A bundler is the permissionless worker of ERC-4337 account abstraction: it collects user operations from the mempool, bundles several into one Ethereum transaction, submits them through the EntryPoint, and earns fees for the service. Anyone can run one — no license, no staking requirement — which is what keeps the account-abstraction economy open. How it works The bundler is the engine room between your smart wallet and the chain: Mempool: users sign user operations (intents), which propagate through a dedicated user-op mempool instead of the regular transaction pool. Validation: the bundler greedily selects compatible operations, checking each wallet's validation logic and any paymaster sponsorship, and simulating the bundle to reject operations that would fail. Submission: it packages the winning set into a single handleOps call on the global EntryPoint contract, which verifies signatures, enforces paymaster deposits, and executes every operation. Compensation: bundlers are paid from per-operation fees and optional paymaster surcharges; competition between bundlers sets the market price for inclusion — exactly like proposer-builder-separation at the user layer. Because inclusion is a market, a user operation is never wedded to one bundler: wallets publish to several, and any bundler can pick it up. Why it matters for decentralization Bundlers replace the centralized relayers of old meta-transaction systems with an open marketplace — the account-abstraction model's censorship-resistance rests entirely on that marketplace staying competitive. Watch bundler concentration the way you watch mining pools: whoever packages operations controls their timing and inclusion, so delay or exclusion is a real, if subtle, power. The infrastructure pillar of our scoring model treats operator-set diversity, not protocol features, as the decisive variable — bundler diversity is the same discipline applied one layer up. Example: the bundler math under the hood Picture a wallet at a checkout on Base. Five user operations are pending; a bundler picks the three that cover gas, simulates them successfully, and submits one handleOps transaction whose gas is refunded across the operations. The user never sees the bundler, the paymaster, or the EntryPoint — but the entire pipeline is public, auditable, and permissionless to join or leave. That is the property that makes smart-wallet UX compatible with the "verify, don't trust" ethos the W3D site is built around. Risks & limitations Operational concentration: in practice a handful of professional bundlers process most volume; arguably-permissionless does not mean automatically widely operated. Reputation/spam dynamics: the alternative mempool is sensitive to spam and sybil operations; bundlers must maintain reputation lists or pay for junk simulation. UX dependence: if bundler coverage vanishes, smart wallets stall — funds stay safe, but the app feels broken. Front-running surface: bundled operations can be cherry-picked or reordered by a bundler with MEV ambitions, so the market depends on honest bundlers competing. The bundler's technical surface is where account abstraction meets real constraints. Three mechanics define how professional bundlers operate: Simulation-first validation: bundlers reject operations that fail dry-gas simulation, using eth_estimateUserOperationGas and local execution to cull junk cheaply — this is what keeps the alternative mempool from being polluted like the old mempool-free days. Gas accounting through the EntryPoint: the bundler pre-pays the whole handleOps transaction, then recovers gas from each operation's prefund and the paymaster's deposit; the EntryPoint's refund ordering (senders first, then paymasters) guarantees no bundler subsidizes an operation forever. Reputation rules: ERC-7562 specifies bundler-side validation rules — per-entity throttling, banned status degrees, and whitelisting — that stop a single actor from spamming the mempool or exploiting the bundler's simulation budget. The operational consequence: a small number of well-capitalized bundlers (Alchemy, Pimlico, Stackup, and their peers) dominate relayed volume today, while anyone with the reference bundler software can enter next week. The market's openness is real; its present concentration is measurable — which is exactly the "permissionless yet concentrated" pattern the W3D infrastructure pillar audits on validator sets, and the reason we publish operator-set facts rather than feature claims. Running a bundler yourself: what it takes The permissionless claim is concrete — here is the minimum viable path: Run the reference bundler (eth-infinitism/bundler) or a commercial binary (Pimlico, Stackup, Alchemy) pointed at your own Ethereum RPC. Expose the standard RPC surface (eth_sendUserOperation, eth_estimateUserOperationGas) and join the alternative mempool so operations