
A security study found 31 vulnerabilities in 15 x402 facilitators. Researchers demonstrated free shopping and asset theft attacks. Coinbase, PayAI and Mogami acknowledged six flaws as of Feb. 6.
Alpha Score of 38 reflects weak overall profile with weak momentum, weak value, poor quality, strong sentiment.
A security study uncovered 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, an HTTP-native standard for programmatic payments. The tested group represented 99% of observed transactions in the study window. Each facilitator failed at least one of eight rules for payment verification or settlement.
The researchers mapped 49 violation instances to four attack classes: free shopping, asset theft, service denial, and gas abuse. They validated two free-shopping cases end to end. Ten more free-shopping cases were classified as high risk because actual loss depended on a merchant releasing service after verification without waiting for settlement or rolling back a failure.
Facilitators check a client's signed payment proof and broadcast settlement, often sponsoring network fees. Merchants use the response to decide when to release a protected service. More than 93% of server addresses in the study were associated exclusively with one facilitator.
The findings do not show that every x402 payment was vulnerable or that Coinbase was breached. Not every attack applied to every facilitator.
In a free-shopping attack, the merchant opens the door before one clean, unique payment has settled. Asset theft gives an attacker a route to facilitator-controlled value. Service denial jams the payment lane with failing or resource-hungry settlements. Gas abuse leaves the facilitator paying the attacker's execution bill.
The paper also reports three gas-abuse instances and one ERC-6492 asset-theft path. A controlled proof of concept induced a token approval. The team made no subsequent transfer and stole no funds.
All 15 facilitators showed high-risk service-denial or cost-amplification paths. The researchers ran no gas-drain experiment or availability-degrading load test and demonstrated no outage.
Their separate address-based analysis covered more than 119 million Base and Solana transactions and estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025, including about $5,800 associated with reverts.
The researchers disclosed findings to 14 of 15 affected parties in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues while others remained in progress. Because results are anonymized, the paper does not identify which specific fix belonged to each vendor.
Before merchants rely on x402 at greater scale, the authors recommend binding verification to settlement and rechecking time and account state, strictly allowlisting ERC-1271 and ERC-6492 transaction shapes, capping sponsored fees, and rejecting uneconomic or non-settleable payments.
Merchants should release service only after settlement succeeds or implement explicit rollback. An open protocol still needs hard controls around the intermediary that decides what counts as paid and safe to execute.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.