Skip to content

Open nowPosted 3 days ago

Staff Software Engineer Smart Wallet & Account Abstraction

Xsolla179 open roles

Where
Russia
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Software Engineer Smart Wallet & Account AbstractionXsolla · Russia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Xsolla's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Xsolla postings stay open a median of 28 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

Xsolla median: 28 days open

The posting

About Xsolla

Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators. Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.

For more information, visit xsolla.com.

About the Role

We're looking for a Staff Engineer to own the smart wallet and account abstraction layer of Xsolla's Web3 platform. This is an individual contributor role with outsized technical scope: you'll be the technical anchor for how millions of players get an on-chain account they never have to think about — setting direction, making hard architectural calls, and raising the bar across the org.

Concretely, you'll own the account model behind Xsolla ZK, our zkSync-based L2, and the wallet that sits inside Xsolla App. Every player who signs in with Xsolla ID receives a deterministic, non-custodial smart account — derived from their identity claim, identical on every device, with private keys that never leave the client. That account is not a separate "wallet" screen: it is the player's inventory, and it backs minting, gifting, trading on our Bazaar marketplace, Merkle-based reward airdrops, gas sponsorship, and an in-app dApp browser that exposes the same signer to third-party applications through an EIP-1193 provider. You'll own the primitives underneath all of it: the ERC-4337 user operation lifecycle, EIP-7702 delegation, session keys and origin-bound Smart Sessions, paymaster and gas abstraction strategy, and the custody and recovery roadmap — including the move from raw key export to MPC custody.

You will own the strategy behind account abstraction, signing, and session management at scale, and evolve our smart account and permissioning model to meet both product and compliance needs. You operate with significant autonomy, but your decisions ripple across teams — so you'll spend real time building buy-in with engineering, product, security, and legal stakeholders, not just designing in isolation.

You are technically deep, calm under pressure, and comfortable being the escalation point when production wallet issues get hard — because in this domain, "hard" means a stuck user operation, a drained paymaster, or a signing prompt a player didn't understand. You write the RFCs and design docs that people actually read, and you create leverage for the broader engineering org through documentation, tooling, and mentorship — without needing a management title to do it.

