Insights on Crypto Payments, Infrastructure, and Operations

Bundler Risk

Pronunciation: BUN-dler RISK

Definition

Bundler Risk is a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to submit user operations. A score for Bundler Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Bundler Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.

Overview

In account-abstraction systems such as ERC-4337, a bundler collects user operations, simulates their validity, packages them, and submits a transaction to an entry-point contract. Users may depend on bundlers for practical access to block inclusion.

A bundler can reject valid operations, delay or reorder submission, apply inconsistent simulation, expose pending intent, or become unavailable. Malicious user operations can also consume bundler resources, exploit simulation differences, or cause losses if validation and fee estimation are incorrect.

Wallets should support multiple bundlers or direct fallback where feasible, verify fee and inclusion status, and avoid treating submission as final. Bundler operators need reputation controls, resource limits, deterministic validation, monitoring, and protection against denial-of-service and mempool abuse.

For Bundler Risk, production scope should name the relevant keys, signing policies, accounts, addresses, transactions, recovery paths, and custody boundaries, the decision being supported, the accountable owner, and the time and jurisdiction boundaries.

Bundler Risk is a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to submit user operations. Bundlers improve account-abstraction usability but add availability, censorship, ordering, simulation, and operational dependencies that wallets must manage.

For Bundler Risk, the assessment should evaluate a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to submit user operations. The assessment record should separate observed evidence supporting a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to submit user operations from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to submit user operations have changed enough to require a new rating, treatment, or approval.

Key Takeaway

Bundlers improve account-abstraction usability but add availability, censorship, ordering, simulation, and operational dependencies that wallets must manage.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)