About the role
About Xsolla
Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators.
Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.
For more information, visit xsolla.com.
About the Role
We're looking for a Staff Engineer to own the smart wallet and account abstraction layer of Xsolla's Web3 platform. This is an individual contributor role with outsized technical scope: you'll be the technical anchor for how millions of players get an on-chain account they never have to think about — setting direction, making hard architectural calls, and raising the bar across the org.
Concretely, you'll own the account model behind Xsolla ZK, our zkSync-based L2, and the wallet that sits inside Xsolla App. Every player who signs in with Xsolla ID receives a deterministic, non-custodial smart account — derived from their identity claim, identical on every device, with private keys that never leave the client.
That account is not a separate "wallet" screen: it is the player's inventory, and it backs minting, gifting, trading on our Bazaar marketplace, Merkle-based reward airdrops, gas sponsorship, and an in-app dApp browser that exposes the same signer to third-party applications through an EIP-1193 provider.
You'll own the primitives underneath all of it: the ERC-4337 user operation lifecycle, EIP-7702 delegation, session keys and origin-bound Smart Sessions, paymaster and gas abstraction strategy, and the custody and recovery roadmap — including the move from raw key export to MPC custody.
You will own the strategy behind account abstraction, signing, and session management at scale, and evolve our smart account and permissioning model to meet both product and compliance needs. You operate with significant autonomy, but your decisions ripple across teams — so you'll spend real time building buy-in with engineering, product, security, and legal stakeholders, not just designing in isolation.
You are technically deep, calm under pressure, and comfortable being the escalation point when production wallet issues get hard — because in this domain, "hard" means a stuck user operation, a drained paymaster, or a signing prompt a player didn't understand. You write the RFCs and design docs that people actually read, and you create leverage for the broader engineering org through documentation, tooling, and mentorship — without needing a management title to do it.
Responsibilities
- Own Smart Wallet & AA Architecture — Own the technical strategy and architecture of our smart wallet platform, covering the account model, signing, session management, and gas abstraction at scale.
- Design the Account & Signing Model — Design and evolve our ERC-4337 user operation lifecycle (prepare → sign → submit → confirm), EIP-7702 delegation, deterministic address derivation from identity, and the session-key and permission primitives that let players act without a prompt on every transaction.
- Own Gas Abstraction — Set the paymaster and gas-sponsorship strategy: what we sponsor, how we meter and cap it, how we defend it from abuse, and how it degrades when sponsorship is unavailable.
- Harden the dApp-Facing Surface — Own the security model where our signer meets third-party applications: EIP-1193 / EIP-6963 provider behavior, origin-bound and policy-versioned sessions, trust tiers, and the transaction and signature confirmation flow. Define what a player is actually approving, and make sure the UI can prove it.
- Drive Custody & Recovery — Lead the custody roadmap from today's interim mechanisms toward MPC-based custody, and design recovery paths (passkeys, guardians, social recovery) that a non-crypto-native player can complete without losing assets.
- Drive Cross-Team Technical Decisions — Drive decisions on account architecture, SDK contracts, data modeling, and platform reliability, and build buy-in across the wallet, marketplace, SDK, mobile, and security teams.
- De-Risk Proactively — Identify systemic risks — key management, signature phishing, reorgs and indexer staleness, bundler and RPC dependencies, contract upgrade paths — and lead initiatives to resolve them before they become incidents.
- Set Engineering Standards — Define engineering standards, review critical code, contracts, and designs, and create leverage for the team through documentation, tooling, and mentorship.
- Align with Stakeholders — Collaborate with product, security, legal, and infra teams to align on roadmap and translate business and regulatory needs into well-scoped technical plans.
- Own Production Escalations — Serve as the go-to escalation point for complex production issues in the wallet and account abstraction domain.
Account Abstraction & Smart Wallets
- ERC-4337 Depth — Deep, hands-on understanding of ERC-4337: EntryPoint (v0.6 through v0.8), the UserOperation lifecycle, bundler and paymaster roles, validation rules (ERC-7562), gas estimation and its failure modes, counterfactual deployment, and signature validation for undeployed accounts (ERC-6492).
- EIP-7702 & the Post-Pectra Landscape — Working knowledge of EOA delegation, its interaction with ERC-4337 EntryPoint v0.8, and the trade-offs and risks it introduces (residual key authority, delegation phishing, storage collisions).
- Smart Account Implementations — Experience building on or extending production smart account implementations (Safe, Kernel, Biconomy, Coinbase Smart Wallet, or equivalent), and familiarity with modular account standards (ERC-7579 / ERC-6900).
- Session Keys & Delegated Permissions — Experience designing scoped, time-limited, policy-bound authority: session keys with TTL and contract allowlists, origin binding, permission revocation, and delegated-permission standards (ERC-7710 / ERC-7715).
