Agent skill

Social Recovery

by Nethereum in Nethereum/Nethereum

Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone.

MITAuto-check passedBackend & APIs

Install Social Recovery

skills CLI
$ npx skills add Nethereum/Nethereum --skill social-recovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Nethereum/Nethereum social-recovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nethereum-skills/skills/social-recovery .claude/skills/social-recovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
social-recovery
GitHub stars
2.3k
Token cost
~3.1k tokens
SKILL.md length
1,056 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone.

  • The user mentions social recovery
  • SKILL.md covers When to Use This, Packages, The Simple Way and Mental Model: Guardians,…, plus 6 more sections
  • Calls dotnet
  • Guardian recovery

What it does

Social Recovery is an agent skill from Nethereum/Nethereum. Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone. Covers Nethereum's SocialRecoveryConfig, SocialRecoveryValidatorModule, and MultiGuardianSigningService. Use whenever the user mentions social recovery, guardian recovery, N-of-M guardians, 'lost my seed phrase / lost my wallet key', recovering a smart contract wallet, break-glass account recovery, or guardian quorum wallet recovery, in .NET/C.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Smart contracts. It works with C# and .NET. The repository describes itself as: Ethereum .Net cross platform integration library. The licence is MIT.

When your agent uses it

  • The user mentions social recovery
  • Guardian recovery
  • N-of-M guardians
  • Lost my seed phrase / lost my wallet key

Example prompts

  • “lost my seed phrase / lost my wallet key”
  • “/social-recovery”

What it can do on your machine

Read from SKILL.md and the folder at commit 229f278. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.nethereum.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Social Recovery loads about 3.1k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,056 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Nethereum/Nethereum at commit 229f278, republished under its MIT licence (© Nethereum). 1,056 words, ~3,140 tokens.

Download SKILL.mdSave it as .claude/skills/social-recovery/SKILL.md (or your agent's skills folder).
name
social-recovery
description
Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone. Covers Nethereum's SocialRecoveryConfig, SocialRecoveryValidatorModule, and MultiGuardianSigningService. Use whenever the user mentions social recovery, guardian recovery, N-of-M guardians, 'lost my seed phrase / lost my wallet key', recovering a smart contract wallet, break-glass account recovery, or guardian quorum wallet recovery, in .NET/C#.
user-invocable
true

Social Recovery: N-of-M Guardian Quorum Account Recovery

Every other signer (an ECDSA key, a passkey, a session key) assumes there is some working credential to authenticate with. Social recovery answers the question those cannot: what happens when the owner key itself is gone? A phone is lost, a seed phrase is destroyed, a hardware wallet dies — no key remains to sign anything, so no session key, second validator, or policy can help, because all of them still need to be invoked by an existing authorized signer.

Social recovery must be set up before that happens: a set of guardians (friends, family, hardware wallets you control, other trusted parties) is installed on the account in advance, so that later, if the owner key is lost, a quorum of guardians — not any single one — can co-sign a UserOperation that rotates the account to a new owner key. No individual guardian can act alone, and guardians have no day-to-day authority over the account — only the collective quorum, exercised once, to recover it.

When to Use This

  • User wants a way to recover a smart account after losing the owner key
  • User mentions guardians, N-of-M quorum, or break-glass recovery for a wallet
  • User is designing an account-recovery UX that shouldn't depend on any single device or person surviving
  • User wants to know who can act during recovery and what happens with too few guardians

Packages

bash
dotnet add package Nethereum.AccountAbstraction
dotnet add package Nethereum.Web3

You need an IAAClient, a deployed ERC-7579-compatible NethereumAccount with at least one validator installed (typically ECDSAValidator — see the modular-accounts skill), plus a deployed SocialRecovery module contract (SocialRecoveryService.DeployContractAndGetServiceAsync, a generated Nethereum contract service — no hand-written ABI).

