Report Identifies 31 Vulnerabilities in x402 Crypto Payment Stack
Key Takeaways
- •A security analysis has reported 31 vulnerabilities affecting the x402 payment stack for agent- and machine-driven crypto payments.
- •The available material does not confirm active exploitation, loss of funds, severity levels, or the scope of real-world exposure.
- •x402 is described as an open protocol for internet-native payments that can support software agents paying for web services without human approval at each step.
- •The issue is significant because companies including Coinbase have promoted AI agent payments as an emerging crypto use case.
- •Observers are awaiting official maintainer responses, remediation details, patch notes, and guidance for projects integrating x402.

A newly published report has identified 31 vulnerabilities affecting x402 crypto payments, a machine-friendly payment standard designed to allow software and AI agents to pay directly for online services. The findings come from a security analysis of the protocol and raise questions about the reliability of a payment flow being adopted for automated transactions.
The figure of 31 vulnerabilities comes from reporting on the newly disclosed research, which links the weaknesses to the x402 payment stack. This article describes what the research reports and does not independently verify any exploit, loss of funds, or real-world abuse. The underlying technical work is available as an academic report on arXiv. The x402 project’s official website describes the standard as an open protocol for internet-native payments.
The report says the affected area is the x402 payment stack used for agent- and machine-driven payments. However, the severity of the issues, the status of any remediation, and the extent of real-world exposure still require further confirmation from maintainers and integrators.
x402 is positioned as infrastructure for automated payments, including use cases in which software agents pay for web services without human intervention at each step. Companies including Coinbase have promoted the broader concept of AI agents using crypto payments, making the security of payment standards relevant to users, merchants, developers, and integration partners that rely on those rails to move value.
If exploitable, weaknesses in a payment flow used by software agents could affect how automated transactions are authorized, trusted, and settled. The report, however, does not confirm active exploitation or provide established severity tiers in the available material. Any practical consequences should therefore be treated as conditional until maintainers or affected projects publish more detailed guidance.
The issue is gaining attention as executives continue to frame agent-driven payments as a developing use case for crypto infrastructure. Coinbase CEO Brian Armstrong has argued separately that AI agents could out-transact humans using crypto, a scenario that would place greater economic weight on standards such as x402. Armstrong has also stated separately that AI will need crypto rather than replace it, underscoring why the safety of machine-readable payment rails is drawing scrutiny.
Security disclosures of this type are commonly followed by patches, coordinated disclosure updates, technical advisories, and statements from protocol maintainers or downstream integrators. The available material does not yet include confirmed mitigation steps, version-specific guidance, or a remediation timeline.
Observers tracking x402 should monitor official communications from the project, patch notes, and any follow-up audits or disclosures from teams integrating the standard. Until maintainers publish confirmed remediation details, the reported count of vulnerabilities should not be treated as a complete measure of operational risk. The most relevant next steps are official responses, technical fixes, deployment guidance, and clarification of whether any of the reported issues have affected live systems.