NewsCryptoStudy Finds 31 Vulnerabilities Across x402 Payment Facilitators

Study Finds 31 Vulnerabilities Across x402 Payment Facilitators

Author: CoinEdition·

Key Takeaways

  • •The tested facilitators handled 99% of observed x402 transactions and 98% of recorded volume across services linking 60,000 sellers with 360,000 buyers.
  • •Researchers identified 49 rule violations, consolidated into 31 vulnerabilities, and found that every tested facilitator breached at least one security rule.
  • •Confirmed cases included two free-shopping flaws, three gas-abuse paths, and one limited ERC-6492 asset-theft scenario involving token approval but no asset transfer.
  • •A review of 119 million Base and Solana transactions found more than $202,000 in x402-related settlement fees, including about $5,800 tied to reverted submissions.
  • •By February 6, Coinbase, PayAI, and Mogami had acknowledged six vulnerabilities collectively, while some fixes were completed and other issues remained under review.
Study Finds 31 Vulnerabilities Across x402 Payment Facilitators

A security study has identified 31 previously unknown vulnerabilities across 15 facilitators that support x402 payments, a system that adapts the internet’s HTTP 402 “Payment Required” response for websites, APIs, and autonomous software agents.

The researchers said the tested facilitators handled 99% of observed x402 transactions and 98% of recorded volume. They did not say that 99% of individual payments had been exploited. The study found that the services examined connected 60,000 sellers with 360,000 buyers, and that every facilitator violated at least one security rule.

Researchers from EPFL, Zhejiang University, and an independent contributor developed a black-box testing system called x402Scope to evaluate the payment process. The system examined authorization controls, proof freshness, settlement safety, and transaction costs.

Under x402, buyers submit signed payment proofs before receiving access to protected services. Facilitators verify those proofs, prepare blockchain transactions, and broadcast settlements on-chain. Because facilitators often sponsor network fees, merchants can accept blockchain payments without running their own blockchain infrastructure. That makes facilitators a shared trust layer for sellers and buyers using x402, so implementation weaknesses can affect more than a single merchant integration.

Vulnerabilities Covered Free Shopping, Theft Paths, Service Denial, and Gas Abuse

The study identified 49 rule violations, which were consolidated into 31 distinct vulnerabilities. The weaknesses were grouped into four attack classes: free shopping, asset theft, service denial, and gas abuse.

Free-shopping flaws could allow merchants to deliver services before a payment is successfully settled. Asset-theft paths could permit attacker-controlled instructions involving assets managed by facilitators. Service-denial weaknesses could trigger repeated failures or resource-intensive transactions. Gas-abuse attacks could leave facilitators paying excessive blockchain fees.

According to the paper, the researchers confirmed two free-shopping cases, three gas-abuse paths, and one limited ERC-6492 asset-theft scenario. The controlled theft test involved only a token approval, and no assets were transferred.

The findings were presented as systemwide security risks for x402 facilitators rather than evidence that all historical transactions were malicious or compromised.

Base and Solana Review Found Failed Settlements and Fee Exposure

To estimate broader cost exposure, the researchers reviewed 119 million Base and Solana transactions recorded between October 1 and December 26, 2025. Base had 1.86 million reverted transactions, a 1.99% failure rate. Solana recorded 5,148 reverts, equal to 0.018%.

Across the two networks, x402-related settlement attempts consumed more than $202,000 in transaction fees. About $5,800 of that amount was associated with reverted submissions. The researchers said they found no evidence proving that malicious activity caused those historical failures.

The team disclosed its findings to 14 affected operators in January 2026. By February 6, Coinbase, PayAI, and Mogami had collectively acknowledged six vulnerabilities. Some weaknesses had been fixed, while others remained under review.

Because several vulnerabilities had not yet been patched, the researchers withheld vendor-specific mappings and technical exploit details. Further operator acknowledgments, patches, and any later technical disclosures are the main items to watch as remediation continues.

The paper recommended several mitigations, including confirming settlement before delivering services, using strict transaction allowlists, capping sponsored fees, enforcing nonce controls, applying deadline checks, and rejecting zero-value payments.