csharp
using System.Linq;
using Nethereum.AccountAbstraction; // AATransactionReceipt
using Nethereum.AccountAbstraction.Client;
using Nethereum.AccountAbstraction.Contracts.Core.NethereumAccount;
using Nethereum.AccountAbstraction.Contracts.Modules.Native.ECDSAValidator;
using Nethereum.AccountAbstraction.ERC7579.Modules;
using Nethereum.AccountAbstraction.ERC7579.Modules.MultiGuardian;
using Nethereum.AccountAbstraction.ERC7579.Modules.SocialRecovery;
using Nethereum.AccountAbstraction.Validation; // Erc7769ErrorCodes
using Nethereum.JsonRpc.Client; // RpcResponseException
using Nethereum.Signer; // EthECKey

The Simple Way

csharp
var accountService = new NethereumAccountService(web3, account.Address);
accountService.UseAccountAbstraction(account, aaClient);

// Install SocialRecovery with a 2-of-3 guardian quorum, signed by the account's CURRENT owner.
var receipt = (AATransactionReceipt)await accountService.InstallSocialRecoveryAndWaitForReceiptAsync(
    socialRecoveryAddress, threshold: 2, new[] { guardian1, guardian2, guardian3 });

That's it — any 2 of those 3 guardians can now recover the account if its owner key is ever lost. ABI-encoding the guardian list, the module type id, fees, gas, and nonce are all automatic.

Mental Model: Guardians, Threshold, Recovery-as-Owner-Rotation

SocialRecovery is an ERC-7579 TYPE_VALIDATOR module, installed exactly like ECDSAValidator or SmartSession, with two pieces of on-chain configuration per account: a guardian list and a threshold (SocialRecoveryConfig). Guardians never get day-to-day control. The only thing a guardian quorum can do is co-sign a UserOperation, and that UserOperation is itself restricted on-chain to a single execute() call whose target is a currently-installed TYPE_VALIDATOR module — in practice, calling transferOwnership on the account's ECDSAValidator to rotate the owner to a new key.

Recovery is a single co-signed UserOperation, not a two-phase propose/approve flow: each guardian signs the same userOp hash with their own key, MultiGuardianSignatureBlobBuilder concatenates the threshold signatures (ascending by guardian address) into one CheckNSignatures-compatible blob, and SocialRecoveryValidatorModule prefixes that blob with the module's own address.

TypeRole
SocialRecoveryConfigBuilds the module's install-time init data — Threshold + Guardians
SocialRecoveryValidatorModuleThe IErc7579ValidatorModule that identifies the installed module and prefixes a recovery signature
MultiGuardianSigningServiceThe IAccountSigningService that has a quorum of guardian keys co-sign a UserOperation

Configure an N-of-M Guardian Quorum

Guardians must be sorted ascending by address and free of duplicates at install time — SocialRecovery.sol's onInstall reverts NotSortedAndUnique() otherwise. MultiGuardianSignatureBlobBuilder.SortAddressesAscending gives you that ordering:

csharp
var guardianKeys = Enumerable.Range(0, guardianCount)
    .Select(_ => EthECKey.GenerateKey())
    .ToArray();

var sortedGuardians = MultiGuardianSignatureBlobBuilder.SortAddressesAscending(
    guardianKeys.Select(k => k.GetPublicAddress()));

var accountService = new NethereumAccountService(web3, account.Address);
accountService.UseAccountAbstraction(account, aaClient);

var receipt = (AATransactionReceipt)await accountService.InstallSocialRecoveryAndWaitForReceiptAsync(
    socialRecoveryAddress, threshold, sortedGuardians);

This is signed by the account's current owner — the guardians are not involved in their own installation. It composes with counterfactual deploy-on-first-op exactly like any other first UserOperation: if the account isn't deployed yet, the same op both deploys it and installs SocialRecovery.

SocialRecoveryConfig also validates itself before ever reaching the chain: GetInitData() throws InvalidOperationException if Guardians is empty, or if Threshold is not between 1 and the guardian count — the same rule SocialRecovery.sol's own onInstall enforces on-chain.

