Aave App Explaining the Underlying of Accounts: Behind Email Login, There Is Still a Key and an Intelligent Account
币界网
11h ago
Ai Focus
For ordinary users, "self-hosting" often means mnemonic phrases, private keys, and irreversible operations; for finance, users expect email login, the ability to forget passwords, and account recovery services. On September 15th, Aave Labs revealed the account architecture of Aave App, attempting to combine these two experiences: users only need an email address or mobile number along with a password to register, while at the underlying level, it relies on an encrypted key controlled by the user in conjunction with a smart contract account.
Helpful
No.Help

For ordinary users, “self-hosting” often implies mnemonic phrases, private keys, and irreversible operations; for finance, users expect email login, the ability to forget passwords, and account recovery services. On September 15th, Aave Labs made public the account architecture of Aave App, attempting to combine these two experiences: users only need an email address or mobile number along with a password to register, while at the underlying level, it relies on an encrypted key controlled by the user in conjunction with a smart contract account.

Aave describes this design as a solution that takes into account both control and usability. It indeed lowers the barrier to using traditional on-chain wallets, but it does not eliminate security trade-offs. Encrypted backups are stored on the Aave backend, biometric recovery involves CoinCover, and smart accounts are also granted limited permissions by Aave. Understanding what each of these components can do is more important than the label of “self-hosted” or not.

Signer is responsible for control rights; the password and device determine how to retrieve them.

Each Aave App user has an external account, which is commonly known as EOA. The official term for it is Signer. The private key is generated on the user's device and then encrypted using the user's password and email or mobile authentication credentials. The encrypted result is uploaded to the Aave backend for storage. When a user logs in from a different device, they need to pass a one-time verification code sent via email or mobile phone, followed by entering the correct password, in order to regain access to their Signer.

This design is different from embedded wallets that can be unlocked with just a SMS verification code. Even if an attacker manages to hijack the SIM card and obtain only the mobile phone number verification code, they still lack the password. Users can also add Passkey and require the use of additional one-time verification codes provided by verifiers such as Google Authenticator. According to this, accounts will not be compromised just because the SIM card is hijacked, but this does not mean that accounts are immune to all attacks. Phishing, device intrusion, weak passwords, and recovery processes remain risks.

When forgetting your password, Aave has designed two recovery paths. The first is device recovery: as long as the user still possesses a device they have used to log in to before, they can update their password using the encrypted materials saved in the device's secure area through methods such as Face ID. The second is an optional biometric recovery option, which is suitable for situations where neither the password nor the old device is available.

Biometric recovery is provided by CoinCover. During registration, users are required to scan their faces. The encryption backups related to the private keys are divided into two parts: one part is given to CoinCover and the other part to Aave. During recovery, CoinCover completes face matching through multiple verification providers and AI; Aave also requires a one-time verification code received by the user through authentication. Both parties then release their respective materials and re-establish access. This approach prevents any single party from holding all the backups, but users must also accept face data processing and reliance on third-party services. This feature is optional and not mandatory by default.

To restrict unauthorized withdrawals, users need to pre-approve the withdrawal destination in advance. New destinations must be confirmed through email or mobile phone verification codes. This whitelist approach can prevent the transfer of funds after some accounts are taken over, but its effectiveness depends on whether the authentication channels are secure, whether the reminders are timely, and whether users will mistakenly approve incorrect addresses on phishing pages.

Intelligent accounts are responsible for automation, and this also brings a set of authorizations that must be understood.

In addition to Signer, Aave App also deploys smart contract accounts for users. It utilizes Alchemy Modular Account and v2, and incorporates a custom ERC-6900 module. Smart accounts can have payments made on their behalf by the platform, multiple operations can be processed in batches, additional signatures may be required for sensitive actions, and they can also grant limited execution permissions to third parties.

These capabilities directly serve the goal of "using it just like finance App". For example, after a user deposits fiat currency from a bank, settlement may take several days. If the funds arrive but the user still has to reopen App and manually deposit the earnings into the treasury, there will be a disruption in the experience. Aave states that the user's smart account will be granted limited permissions by Aave, allowing it to move the stablecoins into the treasury, so that the funds can automatically start generating earnings once they arrive.

