31 Security Flaws Expose 99% of x402 Crypto Payments to Theft and Fraud

31 Security Flaws Expose 99% of x402 Crypto Payments to Theft and Fraud

Last Updated:
31 Security Flaws Expose 99% of x402 Crypto Payments to Theft and Fraud
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Researchers found 31 flaws across 15 facilitators handling 99% of observed x402 payments.
  • Confirmed tests exposed free shopping, gas abuse, and a limited ERC-6492 theft path.
  • More than $202,000 in fees were tied to x402 settlements across Base and Solana.

A security study has uncovered 31 previously unknown vulnerabilities across 15 facilitators supporting x402 payments. Together, those facilitators handled 99% of observed transactions and 98% of recorded volume.

However, the researchers did not claim that 99% of individual payments were exploited. Instead, the findings show that the tested services connected 60,000 sellers with 360,000 buyers, while every facilitator violated at least one security rule.

Facilitator Flaws Create a Systemwide x402 Security Risk

Notably, x402 adapts the internet’s HTTP 402 “Payment Required” response for websites, APIs, and autonomous software agents. Under this system, buyers submit signed payment proofs before gaining access to protected services.

Facilitators then verify those proofs, prepare blockchain transactions, and broadcast settlements on-chain. Because they often sponsor network fees, merchants can accept blockchain payments without maintaining their own infrastructure.

To assess the security of this process, researchers from EPFL, Zhejiang University, and an independent contributor developed x402Scope. The black-box testing system examined authorization controls, proof freshness, settlement safety, and transaction costs.

Their analysis identified 49 rule violations, which were grouped into 31 distinct vulnerabilities. These weaknesses fell into four attack classes: free shopping, asset theft, service denial, and gas abuse.

Free-shopping flaws could allow merchants to release services before payments settle successfully. Meanwhile, asset-theft paths may permit attacker-controlled instructions involving assets managed by facilitators.

Service-denial weaknesses can also cause repeated failures or resource-intensive transactions. In addition, gas-abuse attacks may leave facilitators responsible for excessive blockchain fees.

According to the study, researchers confirmed two free-shopping cases, three gas-abuse paths, and one limited ERC-6492 asset-theft scenario. However, the controlled theft test involved only a token approval, and no assets were transferred.

On-chain Data Reveals Failed Settlements and Rising Fee Exposure

To assess the broader cost exposure, the team reviewed 119 million Base and Solana transactions recorded between October 1 and December 26, 2025. Base registered 1.86 million reverted transactions, representing a 1.99% failure rate.

In comparison, Solana recorded 5,148 reverts, equal to just 0.018%. Across both networks, x402-related settlement attempts consumed more than $202,000 in transaction fees. Of that total, about $5,800 was linked to reverted submissions.

Nevertheless, researchers found no evidence proving that malicious activity caused those historical failures. The team disclosed its findings to 14 affected operators in January 2026. By February 6, Coinbase, PayAI, and Mogami had collectively acknowledged six vulnerabilities.

Although some weaknesses were fixed, others remained under review. Therefore, the researchers withheld vendor-specific mappings and technical exploit details, as several vulnerabilities had not yet been patched.

To reduce future risks, the paper recommended confirming settlement before delivering services. It also advised strict transaction allowlists, capped sponsored fees, nonce controls, deadline checks, and rejection of zero-value payments.

Related: Ledger Exposes Potential Security Flaw in Trezor Wallets

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.