A Guardian Quorum Recovers the Account

The owner key is now lost. A quorum of threshold guardians (any threshold of the installed set — order doesn't matter, only which ones sign) co-signs a UserOperation that calls transferOwnership on the account's ECDSAValidator, through a second, independent NethereumSmartAccount attached to the same address:

csharp
var newOwner = EthECKey.GenerateKey();

// A guardian quorum co-signs the recovery userOp - the account's owner is never involved.
var guardianSigningService = new MultiGuardianSigningService(guardianKeys, threshold);
var socialRecoveryValidator = new SocialRecoveryValidatorModule(socialRecoveryAddress, threshold);
var recoveryAccount = aaClient.GetAccount(account.Address, guardianSigningService, socialRecoveryValidator);

// Driven through the RECOVERY TARGET's own typed service (ECDSAValidatorService), not
// NethereumAccountService.ExecuteAsync - see Common Mistakes below for why that distinction matters.
var ecdsaValidatorService = new ECDSAValidatorService(web3, ecdsaValidatorAddress);
ecdsaValidatorService.UseAccountAbstraction(recoveryAccount, aaClient);

var receipt = (AATransactionReceipt)await ecdsaValidatorService.TransferOwnershipRequestAndWaitForReceiptAsync(
    newOwner.GetPublicAddress());

var rotatedOwner = await ecdsaValidatorService.GetOwnerQueryAsync(account.Address);
// rotatedOwner == newOwner.GetPublicAddress() - the owner has genuinely rotated.

Neither the old owner key nor the new owner key ever signs anything — the rotation is authorized entirely by the guardian quorum through SocialRecoveryValidatorModule.

Show full SKILL.md (405 more words)Show less

Under-Threshold Rejection Is Enforced On-Chain

Fewer guardians than the threshold genuinely cannot recover the account — the chain rejects it, not just client-side discouragement:

csharp
var partialGuardianKeys = guardianKeys.Take(threshold - 1).ToArray();
var partialThreshold = partialGuardianKeys.Length; // one short of the installed threshold

var partialSigningService = new MultiGuardianSigningService(partialGuardianKeys, partialThreshold);
var partialValidator = new SocialRecoveryValidatorModule(socialRecoveryAddress, partialThreshold);
var partialAccount = aaClient.GetAccount(account.Address, partialSigningService, partialValidator);

var attemptedNewOwner = EthECKey.GenerateKey();
ecdsaValidatorService.UseAccountAbstraction(partialAccount, aaClient);

try
{
    await ecdsaValidatorService.TransferOwnershipRequestAndWaitForReceiptAsync(attemptedNewOwner.GetPublicAddress());
}
catch (InvalidOperationException ex) when (ex.InnerException is RpcResponseException rpcEx &&
                                             rpcEx.RpcError.Code == Erc7769ErrorCodes.SimulateValidation)
{
    // Rejected during bundler gas estimation (AA23) - the undersized signature blob fails
    // CheckSignatures' length guard.
}

The rejection happens during the bundler's gas-estimation simulation, before the real op is ever sent. A distinct failure mode exists too: a correctly-sized blob signed entirely by non-guardian keys passes the length guard but fails SocialRecovery's guardian-membership check instead, surfacing as AA24 at send time rather than AA23 during estimation.

Advanced: Changing the Guardian Set Later

SocialRecoveryService also exposes AddGuardianRequestAsync(guardian), RemoveGuardianRequestAsync(prevGuardian, guardian), and SetThresholdRequestAsync(threshold). On-chain these are self-calls (msg.sender == account) — driven through whichever validator currently authorizes the account (typically the owner's ECDSAValidator), not the recovery quorum. Use them to evolve a guardian set while the existing owner key still works, not as part of a lost-key recovery.