The key lies in "limited permissions." Smart accounts do not grant all operational rights to the platform; instead, they specify which assets can be manipulated, the destinations, and the actions that can be performed through modules. However, whether these restrictions are truly clear depends on the module code, the upgrade mechanism, the methods for revoking permissions, and the front-end presentation. Users should not only see "automatic profit generation" but also need to know who can initiate transactions, what the maximum limits are, when these limits can be revoked, and how to handle errors in the contracts.

Articles labeled with Aave only focus on the account level. This does not prove that other objectives such as fixed interest rates, balance protection, and instant zero-fee bank transactions have been fully achieved. The officials list these as “non-negotiable” features of products designed for public savings and plan to introduce them separately. To claim that these goals have already been realized would be an overestimation of the current maturity of these products.

From an industry perspective, this architecture indicates that the direction of wallet competition is changing. In the past, self-hosted products primarily marketed their “user-exclusive mnemonic phrases” as a selling point; now, account abstraction, Passkey, modular permissions, and shard recovery have broken down control into multiple verifiable components. Users may not necessarily need to see blockchain transactions, but they still need to understand recovery services, contract permissions, and the boundaries of hosting.

This is not about replacing the private key with an email address, but rather about hiding the private key behind a more familiar login process. The good outcome is that ordinary people can retain ultimate control over their on-chain accounts without having to manage a string of mnemonic phrases; however, the downside could be that the complexity is shifted from the users to the backend and smart contracts, making the risks less apparent. Making the underlying processes public (as with Aave) is a necessary step, but the next important step is to ensure that permissions, recovery conditions, and exit paths are also clearly presented in the product interface.

Tip
$0
Like
1
Save
0
Views 33
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Coinbase includes the subscription of IPO within App: You can buy stocks, but the amount you receive is not guaranteed by the platform.
Coinbase is transforming itself from an encrypted asset trading platform into a trading gateway that covers a wider range of assets. On September 21st, the company announced the opening of applications for the distribution of IPO to retail users in the United States, with the first project being this week's Oura initial public offering. Eligible customers can view trades and prepare funds within Coinbase App, and after the price range is announced, they can submit "conditional purchase offers." Once the stocks officially begin trading publicly, they can also be traded directly on Coinbase.
币界网
·2026-09-22 10:04:04
182
Canadian construction investment rose to C$23.6 billion in July: Hospital projects drive growth, but residential markets show mixed fortunes
Canadian construction investment accelerated again in July, but this growth does not represent a full recovery in the real estate sector. Data released by Statistics Canada on September 21st indicates that, after seasonal adjustment, national construction investment increased by C$270.9 million month-on-month, a rise of 1.2%, to C$23.6 billion; year-on-year, it increased by 8.1%. Non-residential investment grew by 3.2%, while residential investment only increased slightly by 0.3%. Excluding price changes and calculated at constant 2023 prices, total investment amounted to C$21.2 billion, with a month-on-month increase of 1.0% and a year-on-year increase of 4.7%. The gap between nominal and real growth rates suggests that price factors still contributed a significant portion of this increase.
币百科
·2026-09-22 10:01:50
31
15-minute AI course starts to convert into university credits: Google moves teacher training from "heard of" to "recognized"
There are many free AI courses, but few of them can actually be credited to teachers' continuing education records or university transcripts. On September 18th, Google announced the addition of credit pathways for Google AI Educator Series: participants will be able to obtain free undergraduate-level credits through College Unbound in the future, and may also convert these credits to graduate-level credits with the cooperation of ISTE and Dominican University; teachers and administrators in Illinois can also use Illinois Digital Educators Alliance to accumulate the credits required for license renewals.
CoinMeta
·2026-09-22 10:00:38
28
Only 4 states in the US saw significant job growth in August: National unemployment rate remains stable at 4.1%, but the disparity in local job markets continues to widen
In August, the United States added 162,000 non-farm jobs, which on the surface appears to be a solid national report card. However, state-level data released by the U.S. Bureau of Labor Statistics on September 18th shows that the growth was not widespread: only California, Wisconsin, South Carolina, and New Mexico experienced statistically significant increases in non-farm employment, while the remaining 46 states and the District of Columbia saw virtually no significant changes.
币百科
·2026-09-21 09:53:22
81
View More