OpenChainGraph Suite · ART-613 · ERC-4337 Account Abstraction
ERC-4337 UserOperation Math
Three deterministic legs over bytes you already hold. First, the userOpHash recompute: keccak256(abi.encode(keccak256(packedUserOp), entryPoint, chainId)). Second, the EntryPoint's required prefund, computed from the gas limits you supply. Third, a reconciliation of a paymaster charge you declare against one recomputed from your own declared inputs. Nothing here is fetched: no RPC, no indexer, no receipt lookup, no contract state.
ERC-4337 v0.6 and v0.7keccak256 (vendored, no hand-rolled crypto)Recompute and reconcile only, no settlement claim
๐ All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data โ use synthetic or anonymised inputs only.
What This Does and Does Not Prove
This node recomputes the exact 32 bytes an ERC-4337 account signs, from the UserOperation fields you supply. It does not verify a signature or recover a signer address, and the ERC-4337 specification itself excludes the signature from the hashed struct, so supplying one changes nothing. A recomputed hash is not an inclusion, and a reconciled charge is not a settlement. This node never reads chain state: it cannot tell you whether the account exists, whether the EntryPoint holds a deposit, whether the nonce is still valid, or whether the operation was ever mined.
The EntryPoint version is yours to declare, and it changes what gets hashed. v0.6 hashes a ten-word UserOperation pack. v0.7 hashes an eight-word PackedUserOperation, in which verificationGasLimit and callGasLimit pack into a single accountGasLimits word and maxPriorityFeePerGas and maxFeePerGas pack into gasFees. The prefund formulas differ as well. Guessing the version would silently produce a wrong hash that still looks perfectly well formed, so this node refuses to guess: an unrecognised version returns INDETERMINATE rather than falling back to either layout.
What This Node Never Fetches
L1 data and blob fees are never derived. On rollups the total charge includes an L1 data-fee component that, after EIP-4844, depends on the inclusion-time L1 basefee and blob basefee. Neither is derivable offline from a UserOperation, so this node does not compute them. An L1 data fee enters the reconciliation only when you declare it, and when you do not, its absence is reported as a named gap rather than quietly absorbed into a residual.
The value block.basefee is never fetched either. The effective gas price is min(maxFeePerGas, maxPriorityFeePerGas + block.basefee). When your two fee caps are equal, the EntryPoint's own legacy shortcut returns maxFeePerGas directly and the basefee drops out, so the price is fully derivable offline. When they differ, the price is reported as null with the reason unless you declare a basefee. It is never guessed.
EntryPoint (declared, never inferred)
Both are hashed into the userOpHash, so neither is defaulted. The address you enter is what gets hashed; this node only flags whether it matches the widely published canonical deployment for the version you declared, and never substitutes it.
UserOperation Fields
Use 0x for an empty field. Under v0.7 the first 52 bytes of paymasterAndData carry the paymaster address, its verification gas limit, and its postOp gas limit; a shorter value is reported as not carrying them rather than back-filled with zeros.
Caller-Supplied Gas Limits and Fee Caps
Every value here is yours. This node applies each version's own prefund formula to them and never checks them against a deployed EntryPoint.
Paymaster Reconciliation (all inputs declared, all optional)
Leave any field blank to declare nothing. A blank field is treated as undeclared and named in the output, never as a zero.
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `recompute_erc4337_userop_math`. Task: Recompute the ERC-4337 userOpHash under a declared EntryPoint version (0.6 or 0.7), computes the required prefund from caller-supplied gas limits, and reconciles a declared paymaster charge against one recomputed from declared inputs.
Call it with arguments: {"policy_parameters":{"entryPointVersion":"0.6","entryPoint":"0x5FF137D4b0FDCD49DcA30c7CF57E578a026d2789","chainId":1,"sender":"0x2A1530C4C41db0B0b2bB646CB5Eb1A67b7158667","nonce":0,"initCode":"0x","callData":"0xb61d27f60000000000000000000000005ff137d4b0fdcd49dca30c7cf57e578a026d2789","paymasterAndData":"0x","callGasLimit":100000,"verificationGasLimit":150000,"preVerificationGas":21000,"maxFeePerGas":2000000000,"maxPriorityFeePerGas":1000000000}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string, or re-run the in-page WebMCP tool `recompute_erc4337_userop_math`.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data โ use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-613-erc4337-userop-math.html#p=v1.H4sIAAAAAAAA_wGsAVP-eyJlbnRyeVBvaW50VmVyc2lvbiI6IjAuNiIsImVudHJ5UG9pbnQiOiIweDVGRjEzN0Q0YjBGRENENDlEY0EzMGM3Q0Y1N0U1NzhhMDI2ZDI3ODkiLCJjaGFpbklkIjoxLCJzZW5kZXIiOiIweDJBMTUzMEM0QzQxZGIwQjBiMmJCNjQ2Q0I1RWIxQTY3YjcxNTg2NjciLCJub25jZSI6MCwiaW5pdENvZGUiOiIweCIsImNhbGxEYXRhIjoiMHhiNjFkMjdmNjAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDVmZjEzN2Q0YjBmZGNkNDlkY2EzMGM3Y2Y1N2U1NzhhMDI2ZDI3ODkiLCJwYXltYXN0ZXJBbmREYXRhIjoiMHgiLCJjYWxsR2FzTGltaXQiOjEwMDAwMCwidmVyaWZpY2F0aW9uR2FzTGltaXQiOjE1MDAwMCwicHJlVmVyaWZpY2F0aW9uR2FzIjoyMTAwMCwibWF4RmVlUGVyR2FzIjoyMDAwMDAwMDAwLCJtYXhQcmlvcml0eUZlZVBlckdhcyI6MTAwMDAwMDAwMH3QN3LerAEAAA