Responsibilities

  • Own Smart Wallet & AA Architecture — Own the technical strategy and architecture of our smart wallet platform, covering the account model, signing, session management, and gas abstraction at scale.
  • Design the Account & Signing Model — Design and evolve our ERC-4337 user operation lifecycle (prepare → sign → submit → confirm), EIP-7702 delegation, deterministic address derivation from identity, and the session-key and permission primitives that let players act without a prompt on every transaction.
  • Own Gas Abstraction — Set the paymaster and gas-sponsorship strategy: what we sponsor, how we meter and cap it, how we defend it from abuse, and how it degrades when sponsorship is unavailable.
  • Harden the dApp-Facing Surface — Own the security model where our signer meets third-party applications: EIP-1193 / EIP-6963 provider behavior, origin-bound and policy-versioned sessions, trust tiers, and the transaction and signature confirmation flow. Define what a player is actually approving, and make sure the UI can prove it.
  • Drive Custody & Recovery — Lead the custody roadmap from today's interim mechanisms toward MPC-based custody, and design recovery paths (passkeys, guardians, social recovery) that a non-crypto-native player can complete without losing assets.
  • Drive Cross-Team Technical Decisions — Drive decisions on account architecture, SDK contracts, data modeling, and platform reliability, and build buy-in across the wallet, marketplace, SDK, mobile, and security teams.
  • De-Risk Proactively — Identify systemic risks — key management, signature phishing, reorgs and indexer staleness, bundler and RPC dependencies, contract upgrade paths — and lead initiatives to resolve them before they become incidents.
  • Set Engineering Standards — Define engineering standards, review critical code, contracts, and designs, and create leverage for the team through documentation, tooling, and mentorship.
  • Align with Stakeholders — Collaborate with product, security, legal, and infra teams to align on roadmap and translate business and regulatory needs into well-scoped technical plans.
  • Own Production Escalations — Serve as the go-to escalation point for complex production issues in the wallet and account abstraction domain.
  • ERC-4337 Depth — Deep, hands-on understanding of ERC-4337: EntryPoint (v0.6 through v0.8), the UserOperation lifecycle, bundler and paymaster roles, validation rules (ERC-7562), gas estimation and its failure modes, counterfactual deployment, and signature validation for undeployed accounts (ERC-6492).
  • EIP-7702 & the Post-Pectra Landscape — Working knowledge of EOA delegation, its interaction with ERC-4337 EntryPoint v0.8, and the trade-offs and risks it introduces (residual key authority, delegation phishing, storage collisions).
  • Smart Account Implementations — Experience building on or extending production smart account implementations (Safe, Kernel, Biconomy, Coinbase Smart Wallet, or equivalent), and familiarity with modular account standards (ERC-7579 / ERC-6900).
  • Session Keys & Delegated Permissions — Experience designing scoped, time-limited, policy-bound authority: session keys with TTL and contract allowlists, origin binding, permission revocation, and delegated-permission standards (ERC-7710 / ERC-7715).
  • Signature Schemes & Wallet Interfaces — Practical command of EIP-712 typed data, ERC-1271 contract signatures, WebAuthn / passkey (P-256) signers, and the wallet-facing standards: EIP-1193, EIP-6963, EIP-5792 batched calls, ERC-7677 paymaster interfaces.
  • Production Wallet Experience — Experience designing or operating a production smart wallet or account abstraction system serving real users and real value.
  • Scale in a Major Crypto Organization — Substantial engineering experience at a large crypto product or protocol organization — for example Coinbase, Kraken, Base, Safe, the Ethereum Foundation, Consensys / MetaMask — or a comparable wallet, exchange, or account-abstraction infrastructure team where wallet correctness and custody were core to the product.
  • Operational Judgment Under Value at Risk — You have shipped and operated systems where a bug meant lost funds, and you can talk concretely about the guardrails, reviews, and rollback paths you put in place.
  • Solidity & EVM Fluency — Ability to read, review, and write account, paymaster, and module contracts; gas-aware design; upgradeability and migration patterns; working effectively with external auditors.
  • L2 Specifics — Understanding of L2 execution differences and how they affect wallet design: native account abstraction on zkSync-family chains, transaction and fee models, finality and reorg behavior, and RPC and indexer semantics.
  • Go Engineering — Strong Go (Golang) engineering skills: idiomatic code, concurrency patterns, performance profiling.
  • TypeScript & SDK Design — Ability to design and own client-side SDK surfaces in TypeScript that other engineering teams — internal and external — build on top of.
  • Distributed Systems — Experience with distributed systems and their trade-offs (consistency, availability, failure modes), and with reconciling off-chain state against an authoritative on-chain result.
  • PostgreSQL — Schema design, query optimization, migrations at scale.
  • Kubernetes — Deploying, operating, and debugging services in a k8s environment.
  • Message Streaming — Kafka or NATS — event-driven patterns, consumer groups, at-least-once delivery.
  • Git & CI/CD — Git and modern CI/CD practices.
  • Key Management — Hands-on experience with key material in production: platform secure storage (Keychain / Keystore), HSMs, MPC or threshold signing, and the operational discipline around each.
  • Wallet Threat Modeling — Solid grasp of the wallet attack surface: signature and delegation phishing, malicious dApp origins, replay and cross-chain replay, token approval abuse, and paymaster griefing and DoS.
  • Cross-Team Initiative Leadership — Proven ability to lead multi-quarter technical initiatives across teams.
  • Architectural Influence — Track record of influencing architecture and standards beyond your immediate team.
  • Written & Verbal Communication — You write RFCs and design docs that people actually read.

Nice to Have

  • Experience working in the video game industry, building or operating platforms for game developers, publishers, or players
  • Hands-on experience with the zkSync / Elastic Chain ecosystem (ZKsync OS, Matter Labs stack, native AA and paymaster flows, custom L2 operations)
  • Experience with embedded and ecosystem wallet providers or AA infrastructure vendors (thirdweb, Privy, Dynamic, Turnkey, Pimlico, Alchemy, Biconomy, ZeroDev, Safe{Core}) — and clear views on where to build versus buy
  • Experience with MPC / threshold custody, social recovery, or guardian-based recovery in a consumer product
  • Experience with NFT and token infrastructure at scale: ERC-721 / ERC-1155 / ERC-20 mechanics, marketplace contracts, Merkle-based airdrop and claim distribution, chain indexing services
  • Contributions to open-source wallet, security, or identity projects — including authorship or review of ERC / EIP standards
  • Familiarity with compliance requirements relevant to crypto consumer products: KYC / AML, geofencing, MiCA, SOC 2, ISO 27001, GDPR data minimization, audit logging
  • Experience with identity and auth integration for wallet derivation (OAuth 2.0 / OIDC, JWT verification, token scoping)
  • Background in platform or infrastructure engineering — building systems other engineers build on top of
  • Experience owning a mobile wallet surface (React Native / Expo, WebView provider injection, native signing UI)
  • Hands-on, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work

How We Work

Xsolla operates across multiple time zones, and the smart wallet underpins identity, ownership, and value transfer for every Web3 product we ship. Strong written communication is essential — your architectural decisions and designs need to stand on their own and be actionable without you in the room.

We value directness, technical depth, and follow-through. In this domain that means saying plainly when a design has custody, security, or reversibility implications, defending your position with evidence, and staying engaged until it's resolved. Where a decision touches player funds or key material, we expect the conservative call to be argued for explicitly rather than assumed.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Xsolla's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Xsolla's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Xsolla's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.