actually arrive. Fund the bundler EOA with enough ETH to cover handleOps gas; recover costs from operation fees and paymaster surcharges on each successful bundle. Configure validation rules (ERC-7562 reputation, entity throttling, banned lists) so spam does not burn your simulation budget. Monitor rejection reasons and bundle success rates; a well-run bundler is visible in its own stats, which is itself an infrastructure-decency signal. No staking, no license, no protocol permission — just RPC access, a funded key, and correct validation. That is the openness that makes bundler centralization a market outcome rather than a protocol design; it can be measured, critiqued, and competed against, which is precisely why the W3D methodology prefers measurable operator-set facts over decentralization claims. A note on economics: bundling is profitable only when operations genuinely need each other's gas. A single-operation bundle still pays the EntryPoint's fixed overhead, so live bundlers aggregate aggressively — which is exactly why bundler market-share data tends to look concentrated even while the market stays open. The healthy signal is not "many bundlers," but "threat of entry is real": if the top operators raised fees to censorship levels, new operators would appear within weeks. Frequently asked questions Do I choose my bundler? Your wallet picks automatically, by fee and reliability — the same way it picks a gas price today. Advanced users can route through a specific bundler via RPC settings. Can a bundler steal my funds? No. A bundler can only include your pre-signed operation or ignore it; it cannot alter or misroute it. The risk is censorship, not theft. Why not just use normal transactions? Smart wallets cannot send raw transactions — their programmable logic requires the ERC-4337 flow. Bundlers are simply the price of having programmable accounts. Sources & methodology ERC-4337 spec — bundler and EntryPoint specification. erc4337.io — live bundler operators and market share. W3D methodology + academy dataset. Related terms ERC-4337 · Account abstraction · Paymaster · Smart contract · Mempool Chain audits: Base · Ethereum · tool: Nakamoto coefficient calculator
On this page
A bundler is the permissionless worker of ERC-4337 account abstraction: it collects user operations from the mempool, bundles several into one Ethereum transaction, submits them through the EntryPoint, and earns fees for the service. Anyone can run one — no license, no staking requirement — which is what keeps the account-abstraction economy open.
How it works
The bundler is the engine room between your smart wallet and the chain:
- Mempool: users sign user operations (intents), which propagate through a dedicated user-op mempool instead of the regular transaction pool.
- Validation: the bundler greedily selects compatible operations, checking each wallet’s validation logic and any paymaster sponsorship, and simulating the bundle to reject operations that would fail.
- Submission: it packages the winning set into a single
handleOpscall on the global EntryPoint contract, which verifies signatures, enforces paymaster deposits, and executes every operation. - Compensation: bundlers are paid from per-operation fees and optional paymaster surcharges; competition between bundlers sets the market price for inclusion — exactly like proposer-builder-separation at the user layer.
Because inclusion is a market, a user operation is never wedded to one bundler: wallets publish to several, and any bundler can pick it up.
Why it matters for decentralization
Bundlers replace the centralized relayers of old meta-transaction systems with an open marketplace — the account-abstraction model’s censorship-resistance rests entirely on that marketplace staying competitive. Watch bundler concentration the way you watch mining pools: whoever packages operations controls their timing and inclusion, so delay or exclusion is a real, if subtle, power. The infrastructure pillar of our scoring model treats operator-set diversity, not protocol features, as the decisive variable — bundler diversity is the same discipline applied one layer up.
Example: the bundler math under the hood
Picture a wallet at a checkout on Base. Five user operations are pending; a bundler picks the three that cover gas, simulates them successfully, and submits one handleOps transaction whose gas is refunded across the operations. The user never sees the bundler, the paymaster, or the EntryPoint — but the entire pipeline is public, auditable, and permissionless to join or leave. That is the property that makes smart-wallet UX compatible with the “verify, don’t trust” ethos the W3D site is built around.
Risks & limitations
- Operational concentration: in practice a handful of professional bundlers process most volume; arguably-permissionless does not mean automatically widely operated.
