Account abstraction allows blockchain accounts to use programmable rules for authorizing actions and handling transactions. Depending on the implementation, a wallet can support multiple signers, spending limits, account recovery, batched actions or sponsored fees. These are capabilities that wallet software must implement, not automatic protections for every account.
Two Ethereum approaches
ERC-4337 uses UserOperations that bundlers include in transactions calling an EntryPoint contract. The account validates its authorization rules, and an optional paymaster can cover gas under its own conditions. Network fees still exist when someone else pays them.
EIP-7702, activated with Pectra in May 2025, lets an externally owned account authorize delegation to smart contract code while retaining its address. The delegation persists until changed or cleared; it does not expire automatically after one transaction. The original private key retains powerful control capabilities.
Convenience changes the security model
A wallet might combine a token approval and a swap into one transaction, or require additional signatures above a spending threshold. Recovery works only through mechanisms actually configured and supported.
Contract bugs, unsafe modules, upgrade permissions and compromised recovery participants can undermine these rules. Authorizing malicious delegated code can expose assets without revealing the private key. Account abstraction therefore changes how permissions are managed; it does not eliminate the need to understand what a wallet authorizes.