Crypto Wallets

How a wallet turns a seed into keys and addresses, and where that process goes wrong. The category covers BIP-32 and BIP-39 derivation, the secure elements and PIN stretching inside COLDCARD and Trezor, MetaMask's stored secrets, and an entropy defect that produced seeds far weaker than intended.

Alongside the hardware are the other places keys live: multisig setups on Gnosis Safe, custody services built on AWS Nitro Enclaves, and smart contract wallets under ERC-4337 and EIP-7702, with their nonce, deployment and delegation pitfalls. Several articles are threat models rather than walkthroughs, including one on designing for an attacker who has both the device and its owner.

15 posts

How Alchemy Implements Smart Wallets and Account Abstraction

How Alchemy Implements Smart Wallets and Account Abstraction

A walkthrough of Alchemy's ERC-4337 stack — Modular Account V2 and its semi-modular variants, validation selection through the UserOperation nonce, deferred actions, session-key permission modules, the Rundler bundler, and the hosted Wallet APIs.

Deep dive into MetaMask Secrets

Deep dive into MetaMask Secrets

This article focuses on the different secrets available on Metamask, one of the most used crypto wallets.