Common Mistakes

  • Guardians not sorted/deduplicated before install — SocialRecovery.sol reverts NotSortedAndUnique(). Always run addresses through MultiGuardianSignatureBlobBuilder.SortAddressesAscending first.
  • Routing the recovery call through NethereumAccountService.ExecuteAsync instead of the target module's own service. SocialRecovery.validateUserOp's on-chain decode requires a single execute() call targeting a currently-installed TYPE_VALIDATOR module. Routing through the account's own ExecuteAsync wraps the call in a second execute() — a shape SocialRecovery's fixed-offset decode doesn't recognize. Always attach the target module's own generated service (e.g. ECDSAValidatorService) via UseAccountAbstraction.
  • Threshold out of range — SocialRecoveryConfig.GetInitData() throws client-side for an empty guardian list or a threshold of zero or greater than the guardian count.
  • Assuming under-threshold and non-guardian quorums fail the same way — too few signatures fails the length guard during estimation (AA23); enough signatures from the wrong keys fails the membership check at send time (AA24). Catch both.

Decision Guide

Social recoverySecond validator (e.g. passkey)Session key (SmartSession)
When it's usableOnly after the primary owner key is lostAny timeAny time, within its policy scope
Who can act aloneNobody — a quorum is requiredYesYes, within whatever the policy allows
Needed in advanceGuardians + threshold, installed before the key is lostThe second credential, already installedA session already enabled
Solves "I lost my only key"Yes — this is exactly what it's forOnly if you still have the other credentialNo — a session key can't rotate the owner

Reach for social recovery when the account needs a way back in that doesn't depend on any single device or person surviving. It's complementary to a second validator (fast, no quorum) and a session key (scoped delegated access, covered by the smart-sessions-and-policies skill).

For full documentation, see: https://docs.nethereum.com/docs/account-abstraction/guide-social-recovery

© Nethereum, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/nethereum-skills/skills/social-recovery of Nethereum/Nethereum.

Open the folder on GitHubat commit 229f278

Compare with similar skills

Social Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Social Recovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Social Recovery this skillNethereum/Nethereum2.3k—~3.1kAutomated safety check: PassMIT
Tsp Csharpquerylenshq/ef-querylens225—~1.3kAutomated safety check: PassMIT
XML DocumentationVonage/vonage-dotnet-sdk118—~2.7kAutomated safety check: PassApache-2.0
Dotnet 10 Csharp 14sketch7/FluentlyHttpClient121—~2.2kAutomated safety check: PassMIT
DisCatSharp Discord DevelopmentAiko-IT-Systems/DisCatSharp140—~1.2kAutomated safety check: PassMIT
Foundationdb Advanced LayersSnowBankSDK/foundationdb-dotnet-client158—~3.4kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Tsp Csharp

    querylenshq/ef-querylens

    Comprehensive C and .NET development skill for TSP projects.

    225 GitHub stars~1.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • XML Documentation

    Vonage/vonage-dotnet-sdk

    Improve XML documentation in the Vonage .NET SDK. An agent skill from Vonage/vonage-dotnet-sdk.

    118 GitHub stars~2.7k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Dotnet 10 Csharp 14

    sketch7/FluentlyHttpClient

    A skill your agent uses when building .NET 10 or C 14 applications; when using minimal APIs, modular monolith patterns, or feature folders; when implementing HTTP resilience, Options pattern…

    121 GitHub stars~2.2k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • DisCatSharp Discord Development

    Aiko-IT-Systems/DisCatSharp

    Helps build, explain and troubleshoot C# Discord apps on DisCatSharp, answering from the project's installed version and the library's documentation rather than guesses.

    140 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Foundationdb Advanced Layers

    SnowBankSDK/foundationdb-dotnet-client

    Advanced engineering for sophisticated FoundationDB layers with the .NET client (FoundationDB.Client / SnowBank) — the cluster model and transaction lifecycle (proxies, resolvers, tlogs, storage…

    158 GitHub stars~3.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Tiger Brokers OpenAPI C# SDK

    qusong0627/QuantMind

    Guides building C# and .NET apps on the Tiger Brokers OpenAPI SDK: setup, market data, orders, accounts, options and real-time push, defaulting to paper trading.

