Security Current Affairs

31 Vulnerabilities Expose Every x402 Payment Facilitator to Theft and Free Goods

2026-07-27

A systematic security audit of 15 real-world x402 payment facilitators—the infrastructure handling programmatic payments for AI agents and micro-transactions—uncovered 31 previously unknown vulnerabilities. These aren't theoretical gaps. They affect platforms collectively handling 99% of x402 transactions across over 60,000 sellers and 360,000 buyers. Every single evaluator violated at least one security rule, and every rule was violated by at least one platform. Flawless, this is not.

x402 extends HTTP 402 with a payment negotiation flow, delegating verification and settlement to third-party facilitators acting as shared infrastructure. One flaw in the middle layer affects everyone downstream. Facilitators check payment proofs, broadcast settlements, and often sponsor network fees. Merchants release protected services based on the facilitator's response. It's a centralised chokepoint.

Four distinct attack classes emerged. Free shopping exploits release-after-verify patterns lacking settlement-gated rollback. Asset theft primarily stems from underspecified contract-signature settlement semantics. Service denial happens when proofs verify but later fail, expire, or drain resources during settlement. Gas abuse reflects sponsored-cost ambiguity with insufficient bounds.

The practical risks? Sponsor-paid cost amplification and free goods rank as the dominant hazards. Asset theft occurs less frequently but carries the highest impact—researchers found cases in top-volume facilitators. The consequences are direct: financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas and fees, payment service disruption.

Researchers deliberately scoped the study to map practical risk whilst avoiding harm. They validated two free-shopping cases end-to-end and classified 10 more as high-risk using merchant behaviour patterns. Three gas-abuse instances and one ERC-6492 asset-theft path involving a proof-of-concept that induced token approval but made no transfer were documented. What they didn't do mattered too: no gas-drain experiments, no availability-degrading load tests, no demonstrated outages. All 15 facilitators showed high-risk service-denial or cost-amplification paths regardless.

The economics are already real. Analysis of 119 million Base and Solana transactions between October 1 and December 26, 2025, estimated about $202,000 in gas and fees, including roughly $5,800 from reverts. The protocol is scaling. Money is leaking.

Disclosure started in January. Researchers notified 14 of 15 affected parties. Maintainers acknowledged findings and provided mitigations—Coinbase among them. By February 6, fixes were underway, though anonymisation prevented specific patch attribution to individual vendors.

The ecosystem also revealed concentration risk. More than 93% of server addresses were associated exclusively with one facilitator. Dependency on a handful of intermediaries means any single vulnerability cascades across many merchants simultaneously.

Recommendations followed. For merchants: delay service release until settlement confirms. Facilitators need tighter controls over ERC-1271 and ERC-6492 transaction shapes, stricter fee caps, and rejection of uneconomic payments.

The authors acknowledged scope limits. The discovery doesn't mean every x402 payment was vulnerable or that each facilitator was fully exploitable. But 100% of tested platforms violated rules. As x402 moves from experimental to production use in AI-driven commerce, its security posture remains decidedly immature.


Source & further reading:

Sources