Start
How it works
The steps, with the data that moves.
The actors
| Actor | Holds | Can |
|---|---|---|
| Arm (wallet) | A key and some ETH or tokens | Sign an authorization and the calls it allows |
| Sponsor | Gas money | Send the transaction. Nothing else. |
Coordinator Octopus | Nothing | Call execute on each arm in turn |
Wallet code OctopusWallet | The nonce, in a private slot | Run the calls the wallet's key signed |
1. The authorization
EIP-7702 lets an ordinary wallet point its address at a contract's code. The wallet signs (chainId, implementation, nonce). Once the chain applies it, the wallet's code becomes a short marker 0xef0100 + implementation address, and calls to the wallet run the implementation's code with the wallet's own address, balance and storage. A fresh wallet uses nonce 0.
2. The signed calls
Each wallet signs an EIP-712 message over Execute(callsHash, nonce, deadline). The domain contains the chain and the wallet's own address. The wallet code checks that the signature came from address(this), that is, from the wallet's own key.
3. One transaction
type 4 transaction
to: Octopus
authorizationList: [ auth(wallet 1), auth(wallet 2), ... auth(wallet N) ]
data: fire([ job 1, job 2, ... job N ], atomic)
job = { wallet, calls[], deadline, signature }
The chain applies every authorization before running fire. Then, for each job, the coordinator checks that the wallet carries the trusted marker and calls wallet.execute(calls, deadline, signature).
4. Inside each arm
The wallet code checks the deadline, reads and bumps its nonce, recovers the signer and compares it with its own address, then makes each call. If any call fails the whole arm reverts, including its nonce.
5. Atomic or not
atomic = true: if any arm fails, the transaction reverts and nobody acts. atomic = false: failed arms are skipped and reported in Arm events, the others still go through.
6. Afterwards
The wallets stay delegated until they sign a new authorization, so a wallet can be used again with a new signed job. To undo it, sign an authorization to the zero address. See Limits and risks.