Security study finds 31 vulnerabilities in x402 crypto payment standard

Editorial illustration for: Security study finds 31 vulnerabilities exposing x402 crypto payments to theft and fraud

In brief

  • 31 vulnerabilities discovered across 15 x402 payment facilitators covering 99% of observed transactions
  • Researchers validated two free-shopping cases and mapped 49 violations to four attack classes
  • All 15 facilitators failed at least one of eight payment verification or settlement rules
  • Coinbase, PayAI, and Mogami acknowledged six vulnerabilities as of Feb. 6

Scope and findings

Each facilitator failed at least one of eight rules for payment verification or settlement. All 15 facilitators showed high-risk service-denial or cost-amplification paths. The paper reports three gas-abuse instances and one ERC-6492 asset-theft path.

Researchers covered more than 119 million Base and Solana transactions and estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025. About $5,800 of that total was associated with reverts. The scale of the analysis underscores how widely x402 has been adopted across major blockchain ecosystems.

Attack mechanics

In a free-shopping attack, the merchant opens the door before one clean, unique payment has settled. Asset theft gives an attacker a route to facilitator-controlled value. Researchers classified 10 free-shopping cases as high risk because actual loss depended on a merchant releasing service after verification without waiting for settlement or rolling back a failure.

The distinction matters. Not every transaction was vulnerable, and not every facilitator was exploitable in every way. The study does not show that Coinbase was breached.

Disclosure and remediation

Researchers disclosed findings to 14 of 15 affected parties in January. As of Feb. 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues while others remained in progress. The pace of remediation varies across the ecosystem, with some operators moving faster than others to patch the identified gaps.