Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
31 Security Flaws Expose 99% of x402 Crypto Payments to Theft and Fraud

31 Security Flaws Expose 99% of x402 Crypto Payments to Theft and Fraud

CoineditionCoinedition2026/07/27 15:00
By:Coinedition

A security study has uncovered 31 previously unknown vulnerabilities across 15 facilitators supporting x402 payments. Together, those facilitators handled 99% of observed transactions and 98% of recorded volume.

However, the researchers did not claim that 99% of individual payments were exploited. Instead, the findings show that the tested services connected 60,000 sellers with 360,000 buyers, while every facilitator violated at least one security rule.

Notably, x402 adapts the internet’s HTTP 402 “Payment Required” response for websites, APIs, and autonomous software agents. Under this system, buyers submit signed payment proofs before gaining access to protected services.

Facilitators then verify those proofs, prepare blockchain transactions, and broadcast settlements on-chain. Because they often sponsor network fees, merchants can accept blockchain payments without maintaining their own infrastructure.

To assess the security of this process, researchers from EPFL, Zhejiang University, and an independent contributor developed x402Scope. The black-box testing system examined authorization controls, proof freshness, settlement safety, and transaction costs.

Their analysis identified 49 rule violations, which were grouped into 31 distinct vulnerabilities. These weaknesses fell into four attack classes: free shopping, asset theft, service denial, and gas abuse.

Free-shopping flaws could allow merchants to release services before payments settle successfully. Meanwhile, asset-theft paths may permit attacker-controlled instructions involving assets managed by facilitators.

Service-denial weaknesses can also cause repeated failures or resource-intensive transactions. In addition, gas-abuse attacks may leave facilitators responsible for excessive blockchain fees.

According to the study, researchers confirmed two free-shopping cases, three gas-abuse paths, and one limited ERC-6492 asset-theft scenario. However, the controlled theft test involved only a token approval, and no assets were transferred.

(adsbygoogle = window.adsbygoogle || []).push({});

To assess the broader cost exposure, the team reviewed 119 million Base and Solana transactions recorded between October 1 and December 26, 2025. Base registered 1.86 million reverted transactions, representing a 1.99% failure rate.

In comparison, Solana recorded 5,148 reverts, equal to just 0.018%. Across both networks, x402-related settlement attempts consumed more than $202,000 in transaction fees. Of that total, about $5,800 was linked to reverted submissions.

Nevertheless, researchers found no evidence proving that malicious activity caused those historical failures. The team disclosed its findings to 14 affected operators in January 2026. By February 6, Coinbase, PayAI, and Mogami had collectively acknowledged six vulnerabilities.

Although some weaknesses were fixed, others remained under review. Therefore, the researchers withheld vendor-specific mappings and technical exploit details, as several vulnerabilities had not yet been patched.

To reduce future risks, the paper recommended confirming settlement before delivering services. It also advised strict transaction allowlists, capped sponsored fees, nonce controls, deadline checks, and rejection of zero-value payments.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!