- Flexibility: A single wallet primitive that supports many use cases — end-user wallets, treasury management, disbursements, and more.
- High throughput and availability: Wallets scale to the maximum throughput available per chain, at the fastest speeds possible.
- True ownership: You and your users fully own every wallet. Even if Crossmint were to disappear, wallets continue to function — no vendor lock-in, no dependency on Crossmint infrastructure.
Dual Layer Architecture
Crossmint achieves this by separating two concerns: the wallet itself and the signers that control it.The Core: Smart Contract Wallets
On EVM chains, Crossmint wallets are smart contract wallets implementing ERC-4337 with ERC-7579 modular extensions. Because the wallet is a smart contract, it lives natively on the blockchain — not in a private third-party server that you cannot audit or control. On Solana, wallets use program-derived addresses (PDAs) with equivalent programmatic control. On Stellar, wallets use Soroban smart contracts, with equivalent functionality and additional cost and developer experience improvements around the use of trustlines. This smart contract foundation enables:- Seamless provider migration: If you wish to migrate, you can update the wallet’s recovery signers without changing the wallet address. Your users keep their address, balances, and transaction history regardless of infrastructure changes.
- Programmable authorization logic: Add multiple signers and recovery signers, with optional scoped permissions, with logic fully auditable onchain.
- Flexible gas sponsorship: Wallets can pay gas in USDC, native token, or billed to your Crossmint account. See Gas Sponsorship.
- Easier post-quantum migration: Unlike wallets that couple wallet address with the underlying signer, Crossmint wallets will continue to operate with the same address once keys are upgraded to post-quantum cryptography.
Because the wallet is a smart contract on a public blockchain, it does not depend on Crossmint’s servers to function. If Crossmint were to stop operating, you can interact with the wallet’s smart contract directly — adding new signers, transferring assets, or migrating to another provider — using standard blockchain tools.
The Control Layer: Signers
A signer is a cryptographic identity — such as a device key, passkey, server key, or external wallet — authorized to approve actions on the wallet’s behalf. Every Crossmint wallet organizes its signers into two distinct roles:- Signers handle day-to-day operations: authorizing transactions, signing messages, and interacting with protocols. By default, Crossmint wallets use a device signer — a P256 key generated inside the user’s device secure enclave (iOS Secure Enclave, Android Keystore, or a browser-based credential store). Signing adds zero latency and requires no network round-trip to Crossmint or any third-party server.
- Recovery signers are higher-friction signers used primarily for wallet recovery — for example, when a user switches to a new device and needs to enroll a new device key. Recovery signers use mechanisms like email OTP, SMS OTP, or server-held keys. They can also sign transactions as a fallback when no signer is available.
Recovery signers can sign transactions — they are not limited to recovery operations. The SDK automatically falls back to the recovery signer when no signer is configured or available. However, for the best user experience, signers like device keys and passkeys are preferred for day-to-day use because recovery signers involve higher friction (for example, OTP verification).
What This Means in Practice
For end-user wallets, this architecture enables completely invisible, self-custodial wallets. Users sign transactions on their own device hardware without knowing a blockchain is involved. Gas can be fully sponsored when gas sponsorship is enabled. There is no dependency on a third-party server to sign in or transact. And because the wallet is a smart contract, you have a clear migration path away from any provider — update the recovery signer and move on, keeping the same wallet address and all its assets. For server-side and AI agent wallets, you get low-latency, deterministic signing from your own infrastructure. A server key signer costs nothing per signing operation and supports throughput limited only by your backend. Separate recovery and signing secrets give you key rotation without wallet migration.Why Smart Contract Wallets
Wallets are becoming a foundational primitive for the entire economy and not just for crypto users, but for every person, company, AI agent, and connected device that needs to hold value or authorize payments. At that scale, wallet infrastructure must be extremely cheap to operate, flexible enough to support any custody model, and publicly auditable so that security is a matter of proof, not trust.The Problem with Off-Chain Key Storage
Most wallet infrastructure today stores keys off-chain, inside proprietary enclaves or distributed across MPC networks. This means:- Provider dependency: Wallets depend on a specific provider’s infrastructure to function.
- Latency overhead: Key reconstruction adds latency to every signature.
- Painful migration: Moving to a new provider means exporting keys and creating new wallet addresses.
A Different Approach
Smart contract wallets take a different approach. The wallet is a program deployed on a public blockchain — it does not live in anyone’s private infrastructure. The signer is completely separate and can be anything: a passkey on a user’s phone, an AWS KMS key in your cloud, or a recovery credential. The key stays whole. No splitting, no reconstruction, no added latency.- Security is not a promise — it is code you can read.
- Recovery is not a key-share coordination problem — it is an onchain signer rotation.
- Migration is not an export — it is a signer swap.
Why We Chose This Architecture
We chose this architecture because it is the only one that scales to the future we are building toward: wallets as ubiquitous and permanent as email addresses, but programmable, auditable, and owned by no one except the people and systems that use them.Recovery
Learn how wallet recovery works
Signers
Understand the signer types available for your wallets

