A security study reported 31 previously unknown vulnerabilities across 15 major x402 payment facilitators that together handled 99% of the transactions it observed. Every facilitator failed at least one of eight rules for payment verification or settlement, and the paper mapped 49 violation instances to four attack classes. Coinbase, PayAI and Mogami have acknowledged six of the vulnerabilities.
A new security study reported 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, an HTTP-native standard for programmatic payments. The tested group represented 99% of observed transactions in the study window, and each facilitator failed at least one of eight rules for payment verification or settlement.
The full findings mapped 49 violation instances to four attack classes: free shopping, asset theft, service denial, and gas abuse. Facilitators are the shared middle layer — they check a client’s signed payment proof, construct and broadcast settlement, and often sponsor network fees. Merchants use the facilitator’s response to decide when to release a protected service.
Two free-shopping cases validated, 10 more rated high risk
Researchers validated two free-shopping cases end to end. They classified 10 more as high risk because actual loss depended on a merchant releasing service after verification without waiting for settlement or rolling back a failure.
The paper also reports three gas-abuse instances and one ERC-6492 asset-theft path. A controlled proof of concept induced a token approval, but the team made no subsequent transfer and stole no funds.
But the findings do not show that every x402 payment was vulnerable, that each facilitator was exploitable in every way, or that Coinbase was breached. All 15 facilitators showed high-risk service-denial or cost-amplification paths, yet the researchers ran no gas-drain experiment or availability-degrading load test and demonstrated no outage.
Address analysis estimated about $202,000 in gas and fees
A separate address-based analysis covered more than 119 million Base and Solana transactions and estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025. About $5,800 of that was associated with reverts.
Moreover, failures in this middle layer could affect many merchants. More than 93% of server addresses in the study were associated exclusively with one facilitator.
Three vendors acknowledged six vulnerabilities
The researchers disclosed findings to 14 of 15 affected parties in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues while others remained in progress. Because results are anonymized, the paper does not identify which specific fix belonged to each vendor.
Before merchants rely on x402 at greater scale, the authors recommend binding verification to settlement, reserving nonces, rechecking time and account state, strictly allowlisting ERC-1271 and ERC-6492 transaction shapes, capping sponsored fees, and rejecting uneconomic or non-settleable payments. Merchants should release service only after settlement succeeds or implement explicit rollback.
Sources:
Trading involves risk.