Security ETH SOL

x402 Payments Have a Problem—And Coinbase Knows It

2026-07-27

A security study just mapped out 31 previously unknown vulnerabilities in x402 payment infrastructure. This matters because the 15 tested facilitators collectively serve over 60,000 sellers and 360,000 buyers and account for 99% of observed x402 transactions. If this sounds niche, it won't be for long.

What is x402, anyway? It's the payment protocol emerging from autonomous AI agents that independently purchase access to online services. It extends HTTP 402 by delegating payment proof verification and on-chain settlement to third-party facilitators. Think of it as a middleman layer—and every middleman has weak points.

The research was brutal. Every single evaluated facilitator violated at least one security rule. Every rule was violated by at least one platform. That's not a bug here or there. That's systemic.

Researchers identified four attack classes. The dominant practical risks are sponsor-paid cost amplification and free shopping—where a merchant releases service before settlement completes. Asset theft allows attackers to redirect facilitator-controlled value. Service denial jams payment lanes with failing settlements. Gas abuse exploits facilitators that sponsor network fees, leaving them to absorb the attacker's execution costs.

The impact is real. A separate address-based analysis covering more than 119 million Base and Solana transactions estimated about $202,000 in gas and fees from October 1 to December 26, 2025, including about $5,800 associated with reverts. The ecosystem is already bleeding money through these holes.

The researchers weren't reckless. They responsibly disclosed everything to the respective maintainers—including Coinbase. As of early February 2026, Coinbase, PayAI, and Mogami collectively acknowledged six vulnerabilities. Some fixes are done. Others remain in progress.

On the proof-of-concept front, the team exercised restraint. They validated two free-shopping cases end to end and classified 10 more as high risk because actual loss depended on merchant behaviour. They also documented three gas-abuse instances and one ERC-6492 asset-theft path where they induced a token approval but made no transfer and stole no funds. Responsible disclosure. Hard not to respect that.

But restraint doesn't fix the underlying problem. The authors offered concrete recommendations: bind verification to settlement, reserve nonces, recheck time and account state, strictly allowlist ERC-1271 and ERC-6492 transaction shapes, cap sponsored fees, and reject uneconomic or non-settleable payments. Merchants should release service only after settlement succeeds or implement explicit rollback mechanisms if settlement fails.

The root issue is architectural. x402 delegates payment verification and settlement to third-party facilitators. This centralises trust and validation in one component. A single flaw can affect many services. As the ecosystem scales from millions to billions in transaction volume, these foundational gaps become critical.

Institutional adoption won't happen until this gets sorted. And it will happen. The infrastructure is too useful. But right now, x402 is running on borrowed time and a lot of other people's money.


Source & further reading:

Sources