DC5aCDa04F00adFA |
| BLSAggregator | 0x9AD55930B77C002dF884F4dac846D2077CDA7C8b |
| ValidatorRouter | 0xe785AF830aD33F3E550FfdC0fEB81D42507DA39D |
| SessionKeyValidator | 0x82f16163D0fb9c4dd7507b9999B79527a795291C |
| ForceExitModule | 0x0F6960526acf4cF9123e0aBc82d7a59fA0B6C934 |
| AirAccountDelegate (EIP-7702) | 0x70A8E31c425Ef3F23a2F9E05C48Bd998Aa29085b |
| AgentRegistry | 0x118eD73f22e41cb69282c78b216426D2d98A3935 |
| CalldataParserRegistry | 0x5dEE2c5279eFfC7c7FE711233bE42726EE0d4166 |
v0.18 factory ctor changed (#82 EIP-3860 fix):
AAStarAirAccountFactoryV7(implementation, entryPoint, community, validators[], algorithms[])β the implementation is now injected as ctor arg 1 instead of deployed inside the factory constructor (initcode 49,134 β 13,324 bytes). Deploy scripts + SDK must pass a pre-deployed implementation.setAggregatorandaddStakeare OFF on this testnet deploy (single-op BLS binding everywhere; batch path is Safe-only opt-in on mainnet).
ABI: use abi/AAStarAirAccountV7.full.json (includes diamond-lite AirAccountExtension selectors). Generated reference: docs/abi/reference.md Β· docs/abi/selectors.md Β· docs/abi/capabilities.md (regenerate with pnpm gen:abi-docs).
| Document | Description |
|---|---|
| docs/feature-list.md | Complete feature list M1βM7 β per-milestone tables with characteristics, user value, and active/passive classification |
| Document | Description |
|---|---|
| docs/airaccount-unified-architecture.md | Full system architecture β ERC-4337 flow, contract interactions, guard model |
| docs/architecture-7579-evolution.md | NEW β ERC-7579 module taxonomy, AirAccountβ7579 mapping, algId signal flow, evolution roadmap (Mermaid diagrams) |
| docs/product_and_architecture_design.md | Product vision, UX goals, tiered security model |
| docs/contract-registry.md | Contract inventory β sizes, interfaces, test coverage mapping |
| docs/M6-design.md | M6 technical design β weighted signatures, session keys, EIP-7702 delegate |
| docs/M6-decision.md | M6 scope decisions β what stays vs moves to M7 |
| Document | Description |
|---|---|
| docs/M6-status.md | M6 feature completion table, Sepolia E2E results, known issues |
| docs/M6-plan.md | M6 feature spec β session keys, weighted multi-sig, OAPD, EIP-7702 |
| docs/M7-plan.md | M7 roadmap β ERC-7579 modules, agent economy (x402, ERC-8004), WalletBeat Stage 1/2 integration, frontend SDK guides, audit pricing |
| docs/M7-TODO.md | NEW β M7 developer TODO: 26 items across contract/frontend layers, execution order, WalletBeat stage mapping |
| docs/M5-plan.md | M5 feature spec β ERC20 guard, guardian acceptance, zero-trust T1 |
| docs/M4-plan.md | M4 feature spec β cumulative signatures, tiered verification, social recovery |
| docs/audit-scope.md | C12 audit scope document for CodeHawks β in-scope contracts, interfaces, deployment scripts |
| docs/known-issues.md | Accepted risks and known limitations (EIP-7702 permanence, guardian self-dealing) |
| docs/multichain-deployment.md | Multi-chain deployment addresses β Base, Arbitrum, OP Stack |
| Document | Description |
|---|---|
| docs/airaccount-comprehensive-analysis.md | NEW β M1βM7 feature table, gas evolution charts, security industry comparison (vs Safe/ZeroDev/Coinbase/Argent), competitive analysis, gap analysis, multi-chain roadmap |
| docs/2026-03-20-audit-report.md | Security audit report 2026-03-20 β HIGH/MEDIUM findings + fixes |
| docs/M6-security-review.md | M6 internal security review β session key scoping, replay protection, guardian domain separation |
| docs/walletbeat-assessment.md | WalletBeat Stage 0/1/2 assessment β contract layer status, Stage 1 blockers (audit + private transfers), Stage 2 items |
