Working on @Walletbeat 🌸 Who watches the wallets?

Mainnet
Working on walletbeat, an L2Beat for Ethereum wallets. Inspired by @VitalikButerin in one of his blog posts. Who watches the wallets?
19
5
96
7,262
tl;dr really hard to move adoption forward when doing so requires coordination between different pieces of the stack. Yes, coordination problems exist within coordination technology. Doing our part @walletbeat 🫡
Replying to @shynxbt
for these features to work properly, both wallets and apps need to adopt these standards. this often goes just one way and users are confused why things aren' working: let's go in order: - clear signing is fairly new, approx 1-2 months. for this to work, protocols need to "describe" their transactions (clearsigning.org) and wallets need to support 7730. for example, Ambire supports clear signing when using Trezor but not Ledger (they basically want to charge us for clear signing to work kek). - connect any wallet to any app: most wallet support it nowadays but not all apps, we hear all the time "cannot connect your wallet to xyz app" - batching "approve & swap": wallets need to support 7702 (at this point only MetaMask and Ambire do it properly) and apps need to support 5792. the only hardware wallet that supports 7702 is @gridplus, no support from major hww yet and it's been over 1.5 years. hence approve&swap only works with hot accounts and Safe accounts. most major apps adopted 5792 today but some still do not eg Aave. - abstracted gas: this is basically solved, the only app that does not support this yet is Uniswap which still checks if account has sufficient native token which gates gas abstraction there are many (and more) chicken and egg problems in here. we need to do better at the coordination level.
2
9
375
polymutex 🌸 retweeted
yep. i always try to think about this as if ethereum were a person. do you respect a person more if they are squirming around to appease you or if they are sure in their own principles, without forcing them on you / proselytising?
Reminds me of the @post_polar_ interview we did with @walletbeat: "Crypto does not need any sanctioning from academia" We might be better off affirming our own values instead of constantly trying to please other elements of society After all, "crypto is a subculture that can't accept it's a subculture" kek
3
12
699
polymutex 🌸 retweeted
This might seem nerded out, but the ability to run a node at home from anywhere in the world is one of the things that gives your crypto physical properties. It means that you can *physically* verify for yourself that some random bits on a network in the cloud belong to you. More important than actually running a node, is the *option to* run a node. To quickly sink up with the chain tip from anywhere in the world with just a laptop. It doesn’t mean everyone will do it, but at least they can if they want to. Kind of like a fundamental right. A constitutional amendment. That’s what separates blockchains from databases at the end of the day.
Reminder: you can now sync an ethereum node within half a day and with aggressive settings the space it takes up on disk can be under half a terabyte. EIP-4444 and hard work by client teams on optimizing snap sync has improved things *a lot*. Glamsterdam will improve the sync situation further still (eg. Nimbus's new sync protocol uses it)
10
13
148
5,428
yes
Humble brag: Ambire is #1 on @walletbeat
1
1
19
655
polymutex 🌸 retweeted
The dystopic future we wanted: cyberpunk The dystopic future we get: corporates acting cutesie sarcastic ironic lowercase about pushing authoritarianism and total surveillance
when you launch an extremely popular age assurance update that everyone on Discord was really looking forward to and it has bugs
2
4
24
409
polymutex 🌸 retweeted
Wallets must support atomic batched transactions. Token approvals are meant to be batched with swaps, deposits etc. This keeps you safe and removes the need to revoke approvals. Atomic batched transactions make such batched transactions safer and easier to understand for the user, as well as enabling advanced DeFi use-cases.
2
6
33
821
polymutex 🌸 retweeted
Privacy is a human right. But how private is your address? NYMIS is a privacy scanner. It answers one question: “What does the blockchain know about me?” Enter your wallet address and it reveals privacy leaks across identity, KYC services, related addresses, funding history and more. Try it: nymis.io/ Built with @nansen_ai relationship and transaction intelligence.
