Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy
Security flaws throughout main x402 cost facilitators may expose facilitator-held property and depart retailers with out receiving cost for companies supplied, based on new research introduced at the thirty fifth USENIX Security Symposium.
Researchers examined 15 main x402 facilitators, together with Coinbase, Thirdweb, PayAI and Mogami, and discovered that each platform violated a minimum of one security rule.
They mapped 49 rule violations to 31 distinct vulnerabilities throughout programs that accounted for 99% of noticed x402 transactions and 98% of cost quantity throughout the research.
The researchers recognized 4 broad assault lessons, together with free purchasing, asset theft, service disruption, and fuel abuse.
They immediately validated six assault paths beneath bounded circumstances, together with two free-shopping assaults, three gas-abuse assaults, and one path that might expose facilitator-held property.

The findings don’t imply that 99% of x402 transactions had been themselves weak. Rather, the paper stated the assaults may trigger “direct monetary loss to retailers, theft of facilitator-held property, unbounded sponsor-paid fuel/charges, and disruption of cost companies.”
The findings come as x402 is being promoted as infrastructure for machine-driven commerce, permitting web sites and APIs to request funds that software program and AI agents can complete autonomously. Facilitators sit between consumers and retailers, checking signed cost authorizations earlier than submitting transactions to blockchains.
That place provides facilitators vital management over settlement whereas additionally concentrating threat.
Facilitator funds may very well be uncovered
The most extreme assault path concerned ERC-6492, an Ethereum signature customary designed to assist signatures from smart-contract wallets that will not but have been deployed.
Researchers discovered that malicious metadata may trigger a facilitator to fund and submit an arbitrary token-approval transaction relatively than the cost it anticipated to settle.
The researchers stopped in need of shifting facilitator funds, however labeled the flaw as a direct path to asset theft as a result of an attacker may doubtlessly use that authority to approve transfers of property managed by the facilitator.
Three other validated assaults exploited the similar financial function that makes facilitators helpful to retailers: facilitators can sponsor blockchain transaction charges on their behalf.
Attackers may power affected implementations to pay for costly smart-contract deployment or initialization, shifting doubtlessly unbounded community prices onto the facilitator.
“If facilitators sponsor charges with out dependable reconciliation or chargeback, attacker-induced settlement can grow to be direct sponsor loss,” the researchers wrote.
That publicity is already seen in regular settlement exercise, although the research didn’t set up that historic failures had been malicious.
Researchers analyzed greater than 119 million x402 transactions throughout Base and Solana between Oct. 1 and Dec. 26, 2025. Facilitators spent about $202,000 on community charges, together with roughly $5,800 on Base transactions that in the end reverted or failed.
The failed transactions present the financial asymmetry built into sponsored settlement: a facilitator can incur blockchain prices even when the cost itself by no means completes.
Merchants can launch companies earlier than cost lands
A second group of flaws creates the reverse downside, shifting losses from facilitators to retailers. The researchers dubbed the assault “free purchasing.”
An x402 payment can cross an preliminary off-chain verification however nonetheless fail when submitted to the blockchain, together with as a result of an authorization has expired or the purchaser not has enough funds.
If a service provider releases an irreversible service instantly after verification, the purchaser can obtain the product although settlement later fails.
Researchers immediately validated two free-shopping assault paths and labeled one other 10 as high threat.
The downside prolonged past particular person facilitators to software program provided to retailers. All seven official Coinbase reference server kits examined by the researchers lacked specific mechanisms for reversing actions taken after a profitable verification.
In variations of Coinbase’s Flask package by 0.2.1, protected assets may very well be launched after verification no matter whether or not the subsequent settlement succeeded.
That design is very consequential for AI-driven commerce, the place autonomous software program could request and devour APIs, knowledge, or other digital companies inside seconds. McKinsey has estimated that AI brokers may mediate $3 trillion to $5 trillion of world client commerce by 2030.
Coinbase dominates a concentrated facilitator market
The potential blast radius is amplified by the focus of (*14*) throughout the researchers’ measurement window.
Coinbase was the largest facilitator by a large margin, processing 77.17 million transactions and practically $27 million in cost quantity.
Concentration additionally appeared on the service provider facet. More than 93% of the roughly 53,500 distinctive servers noticed in the research had been related to a single facilitator.
That construction creates a vulnerability, outage, or flawed software program assumption at one giant supplier that may have an effect on 1000’s of retailers relatively than stay remoted to a small implementation.
It additionally makes remediation uneven. Fixing a facilitator’s core service could not eradicate publicity if retailers proceed operating older software program improvement kits or launch merchandise earlier than settlement finality.
Fixes have began, however deployment stays unclear
The disclosures have prompted remediation by a few of the facilitators examined, although the public document doesn’t present how broadly these fixes have been utilized to reside x402 infrastructure.
The paper’s newest remediation replace, dated Feb. 6, stated Coinbase, PayAI and Mogami had collectively confirmed six vulnerabilities. Some had been fastened, whereas work continued on others.
The researchers didn’t publicly map particular person vulnerabilities to particular facilitators, making it troublesome to find out which suppliers had been uncovered to every assault or how broadly fixes have reached manufacturing programs.
Instead, they beneficial treating all client-provided transaction fields as untrusted, rechecking cost circumstances instantly earlier than settlement, and imposing strict limits on facilitator-sponsored fuel prices.
For retailers, the researchers beneficial withholding irreversible companies till settlement succeeds or sustaining a strategy to reverse actions when cost fails.
Those safeguards tackle the assault paths recognized in the research. Their effectiveness will rely on whether or not facilitators, SDK builders, and retailers deploy them persistently throughout an x402 market whose exercise is already concentrated amongst a small group of suppliers.
The put up Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy appeared first on CryptoSlate.
