31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping

The 15 operators covered 99% of observed transactions, with two free-shopping cases validated and other high-impact tests deliberately bounded.

Mixed-media editorial collage showing a damaged blue x402 pipeline spilling payment tokens beside a watchful eye, shopping cart warning, and broken security lock.
Image by CryptoSlate
2 min read

Quick Take

  1. A July 21 study found 31 previously unknown vulnerabilities across 15 x402 payment facilitators.
  2. The tested operators handled 99% of observed transactions, so failures in this middle layer could affect many merchants.
  3. Other high-risk paths were not fully exercised, leaving open whether merchants can safely rely on verification before settlement.

A new security study reported 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, an HTTP-native standard for programmatic payments. The tested group represented 99% of observed transactions in the study window, and each facilitator failed at least one of eight rules for payment verification or settlement.

The full findings mapped 49 violation instances to four attack classes: free shopping, asset theft, service denial, and gas abuse.

Coinbase reveals x402 protocol to enable on-chain payments via HTTP
Related Reading

Coinbase reveals x402 protocol to enable on-chain payments via HTTP

The project allows real-world use cases such as per-play gaming models, per-inference AI services, and per-article paywalls for publishers.
May 6, 2025 · Gino Matos

Facilitators are the shared middle layer. They check a client's signed payment proof, construct and broadcast settlement, and often sponsor network fees; merchants use the response to decide when to release a protected service. More than 93% of server addresses in the study were associated exclusively with one facilitator.

The findings do not show that every x402 payment was vulnerable, that each facilitator was exploitable in every way, or that Coinbase was breached.

What is x402? The HTTP-402 payments standard powering AI agents, explained
Related Reading

What is x402? The HTTP-402 payments standard powering AI agents, explained

Coinbase’s open protocol just hit V2. Here’s how x402 moves USDC over plain HTTP, what “facilitators” do, and why Solana/Base are leaning in.
Dec 18, 2025 · Gino Matos

What the four attack classes proved

In a free-shopping attack, the merchant opens the door before one clean, unique payment has settled. Asset theft gives an attacker a route to facilitator-controlled value. Service denial jams the payment lane with failing or resource-hungry settlements, and gas abuse leaves the facilitator paying the attacker’s execution bill.

Researchers validated two free-shopping cases end to end. They classified 10 more as high risk because actual loss depended on a merchant releasing service after verification without waiting for settlement or rolling back a failure.

The paper also reports three gas-abuse instances and one ERC-6492 asset-theft path. A controlled proof of concept induced a token approval, but the team made no subsequent transfer and stole no funds.

Tiny x402 payments expose the approval gap holding AI agents back
Related Reading

Tiny x402 payments expose the approval gap holding AI agents back

Artemis data shows crypto-native agentic payments are settling into millions of tiny x402 transactions, exactly the kind of automation the sector was built for.
May 27, 2026 · Gino Matos

Infographic mapping the x402 facilitator payment flow, four attack classes, study evidence limits, measured transaction costs and recommended controls

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

You’re subscribed. Welcome aboard.

All 15 facilitators showed high-risk service-denial or cost-amplification paths, but the researchers ran no gas-drain experiment or availability-degrading load test and demonstrated no outage. Their separate address-based analysis covered more than 119 million Base and Solana transactions and estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025, including about $5,800 associated with reverts.

The researchers disclosed findings to 14 of 15 affected parties in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues while others remained in progress. Because results are anonymized, the paper does not identify which specific fix belonged to each vendor.

CryptoSlate has previously explained x402's facilitator model, covered its authorization constraints, and announced an x402 integration through Proofivy.

Before merchants rely on x402 at greater scale, the authors recommend binding verification to settlement, reserving nonces, rechecking time and account state, strictly allowlisting ERC-1271 and ERC-6492 transaction shapes, capping sponsored fees, and rejecting uneconomic or non-settleable payments.

Merchants should release service only after settlement succeeds or implement explicit rollback. An open protocol still needs hard controls around the intermediary that decides what counts as paid and safe to execute.