31
12
87
8,561
polymutex 🌸 retweeted
Replying to @BattleJeff1
most are easy fixes, wallets and apps need to support: - connect any wallet to any app (eip-6963) - gas abstraction (just don't check if accs has sufficient native) - batching "approve & swap" (eip5792) - clear signing (eip7730)
1
4
13
288
polymutex 🌸 retweeted
With 360 Bitcoin wrench attacks cataloged, it's time to take the archive to the next level. Over the weekend I clanked out this interactive dashboard; feedback is welcome! jlopp.github.io/physical-bit…
76
118
774
107,656
Love this breakdown of adversaries on the L2BEAT privacy dashboard. Might need to borrow some inspiration here...
Replying to @l2beat
The five adversaries: 👁 Public observer - anyone reading the chain through a block explorer 🔍 Chain analyst - someone who scrapes all the data and uses clustering, timing, heuristics 🌐 Network observer - your RPC, relayer, ISP, the frontend 🔑 Privileged insider - protocol operators, governance, admin view keys ⏳ Future adversary - quantum computers, someone who has all historical data
1
6
35
1,554
polymutex 🌸 retweeted
Privacy should be a priority and should no longer an afterthought Interestingly, privacy is where wallets suck the most in @walletbeat We have yet to see a good wallet that's prioritizing privacy LOVE THIS ALL IN ENERGY FROM @VitalikButerin BTW
It's only dead if you give up I'm not giving up on privacy. I'm doubling down. firefly.social/post/x/210138…
1
2
20
622
polymutex 🌸 retweeted
Does your wallet support duress resistance to protect you from physical attacks? 🔧
1
4
13
527
polymutex 🌸 retweeted
Looks clean, but can we pls remove the separate approve txs now?
Aave V3 got a brand new look.
7
1
41
6,459
polymutex 🌸 retweeted
Corpslop and layers of abstraction that dissolve all personal responsibility are how evil hides.
Screenshots of the Philip Morris website. (reminder: they're a leading cigarette company) It's a good calibration point for how good modern marketing is at dressing up pretty much any corporate (or, for that matter, government) behavior and making it sound responsible and safe.
1
10
61
6,338
polymutex 🌸 retweeted
Security is about ensuring that your account remains yours. So how can wallets embody Security? A Walletbeat thread 🧵
1
7
21
803
polymutex 🌸 retweeted
$120k for a local-first @safe UI, oh yes!!!
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work. initiatives.thedao.fund/
20
6
188
27,452
polymutex 🌸 retweeted
A BIG HOWEVER: While testing it, I found out that @Uniswap has been silently approving unlimited tokens without letting users know about it This is a big red flag for a wallet to do
Your wallet might be silently approving unlimited tokens, and you might not know I tested 11 wallets’ in-wallet swaps to see what happens behind the UI, and whether they show it @phantom, @BitgetWallet, & @Uniswap Wallet unfortunately silently approve unlimited allowances 🧵
1
1
5
131
polymutex 🌸 retweeted
"Crypto is a self-legislating subculture. It doesn't need the sanctioning of academia." @post_polar_ on affirming Ethereum's own internal values instead of chasing outside approval. Filmed at @dappcon during @berblockweek.
2
4
17
511
"Fragmentation of the EVM and wallet UX across L1 and L2s is inevitable due to their conflicting needs" Insightful, but also kind of obvious in retrospect when considering that each blockchain tends to have its own set of to-go wallets, with only few supporting multiple at once.
