|

31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping

Coinbase reveals x402 protocol to enable on-chain payments via HTTP

A brand new safety research reported 31 beforehand unknown vulnerabilities throughout 15 main facilitators supporting x402, an HTTP-native normal for programmatic payments. The examined group represented 99% of noticed transactions within the research window, and every facilitator failed at the very least one of eight guidelines for cost verification or settlement.

The full findings mapped 49 violation cases to 4 assault courses: free shopping, asset theft, service denial, and gasoline abuse.

Coinbase reveals x402 protocol to enable on-chain payments via HTTP
Related Reading

Coinbase reveals x402 protocol to enable on-chain payments via HTTP

The project allows real-world use cases such as per-play gaming models, per-inference AI services, and per-article paywalls for publishers.
May 6, 2025
·
Gino Matos

Facilitators are the shared center layer. They examine a consumer’s signed cost proof, assemble and broadcast settlement, and usually sponsor community charges; retailers use the response to determine when to launch a protected service. More than 93% of server addresses within the research have been related completely with one facilitator.

The findings don’t present that each x402 payment was susceptible, that every facilitator was exploitable in each method, or that Coinbase was breached.

What is x402? The HTTP-402 payments standard powering AI agents, explained
Related Reading

What is x402? The HTTP-402 payments standard powering AI agents, explained

Coinbase’s open protocol just hit V2. Here’s how x402 moves USDC over plain HTTP, what “facilitators” do, and why Solana/Base are leaning in.
Dec 18, 2025
·
Gino Matos

What the 4 assault courses proved

In a free-shopping assault, the service provider opens the door earlier than one clear, distinctive cost has settled. Asset theft offers an attacker a route to facilitator-controlled worth. Service denial jams the cost lane with failing or resource-hungry settlements, and gasoline abuse leaves the facilitator paying the attacker’s execution invoice.

Researchers validated two free-shopping circumstances finish to finish. They categorized 10 extra as high threat as a result of precise loss relied on a service provider releasing service after verification with out ready for settlement or rolling again a failure.

The paper additionally studies three gas-abuse cases and one ERC-6492 asset-theft path. A managed proof of idea induced a token approval, however the staff made no subsequent switch and stole no funds.

Tiny x402 payments expose the approval gap holding AI agents back
Related Reading

Tiny x402 payments expose the approval gap holding AI agents back

Artemis data shows crypto-native agentic payments are settling into millions of tiny x402 transactions, exactly the kind of automation the sector was built for.
May 27, 2026
·
Gino Matos

Infographic mapping the x402 facilitator payment flow, four attack classes, study evidence limits, measured transaction costs and recommended controls

All 15 facilitators confirmed high-risk service-denial or cost-amplification paths, however the researchers ran no gas-drain experiment or availability-degrading load take a look at and demonstrated no outage. Their separate address-based evaluation coated greater than 119 million Base and Solana transactions and estimated about $202,000 in gasoline and charges from Oct. 1 to Dec. 26, 2025, together with about $5,800 related to reverts.

The researchers disclosed findings to 14 of 15 affected events in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and mounted some points whereas others remained in progress. Because outcomes are anonymized, the paper doesn’t establish which particular repair belonged to every vendor.

CryptoSlate has previously explained x402’s facilitator model, coated its authorization constraints, and introduced an x402 integration through Proofivy.

Before retailers depend on x402 at higher scale, the authors suggest binding verification to settlement, reserving nonces, rechecking time and account state, strictly allowlisting ERC-1271 and ERC-6492 transaction shapes, capping sponsored charges, and rejecting uneconomic or non-settleable payments.

Merchants ought to launch service solely after settlement succeeds or implement specific rollback. An open protocol nonetheless wants exhausting controls across the middleman that decides what counts as paid and secure to execute.

The submit 31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping appeared first on CryptoSlate.

Similar Posts