Loading market data...

Researchers Find 31 Vulnerabilities Across 15 x402 Payment Facilitators

Researchers Find 31 Vulnerabilities Across 15 x402 Payment Facilitators

A new study has uncovered 31 security vulnerabilities across 15 facilitators that support the x402 payment protocol — a system that handles nearly all observed transactions in the research window. Each of the 15 facilitators failed at least one of eight core rules for payment verification or settlement, opening the door to four distinct attack classes: free shopping, asset theft, service denial, and gas abuse.

Four Attack Classes Identified

Free-shopping attacks let merchants open a service before a payment settles. Asset theft gives attackers access to facilitator-controlled value. Service denial jams payment lanes, and gas abuse forces facilitators to pay the attacker's execution costs. Researchers validated two free-shopping cases end-to-end and flagged 10 more as high risk. They also reported three gas-abuse instances and one asset-theft path tied to the ERC-6492 standard.

A controlled proof of concept induced a token approval but no actual transfer or theft was executed. All 15 facilitators showed high-risk service-denial or cost-amplification paths, though researchers didn't run a gas-drain experiment or an availability-degrading load test. No outage was demonstrated.

The Cost of Vulnerabilities

An address-based analysis covering over 119 million Base and Solana transactions estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025. That includes roughly $5,800 associated with reverts — transactions that failed but still cost money. The figure doesn't represent stolen funds, but rather the operational waste attackers could exploit.

Vendor Responses

Findings were disclosed to 14 of the 15 affected parties in January. As of Feb. 6, Coinbase, PayAI, and Mogami had collectively acknowledged six vulnerabilities. Some have been fixed; others are still being worked on. The paper is anonymized, so it's not clear which fix belongs to which vendor.

The researchers stressed that the findings don't show every x402 payment was vulnerable, that each facilitator was exploitable in every way, or that Coinbase was breached.

What's Recommended

The study's recommendations include binding verification to settlement, reserving nonces, rechecking time and account state, strictly allowlisting ERC-1271 and ERC-6492 transaction shapes, capping sponsored fees, and rejecting uneconomic or non-settleable payments. Whether the remaining facilitators will patch before the next disclosure deadline remains an open question.