| Document | Description |
|---|---|
| docs/acceptance-guide.md | E2E acceptance testing guide β Sepolia scripts, multi-chain deploy (OP Mainnet, Base), step-by-step commands |
| docs/m5-deployment-record.md | M5 Sepolia deployment record β tx hashes, gas costs, E2E verification |
| docs/contract-registry.md | All deployed addresses across M1βM6 milestones |
| Document | Description |
|---|---|
| docs/gas-analysis.md | Gas benchmarks by milestone β M1 through M6, comparison vs industry (Light Account, Kernel v3, Safe) |
| docs/gas-optimization-plan.md | Gas optimization strategies β storage packing, optimizer runs, EIP-170 compliance |
| Document | Description |
|---|---|
| docs/M4.5-weighted-signature-research.md | Weighted signature design research β threshold schemes, bitmap encoding |
| docs/eip-8130-upgrade-plan.md | EIP-8130 upgrade path analysis β non-upgradable migration strategy |
| docs/validator-upgrade-pq-analysis.md | Post-quantum validator analysis β CRYSTALS-Dilithium, EVM precompile timeline |
v0.18 is already deployed on Sepolia β see Deployed Contracts table above and the full runbook in
docs/deployment-v0.18.md. To deploy a fresh stack:
# Requires .env.sepolia with PRIVATE_KEY_ANNI, SEPOLIA_RPC_URL*, BLS_TEST_* node keys.
# TS+viem is the supported path β forge script fails on macOS (Socket operation on non-socket).
pnpm tsx scripts/deploy-v0.18.ts
# β deploys 10 contracts + 6 wiring txs; prints AIRACCOUNT_V018_* to append to .env.sepolia
# β factory ctor injects a pre-deployed implementation (arg 1) β #82 EIP-3860 fix# Requires .env.op-mainnet with DEPLOYER_ACCOUNT (cast wallet)
forge script script/DeployFactoryV7.s.sol --rpc-url $OP_MAINNET_RPC_URL \
--account optimism-deployer --broadcast --verify -vvvv0.18 added on-chain phases 13-16 (WS-A/B/C/G); the beta.3 phases 08-12 still apply for the execute / session / bundler surface.
# v0.18 phases (WS-A/B/C/G) β see docs/deployment-v0.18.md for per-test results
pnpm tsx scripts/e2e-v0172/13-ws-a-module-nonce.ts # 8 tests β module-nonce replay
pnpm tsx scripts/e2e-v0172/14-ws-b-forceexit-toctou.ts # 7 tests β ForceExit TOCTOU
pnpm tsx scripts/e2e-v0172/15-ws-c-sessionkey-cap-velocity.ts # 4 tests (+1 opt-in SKIP) β session cap/velocity
pnpm tsx scripts/e2e-v0172/16-ws-g-p256-low-s.ts # 6 tests β P256 low-S guard
# beta.3 phases (Phase 09 must run alone β Jason wallet nonce conflict with Phase 11)
pnpm tsx scripts/e2e-v0172/08-multi-account-types.ts # 8 tests β account variants
pnpm tsx scripts/e2e-v0172/09-execute-transactions.ts # 10 tests β execute (run standalone)
pnpm tsx scripts/e2e-v0172/10-session-key-txns.ts # 11 tests β session keys
pnpm tsx scripts/e2e-v0172/11-guardian-recovery-module.ts # 12 tests β guardian + module install/uninstall
pnpm tsx scripts/e2e-v0172/12-userop-bundler.ts # 4 tests β ERC-4337 UserOp via Pimlicoforge build # compile
forge test # 799 unit tests (cancun)
forge test --match-path test/SessionKeyValidator.t.sol -v # specific suite
forge test --summary # per-suite breakdown- No upgradability β no proxy patterns; new features require new contract + user migration
- Immutable guards β spending limits can only be tightened, never loosened
- Guardian-threshold recovery β 2-of-3 required; private key alone cannot bypass
- Session key revocation β nonce-based, prior grant signatures invalidated on revoke
- EIP-7212 P256 β hardware-bound passkey authentication, available on OP Mainnet (Fjord)
- Audit reports β see
docs/2026-03-*-audit-report.md
This project is licensed under the Apache License, Version 2.0.
Copyright 2024-present MushroomDAO Contributors.
See NOTICE Β· TRADEMARK.md Β· LICENSE-zh.md Β· TRADEMARK-zh.md for details.