Security flaws across 15 major x402 payment facilitators could expose facilitator-held assets, leave merchants unpaid and saddle providers with unbounded blockchain fees, according to research presented at the 35th USENIX Security Symposium. The researchers found 49 rule violations mapping to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions and 98% of payment volume, and they directly validated six attack paths spanning free shopping, gas abuse and one route to potential asset theft. The most severe case involved ERC-6492 (Ethereum signature standard for undeployed smart-contract wallets), where malicious metadata could trick a facilitator into funding and submitting an arbitrary token approval instead of the intended payment, while merchant-side flaws allowed services to be released after off-chain verification even if on-chain settlement later failed. The study reviewed more than 119 million x402 transactions on Base and Solana between Oct. 1 and Dec. 26, 2025, found facilitators spent about $202,000 on network fees, and said concentration around Coinbase, which processed 77.17 million transactions and nearly $27 million in payment volume, could magnify the impact unless fixes and settlement safeguards are deployed consistently.