31 Flaws Found in x402 Facilitators Covering 99% of Payments

A July 21 study identified 31 vulnerabilities across 15 x402 payment facilitators that handled 99% of observed transactions, exposing multiple attack paths against merchant payments.

A July 21 security study identified 31 previously unknown vulnerabilities across 15 payment facilitators that support x402, an HTTP-native standard for programmatic payments. The tested facilitators handled 99% of observed x402 transactions in the study window.

Researchers examined the shared middle layer of x402: the facilitators that verify signed payment proofs, construct and broadcast settlements, and often sponsor network fees. Merchants rely on facilitator responses to decide when to release a paid service. More than 93% of server addresses observed in the study were used exclusively by a single facilitator, indicating concentration in how settlements are routed.

The study mapped 49 violation instances to four attack classes: free-shopping, asset theft, service denial and gas abuse. Free-shopping occurs when a merchant accepts a service before a unique, settled payment exists. Asset-theft paths give attackers routes to facilitator-controlled value. Service denial covers settlements that fail or use excessive resources. Gas abuse leaves the facilitator paying excessive execution fees.

Researchers validated two free-shopping cases end to end and classified 10 additional free-shopping cases as high risk because losses would occur if a merchant released service after verification without waiting for settlement or without rolling back failures. The team reported one asset-theft path tied to ERC-6492 and produced a controlled proof of concept that induced a token approval but did not transfer tokens or steal funds. The study identified three gas-abuse instances.

All 15 facilitators showed high-risk service-denial or cost-amplification paths under the test rules. The researchers did not run a gas-drain experiment or availability-degrading load test and did not demonstrate an outage during their work.

A separate address-based analysis of more than 119 million transactions on Base and Solana covered Oct. 1 to Dec. 26, 2025. That analysis estimated about $202,000 in gas and fees during the period, including roughly $5,800 tied to reverted transactions.

The authors disclosed their findings to 14 of the 15 affected parties in January. By Feb. 6, three named firms-Coinbase, PayAI and Mogami-had collectively acknowledged six of the reported vulnerabilities and addressed some issues. The study anonymizes results and does not link specific fixes to particular vendors. The report notes some vulnerabilities remained under remediation at the time of disclosure.

To reduce exposure, the authors recommended tying verification to final settlement, reserving nonces to prevent reuse, rechecking time and account state before finalizing actions, and strictly allowlisting ERC-1271 and ERC-6492 transaction shapes. They also advised capping sponsored fees and rejecting payments that are uneconomic or cannot be settled. Merchants were urged to release service only after settlement succeeds or to implement explicit rollback procedures when settlement fails.

The study provides a detailed set of test rules and observed failures for the x402 facilitator model and documents specific instances where facilitator behavior could lead to premature service release, value extraction or increased transaction costs.

Articles by this author