- Signature Schemes & Wallet Interfaces — Practical command of EIP-712 typed data, ERC-1271 contract signatures, WebAuthn / passkey (P-256) signers, and the wallet-facing standards: EIP-1193, EIP-6963, EIP-5792 batched calls, ERC-7677 paymaster interfaces.
- Production Wallet Experience — Experience designing or operating a production smart wallet or account abstraction system serving real users and real value.
Production Crypto Track Record
- Scale in a Major Crypto Organization — Substantial engineering experience at a large crypto product or protocol organization — for example Coinbase, Kraken, Base, Safe, the Ethereum Foundation, Consensys / MetaMask — or a comparable wallet, exchange, or account-abstraction infrastructure team where wallet correctness and custody were core to the product.
- Operational Judgment Under Value at Risk — You have shipped and operated systems where a bug meant lost funds, and you can talk concretely about the guardrails, reviews, and rollback paths you put in place.
Smart Contracts & EVM
- Solidity & EVM Fluency — Ability to read, review, and write account, paymaster, and module contracts; gas-aware design; upgradeability and migration patterns; working effectively with external auditors.
- L2 Specifics — Understanding of L2 execution differences and how they affect wallet design: native account abstraction on zkSync-family chains, transaction and fee models, finality and reorg behavior, and RPC and indexer semantics.
Backend Engineering
- Go Engineering — Strong Go (Golang) engineering
Skills
idiomatic code, concurrency patterns, performance profiling.
- TypeScript & SDK Design — Ability to design and own client-side SDK surfaces in TypeScript that other engineering teams — internal and external — build on top of.
- Distributed Systems — Experience with distributed systems and their trade-offs (consistency, availability, failure modes), and with reconciling off-chain state against an authoritative on-chain result.
Data & Infrastructure
- PostgreSQL — Schema design, query optimization, migrations at scale.
- Kubernetes — Deploying, operating, and debugging services in a k8s environment.
- Message Streaming — Kafka or NATS — event-driven patterns, consumer groups, at-least-once delivery.
- Git & CI/CD — Git and modern CI/CD practices.
Security
- Key Management — Hands-on experience with key material in production: platform secure storage (Keychain / Keystore), HSMs, MPC or threshold signing, and the operational discipline around each.
- Wallet Threat Modeling — Solid grasp of the wallet attack surface: signature and delegation phishing, malicious dApp origins, replay and cross-chain replay, token approval abuse, and paymaster griefing and DoS.
Leadership
- Cross-Team Initiative Leadership — Proven ability to lead multi-quarter technical initiatives across teams.
- Architectural Influence — Track record of influencing architecture and standards beyond your immediate team.
- Written & Verbal Communication — You write RFCs and design docs that people actually read.
Nice to Have
- Experience working in the video game industry, building or operating platforms for game developers, publishers, or players
- Hands-on experience with the zkSync / Elastic Chain ecosystem (ZKsync OS, Matter Labs stack, native AA and paymaster flows, custom L2 operations)
- Experience with embedded and ecosystem wallet providers or AA infrastructure vendors (thirdweb, Privy, Dynamic, Turnkey, Pimlico, Alchemy, Biconomy, ZeroDev, Safe{Core}) — and clear views on where to build versus buy
- Experience with MPC / threshold custody, social recovery, or guardian-based recovery in a consumer product
- Experience with NFT and token infrastructure at scale:
ERC-721 / ERC-1155 / ERC-20 mechanics, marketplace contracts, Merkle-based airdrop and claim distribution, chain indexing services
- Contributions to open-source wallet, security, or identity projects — including authorship or review of ERC / EIP standards
- Familiarity with compliance requirements relevant to crypto consumer products: KYC / AML, geofencing, MiCA, SOC 2, ISO 27001, GDPR data minimization, audit logging
- Experience with identity and auth integration for wallet derivation (OAuth 2.0 / OIDC, JWT verification, token scoping)
- Background in platform or infrastructure engineering — building systems other engineers build on top of
- Experience owning a mobile wallet surface (React Native / Expo, WebView provider injection, native signing UI)
- Hands-on, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work
How We Work
Xsolla operates across multiple time zones, and the smart wallet underpins identity, ownership, and value transfer for every Web3 product we ship. Strong written communication is essential — your architectural decisions and designs need to stand on their own and be actionable without you in the room.
We value directness, technical depth, and follow-through. In this domain that means saying plainly when a design has custody, security, or reversibility implications, defending your position with evidence, and staying engaged until it's resolved. Where a decision touches player funds or key material, we expect the conservative call to be argued for explicitly rather than assumed.
Source: the employer's own careers page.