I'm sad to report that the AA collab between 8130 and 8141 (Frames) broke down last week, and Base and Ethereum are now going separate ways to implement different AA standards. I want to share some reflections on this collab and on the future of the EVM. For a long time, the EVM has been a unifying force between L1 and L2s. Thanks to a standard account model (EOA) and a standard transaction type (EIP-1559), users have been able to enjoy their wallets working seamlessly across EVM chains. Similarly, a AA standard shared across L1 and L2s would ensure a consistent multi-chain UX for smart accounts, including post-quantum (PQ) accounts which we will eventually all use. As the crypto industry matures, however, L1 and L2s are starting to diverge in the values they provide and the use cases they target: - For the L1, it's all about CROPS -- censorship-and-capture resistance, open source, privacy, and security. In short, Ethereum L1 wants to be the most decentralized programmable settlement layer of the world, which is what makes it a good base layer for L2s in the first place. - For L2s, it's all about scaling, customization, and compliance -- things that commercial and enterprise use cases demand, and that the L1 does not provide. These diverging needs have pushed the shared layer -- the EVM -- to its limit, and AA proved to be the breaking point. While L1 and L2s both value core AA use cases such as gasless transactions and passkey wallets, they differ sharply in what these features must comply with: - For the L1, AA transactions must be uncensorable, private, and quantum-resistant, which call for a transaction type optimized for PQ signature aggregation and privacy protocols, and an account model that can be freely programmed and extended by developers without permissions from the chain. These needs lead to AA standards such as ERC-4337, EIP-7701, and now EIP-8141 aka Frame Transactions. - For L2s, AA transactions must work at high scale, and they must be legible such that the protocol can enforce clear rules about what kinds of accounts/transactions are permitted vs not. These needs lead to AA standards such as Tempo Transactions and now EIP-8130 by Base. With the AA collab, the authors of 8130 and 8141 tried to define a shared standard that can work for both L1 and L2s. While we identified a number of technical solutions, they all required one side or the other to compromise at least a little bit on their core goals. But ultimately, Ethereum wanted to be the best version of Ethereum, and Base wanted to be the best version of Base, and while both sides acknowledged the benefits of ecosystem interoperability, it was ultimately secondary to the need for each chain to achieve their core goals. So separate ways we went, putting the burden on wallets to deal with the fragmentation that ensues. Now, just because we ended up with fragmentation doesn't necessarily mean it was a bad outcome. If reducing fragmentation comes at the cost of homogenizing chains to the point that they fail to solve problems for the users they care about, that would not be a price worth paying. While I was initially sad that the collab did not come to a successful conclusion, I took solace in the fact that both Ethereum and Base are now free to innovate on AA to the maximal extent in accordance with their own visions, unshackled from the need to accommodate the other side. If they execute well, and if the wallet community can bridge over the fragmentation, we may well end up with the best possible UX for the end users. So where does that leave us -- the broader Ethereum community including Ethlabs -- if we want to continue pushing for a consistent UX across EVM chains? I see two paths forward: - We can establish a coordination mechanism that encompasses more stakeholders than ACD itself (where only L1 client devs have voting powers), to govern shared L1<>L2 resources such as the EVM. That way, L2s can participate in shaping the EVM, as opposed to having to accept whatever the ACD decides, or being forced to fork if they don't like the decision (such as in this case with Base). - We can accept that fragmentation of the EVM and wallet UX across L1 and L2s is inevitable due to their conflicting needs, and dedicate our resources to building wallets and applications that can abstract over the differences. Indeed, the collab was an exercise in the first path -- we invited Base, Arbitrum, and other stakeholders to directly influence how native AA shapes up for the L1. While it ultimately failed in this case, I feel a better outcome could've been achieved if we had established a dialog between both sides way earlier, as opposed to well after L1 core devs had rallied around Frames. On the other hand, I also learned from this exercise that some differences are unavoidable, and indeed it would be counterproductive to overly pursue interoperability at the cost of differentiation. In other words, we sometimes just gotta let the chains cook. For that reason, I've also become more bullish about the second path -- building wallets and applications that can speak the native transaction types of each chain, and hide the complexity from users through UX abstractions. This puts a lot of onus on the wallet/application developers of course, but on the bright side, it's also an opportunity for wallets/applications to stand out and differentiate, by competing to provide great UX across chains despite the underlying fragmentation. Ethereum is the art of staying together while remaining different. We must accept that chains will succeed by innovating, and innovations will naturally result in differences. On the other hand, we must never give up on dialogue when we can achieve interoperability without compromising core product goals. As Ethereum and crypto grow to eat the world, the push and pull between innovation and collaboration will only intensify, and it's up to all of us -- builders across L1 and L2s, applications and wallets -- to determine whether diverse innovations will split Ethereum apart, or make it thrive as one.
7
292
polymutex 🌸 retweeted
At Walletbeat, we use a framework to evaluate wallets across five dimensions: Security, Privacy, Transparency, Ecosystem Alignment, and Self-sovereignty. The same exact values that CROPS stands for. Now, let's take a look at how these attributes are rated, based on different wallets 🧵
1
3
10
353