Safety flaws throughout main x402 fee facilitators may expose facilitator-held belongings and depart retailers with out receiving fee for companies supplied, in accordance with new analysis offered on the thirty fifth USENIX Safety Symposium.
Researchers examined 15 main x402 facilitators, together with Coinbase, Thirdweb, PayAI and Mogami, and located that each platform violated not less than one safety rule.
They mapped 49 rule violations to 31 distinct vulnerabilities throughout programs that accounted for 99% of noticed x402 transactions and 98% of fee quantity throughout the research.
The researchers recognized 4 broad assault lessons, together with free procuring, asset theft, service disruption, and gasoline abuse.
They instantly validated six assault paths below bounded situations, together with two free-shopping assaults, three gas-abuse assaults, and one path that would expose facilitator-held belongings.

The findings don’t imply that 99% of x402 transactions had been themselves weak. Somewhat, the paper stated the assaults may trigger “direct monetary loss to retailers, theft of facilitator-held belongings, unbounded sponsor-paid gasoline/charges, and disruption of fee companies.”
The findings come as x402 is being promoted as infrastructure for machine-driven commerce, permitting web sites and APIs to request funds that software program and AI brokers can full autonomously. Facilitators sit between consumers and retailers, checking signed fee authorizations earlier than submitting transactions to blockchains.
That place offers facilitators vital management over settlement whereas additionally concentrating danger.
Facilitator funds may very well be uncovered
Essentially the most extreme assault path concerned ERC-6492, an Ethereum signature customary designed to help signatures from smart-contract wallets that will not but have been deployed.
Researchers discovered that malicious metadata may trigger a facilitator to fund and submit an arbitrary token-approval transaction slightly than the fee it anticipated to settle.
The researchers stopped in need of shifting facilitator funds, however labeled the flaw as a direct path to asset theft as a result of an attacker may probably use that authority to approve transfers of belongings managed by the facilitator.
Three different validated assaults exploited the identical financial characteristic that makes facilitators helpful to retailers: facilitators can sponsor blockchain transaction charges on their behalf.
Attackers may power affected implementations to pay for costly smart-contract deployment or initialization, shifting probably unbounded community prices onto the facilitator.
“If facilitators sponsor charges with out dependable reconciliation or chargeback, attacker-induced settlement can turn out to be direct sponsor loss,” the researchers wrote.
That publicity is already seen in regular settlement exercise, though the research didn’t set up that historic failures had been malicious.
Researchers analyzed greater than 119 million x402 transactions throughout Base and Solana between Oct. 1 and Dec. 26, 2025. Facilitators spent about $202,000 on community charges, together with roughly $5,800 on Base transactions that finally reverted or failed.
The failed transactions present the financial asymmetry constructed into sponsored settlement: a facilitator can incur blockchain prices even when the fee itself by no means completes.
Retailers can launch companies earlier than fee lands
A second group of flaws creates the other drawback, shifting losses from facilitators to retailers. The researchers dubbed the assault “free procuring.”
An x402 fee can move an preliminary off-chain verification however nonetheless fail when submitted to the blockchain, together with as a result of an authorization has expired or the customer now not has enough funds.
If a service provider releases an irreversible service instantly after verification, the customer can obtain the product though settlement later fails.
Researchers instantly validated two free-shopping assault paths and labeled one other 10 as excessive danger.
The issue prolonged past particular person facilitators to software program provided to retailers. All seven official Coinbase reference server kits examined by the researchers lacked specific mechanisms for reversing actions taken after a profitable verification.
In variations of Coinbase’s Flask package by 0.2.1, protected assets may very well be launched after verification no matter whether or not the following settlement succeeded.
That design is particularly consequential for AI-driven commerce, the place autonomous software program could request and devour APIs, information, or different digital companies inside seconds. McKinsey has estimated that AI brokers may mediate $3 trillion to $5 trillion of worldwide client commerce by 2030.
Coinbase dominates a concentrated facilitator market
The potential blast radius is amplified by the focus of x402 exercise throughout the researchers’ measurement window.
Coinbase was the biggest facilitator by a large margin, processing 77.17 million transactions and practically $27 million in fee quantity.
Focus additionally appeared on the service provider facet. Greater than 93% of the roughly 53,500 distinctive servers noticed within the research had been related to a single facilitator.
That construction creates a vulnerability, outage, or flawed software program assumption at one massive supplier that may have an effect on 1000’s of retailers slightly than stay remoted to a small implementation.
It additionally makes remediation uneven. Fixing a facilitator’s core service could not get rid of publicity if retailers proceed operating older software program improvement kits or launch merchandise earlier than settlement finality.
Fixes have began, however deployment stays unclear
The disclosures have prompted remediation by a number of the facilitators examined, although the general public file doesn’t present how extensively these fixes have been utilized to stay x402 infrastructure.
The paper’s newest remediation replace, dated Feb. 6, stated Coinbase, PayAI and Mogami had collectively confirmed six vulnerabilities. Some had been fastened, whereas work continued on others.
The researchers didn’t publicly map particular person vulnerabilities to particular facilitators, making it tough to find out which suppliers had been uncovered to every assault or how broadly fixes have reached manufacturing programs.
As an alternative, they really useful treating all client-provided transaction fields as untrusted, rechecking fee situations instantly earlier than settlement, and imposing strict limits on facilitator-sponsored gasoline prices.
For retailers, the researchers really useful withholding irreversible companies till settlement succeeds or sustaining a solution to reverse actions when fee fails.
These safeguards deal with the assault paths recognized within the research. Their effectiveness will rely upon whether or not facilitators, SDK builders, and retailers deploy them persistently throughout an x402 market whose exercise is already concentrated amongst a small group of suppliers.





