MEVBoostAA Weekly [1]

【EN】

Progress of Last Week [2023.05.15 - 2023.05.21]

  • Modify MEVBoostPaymaster workflow

    • Modify to charge in PostOp, while only checking the Searcher balance in paymaster validation

      • Clearer workflow

      • Lower gas consumption: 20730 gas reduction

    • Analyze the attack vectors against MEVBoostPaymaster reputation in both new and old modes

      • From the perspective of Bundler, these attack vectors cannot resist attacks on the reputation of MEVBoostPaymaster, whether in new or old modes.

      • However, due to the fact that the userOp using MEVBoostPaymaster is directly linked by the searcher (the searcher will submit the bundle in some way) and does not go through the Bundler.

        • Searchers will construct the bundle themself and push it to the EntryPoint without relying on the Bundler system

        • Bundler's reputation system and constraints on the userOp validation phase will not affect MEVBoostPaymaster

        • Note: Relevant analysis articles will be published in the future

  • Searcher signature follows ERC-721 signature

    • More standard and better matching with the wallet implementation
  • MEVBoostAccount&MEVBoostPaymaster supports ERC165

    • Easy to filter the MEVBoostAA components
  • MEVBoostAccount inherits CallBackHandler

    • Support ERC-721 callback and so on
  • Adjust the code specifications to follow the style in the official documentation

Plan of this week [2023.05.22 - 2023.05.23]

  • Write an article analyzing the attack vectors against MEVBoostPaymaster reputation in both old and new modes, and explaining why MEVBoostPaymaster is secure.

  • Start to develop SDK for sender

【CN】

上周进展【2023.05.15 - 2023.05.21】

  • 修改 MEVBoostPaymaster 工作流

    • 修改为在 PostOp 扣款,而在 ValidationPaymaster 中只检查 Searcher 余额

      • 工作流更加清晰

      • 更低的 gas 消耗:降低 20730 gas

    • 分析了新旧模式下对 MEVBoostPaymaster 信誉的攻击向量

      • 在 Bundler 的视角看这些攻击向量,无论新旧模式都无法防住对 MEVBoostPaymaster 的信誉的攻击。

      • 然而,由于采用 MEVBoostPaymaster 的 userOp 是由 Searcher 负责直接上链的(Searcher 会以某种方式直接提交 bundle),并不会经过 Bundler。

        • Searcher 会自己构造 bundle 上链,无需依靠 Bundler 系统

        • Bundler 的信誉系统以及对 userOp validation 阶段的约束并不会影响 MEVBoostPaymaster

      • 注:后续会发表相关的分析文章

  • Searcher 签名遵循 ERC-721 签名

    • 更加规范,与钱包匹配更好
  • MEVBoostAccount & MEVBoostPaymaster 支持 ERC165

    • 方便识别 MEVBoostAA 相关组件
  • MEVBoostAccount 继承 CallBackHandler

    • 支持 ERC-721 回调
  • 调整代码规范,遵循官方文档中的 style

本周展望【2023.05.22 - 2023.05.23】

  • 撰写文章,分析了新旧模式下对 MEVBoostPaymaster 信誉的攻击向量,并说明 MEVBoostPaymaster 为什么是安全的。

  • MEVBoostAA 的 contract 初版定型

  • 基于 MEVBoostAA 的 contract 初版,开始开发 sender 端的 SDK

Subscribe to MEVBoostAA
Receive the latest updates directly to your inbox.
Mint this entry as an NFT to add it to your collection.
Verification
This entry has been permanently stored onchain and signed by its creator.