Security Current Affairs

31 Critical Flaws Found in x402 Payment Infrastructure That Handles 99% of Transactions

2026-07-27

A security study just dropped findings that should worry anyone relying on x402 payment facilitators. Researchers uncovered 31 previously unknown vulnerabilities across 15 platforms that collectively handle 99% of observed transactions. These facilitators serve over 60,000 sellers and 360,000 buyers. That's a lot of people potentially exposed.

x402 extends HTTP 402 with a payment negotiation flow, delegating payment proof verification and on-chain settlement to third-party facilitators. These middlemen act as shared payment infrastructure for independent merchants. The problem is obvious: centralize trust in one component, and a single flaw breaks everything downstream. Every single evaluated facilitator violated at least one security rule. All eight rules tested were broken by at least one platform.

The main attack vectors? Free shopping, asset theft, service denial, and gas abuse. Free-shopping attacks let merchants release services before on-chain payment settles. Asset theft exploits facilitators holding collateral or managing permissioned transfers. Service denial happens when payments verify but fail during settlement. Gas abuse drains sponsored fee budgets.

The dominant practical risks were sponsor-paid cost amplification and free shopping. Asset theft was less frequent but carried the highest impact, showing up in top-volume facilitators. The researchers built a semi-automated black-box testing tool and applied it to 15 major facilitators. They responsibly disclosed findings to maintainers. Coinbase acknowledged the findings and provided mitigations, as did other affected parties.

The researchers intentionally limited testing scope. They validated two free-shopping cases end-to-end with consistent freshness and replay enforcement gaps. But they explicitly ran no gas-drain experiments, availability-degrading load tests, or outage demonstrations. The security research was genuine; the restraint was real.

Large-scale measurement of 119 million x402-related transactions on Base and Solana added crucial context. From October 1 to December 26, 2025, the ecosystem burned approximately $202,000 in gas and fees. About $5,800 came from transaction reversions. Coinbase dominated both dimensions: 77.17 million transactions and $26.85 million in payment volume. Concentration risk at that scale is dangerous. Policy changes or security issues at Coinbase could crater huge portions of the ecosystem.

The protocol's real weakness is architectural. x402 spans multiple parties, layers, proof formats, and signature models. That creates a massive validation surface. End-to-end atomicity and cost bounding become nightmarishly difficult in practice. Researchers have already documented replay, front-running, and grant-before-settle attacks across x402 SDKs. A signature-verification bypass was disclosed in March 2026.

Before this protocol scales further, the researchers recommend merchants bind verification to settlement, reserve nonces, recheck time and account state, strictly allowlist ERC-1271 and ERC-6492 transaction shapes, cap sponsored fees, and reject uneconomic or non-settleable payments. Release service only after settlement succeeds or implement explicit rollback.

Eight critical security rules emerged: facilitators are payment infrastructure where decisions about what counts as paid determine safety. Hard controls around the intermediary are non-negotiable.

As adoption accelerates among AI agents and API services, these gaps need fixing before the protocol becomes systemically important to internet micropayments. Right now it's still avoidable. Soon it won't be.


Source & further reading:

Sources