- Reputation/spam dynamics: the alternative mempool is sensitive to spam and sybil operations; bundlers must maintain reputation lists or pay for junk simulation.
- UX dependence: if bundler coverage vanishes, smart wallets stall — funds stay safe, but the app feels broken.
- Front-running surface: bundled operations can be cherry-picked or reordered by a bundler with MEV ambitions, so the market depends on honest bundlers competing.
The bundler’s technical surface is where account abstraction meets real constraints. Three mechanics define how professional bundlers operate:
- Simulation-first validation: bundlers reject operations that fail dry-gas simulation, using
eth_estimateUserOperationGasand local execution to cull junk cheaply — this is what keeps the alternative mempool from being polluted like the old mempool-free days. - Gas accounting through the EntryPoint: the bundler pre-pays the whole
handleOpstransaction, then recovers gas from each operation’s prefund and the paymaster’s deposit; the EntryPoint’s refund ordering (senders first, then paymasters) guarantees no bundler subsidizes an operation forever. - Reputation rules: ERC-7562 specifies bundler-side validation rules — per-entity throttling, banned status degrees, and whitelisting — that stop a single actor from spamming the mempool or exploiting the bundler’s simulation budget.
The operational consequence: a small number of well-capitalized bundlers (Alchemy, Pimlico, Stackup, and their peers) dominate relayed volume today, while anyone with the reference bundler software can enter next week. The market’s openness is real; its present concentration is measurable — which is exactly the “permissionless yet concentrated” pattern the W3D infrastructure pillar audits on validator sets, and the reason we publish operator-set facts rather than feature claims.
Running a bundler yourself: what it takes
The permissionless claim is concrete — here is the minimum viable path:
- Run the reference bundler (eth-infinitism/bundler) or a commercial binary (Pimlico, Stackup, Alchemy) pointed at your own Ethereum RPC.
- Expose the standard RPC surface (
eth_sendUserOperation,eth_estimateUserOperationGas) and join the alternative mempool so operations actually arrive. - Fund the bundler EOA with enough ETH to cover
handleOpsgas; recover costs from operation fees and paymaster surcharges on each successful bundle. - Configure validation rules (ERC-7562 reputation, entity throttling, banned lists) so spam does not burn your simulation budget.
- Monitor rejection reasons and bundle success rates; a well-run bundler is visible in its own stats, which is itself an infrastructure-decency signal.
No staking, no license, no protocol permission — just RPC access, a funded key, and correct validation. That is the openness that makes bundler centralization a market outcome rather than a protocol design; it can be measured, critiqued, and competed against, which is precisely why the W3D methodology prefers measurable operator-set facts over decentralization claims.
A note on economics: bundling is profitable only when operations genuinely need each other’s gas. A single-operation bundle still pays the EntryPoint’s fixed overhead, so live bundlers aggregate aggressively — which is exactly why bundler market-share data tends to look concentrated even while the market stays open. The healthy signal is not “many bundlers,” but “threat of entry is real”: if the top operators raised fees to censorship levels, new operators would appear within weeks.
Frequently asked questions
Do I choose my bundler?
Your wallet picks automatically, by fee and reliability — the same way it picks a gas price today. Advanced users can route through a specific bundler via RPC settings.
Can a bundler steal my funds?
No. A bundler can only include your pre-signed operation or ignore it; it cannot alter or misroute it. The risk is censorship, not theft.
Why not just use normal transactions?
Smart wallets cannot send raw transactions — their programmable logic requires the ERC-4337 flow. Bundlers are simply the price of having programmable accounts.
Sources & methodology
- ERC-4337 spec — bundler and EntryPoint specification.
- erc4337.io — live bundler operators and market share.
- W3D methodology + academy dataset.
Related terms
ERC-4337 · Account abstraction · Paymaster · Smart contract · Mempool
Chain audits: Base · Ethereum · tool: Nakamoto coefficient calculator