Security study finds 31 vulnerabilities across 15 x402 payment facilitators

Researchers found all tested providers breached payment verification or settlement rules, while Coinbase and PayAI acknowledged issues and merchants were urged to wait for final settlement.

SOL

Summary

A security study identified 31 previously unknown vulnerabilities across 15 major facilitators used by x402, an HTTP-native standard for programmatic payments, with the tested group accounting for 99% of observed transactions during the study window. Researchers said every facilitator failed at least one of eight rules tied to payment verification or settlement, and mapped 49 violation instances into four attack classes: free shopping, asset theft, service denial, and gas abuse. The paper said the findings do not mean every x402 payment was vulnerable, every facilitator was exploitable in every way, or that Coinbase was breached. Facilitators act as the middle layer in x402, checking a client’s signed payment proof, constructing and broadcasting settlement, and often sponsoring network fees so merchants can decide when to release a protected service. The study said more than 93% of server addresses it examined were associated exclusively with one facilitator, underscoring how much trust is concentrated in that layer. Researchers validated two free-shopping cases end to end and flagged 10 more as high risk, depending on whether a merchant released service after verification without waiting for settlement or failed to roll back when settlement failed. The paper also reported three gas-abuse cases and one ERC-6492 asset-theft path. In that proof of concept, the team induced a token approval but made no transfer and stole no funds. All 15 facilitators showed high-risk service-denial or cost-amplification paths, although the researchers said they did not run a gas-drain experiment or an availability-degrading load test and showed no outage. A separate address-based review covered more than 119 million Base and Solana transactions and estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025, including roughly $5,800 linked to reverts. The researchers disclosed the issues to 14 of the 15 affected parties in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues, while others were still being addressed. The authors said merchants should tie verification directly to settlement, reserve nonces, recheck time and account state, strictly allowlist ERC-1271 and ERC-6492 transaction shapes, cap sponsored fees, and reject uneconomic or non-settleable payments. They also urged merchants not to rely only on pre-verification and to provide services only after final settlement is confirmed or implement explicit rollback logic.

Terms & Concepts
  • x402: HTTP-native standard for programmatic payments
  • ERC-6492: Standard for validating signatures before deployment
  • nonce: Unique transaction value used once