Content
@
0 reply
0 recast
2 reactions
Dan Romero
@dwr.eth
Convince me I’m wrong: not a ton of incentive to be first to AA wallets given security risk / lack of Lindyness.
12 replies
1 recast
13 reactions
Matt Solomon
@msolomon.eth
What’s the security and lindy issues you have in mind? A private key is the worst security model, and allowing users to change implementations/fallback handlers lets you adapt to whatever becomes the standard
2 replies
0 recast
0 reaction
horsefacts
@horsefacts.eth
I participated in a c4 contest for one AA wallet and came away pretty spooked about the security surface area: it found deploy frontrunning, destroyable impls, gas refund exploits, several signature replays and bypasses. The core spec is simple, but there's a lot that can go wrong in the implementation and periphery.
1 reply
0 recast
4 reactions
Varun Srinivasan
@v
I think @dwr.eth's statement is true for larger projects. Don't know if contracts are audited well, bundlers work in practice etc. Better to let smaller projects try out, run into errors and improve before jumping onboard. The pareto optimial time to jump on new tech shifts based on your risk tolerance
1 reply
0 recast
2 reactions