    1.7k GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed

More from Nethereum/Nethereum

All 71 skills in this repo
  • Aa Batching Paymasters

    Nethereum/Nethereum

    Help users batch multiple calls into a single UserOperation and sponsor gas with paymasters using Nethereum Account Abstraction.

    2.3k GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check passed
  • Aa Bundler

    Nethereum/Nethereum

    Help users run an ERC-4337 bundler using Nethereum — set up in-process or standalone bundlers with mempool, validation, reputation, and JSON-RPC server.

    2.3k GitHub stars~1.2k tokensUpdated 6 days ago
    Auto-check passed
  • Abi Encoding

    Nethereum/Nethereum

    Encode and decode Ethereum ABI data with Nethereum. An agent skill from Nethereum/Nethereum.

    2.3k GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed
  • Abi Retrieval

    Nethereum/Nethereum

    Fetch contract ABIs from Sourcify, Etherscan, and 4Byte Directory using the composite ABIInfoStorage pattern (.NET/C).

    2.3k GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check passed
  • Account Abstraction

    Nethereum/Nethereum

    Help users implement ERC-4337 Account Abstraction with Nethereum — send UserOperations, use smart accounts, route contract calls through a bundler, enable gasless transactions, or work with AA in…

    2.3k GitHub stars~1.7k tokensUpdated 6 days ago
    Auto-check passed
  • Address Utils

    Nethereum/Nethereum

    Validate and format Ethereum addresses with Nethereum. An agent skill from Nethereum/Nethereum.

    2.3k GitHub stars~1.2k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Social Recovery

What does Social Recovery do?

Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone. Social Recovery is an agent skill from Nethereum/Nethereum. Help users recover an ERC-4337 smart account after the owner key is lost, using an N-of-M guardian quorum — no single guardian can act alone.

When should I use Social Recovery?

Social Recovery fits situations like: the user mentions social recovery; guardian recovery; N-of-M guardians; lost my seed phrase / lost my wallet key.

How do I install Social Recovery in Claude Code?

Run `npx skills add Nethereum/Nethereum --skill social-recovery -a claude-code`. Or copy the skill folder (plugins/nethereum-skills/skills/social-recovery in Nethereum/Nethereum) into .claude/skills/social-recovery in your project. Claude Code loads it when a task matches its description.

How do I install Social Recovery in Codex?

Run `npx skills add Nethereum/Nethereum --skill social-recovery -a codex`. Or copy the skill folder (plugins/nethereum-skills/skills/social-recovery in Nethereum/Nethereum) into .agents/skills/social-recovery in your project. Codex loads it when a task matches its description.

Can I use Social Recovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Nethereum/Nethereum --skill social-recovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/social-recovery, .gemini/skills/social-recovery, .github/skills/social-recovery and .opencode/skills/social-recovery in your project.

What does Social Recovery need to run?

Going by SKILL.md and its folder, Social Recovery needs the command-line tools its instructions call (dotnet).

Does Social Recovery access the network?

SKILL.md names 1 domain. As links in the text: docs.nethereum.com. This is read from the text; nothing was executed.

Is Social Recovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Social Recovery use?

Social Recovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Social Recovery use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Social Recovery?

Skills that share tags, products or a category with Social Recovery: Tsp Csharp (querylenshq/ef-querylens, 225 stars), XML Documentation (Vonage/vonage-dotnet-sdk, 118 stars), Dotnet 10 Csharp 14 (sketch7/FluentlyHttpClient, 121 stars) and DisCatSharp Discord Development (Aiko-IT-Systems/DisCatSharp, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Social Recovery?

Nethereum (a GitHub organization) maintains it in Nethereum/Nethereum, which has 2,260 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on October 5, 2026.

Source: Nethereum/Nethereum on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.