A new security study reported 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, the native HTTP standard for programmatic payments. The tested group accounted for 99% of the transactions observed within the study period, and each facilitator failed to meet at least one of the eight rules regarding payment verification or settlement.
The full findings mapped 49 violation cases to four attack classes: free shopping, asset theft, denial of service, and gas abuse.
Facilitators are a shared middle layer. They verify clients’ signed payment proofs, structure and broadcast payments, and often sponsor network fees. The seller uses the response to decide when to release the protected service. More than 93% of the server addresses in this study were associated with only one facilitator.
This finding does not indicate that all x402 payments are vulnerable, that each facilitator is exploitable in any way, or that Coinbase has been compromised.
What the four attack classes have proven
In a free shopping attack, a merchant opens the door before a clean, unique payment has been completed. Theft of assets gives attackers a route to value controlled by intermediaries. Denial of service can cause payments to fail, resource-intensiveness can clog payment lanes, and gas abuse can cause intermediaries to pay for the attacker’s execution.
Researchers verified two free shopping cases end-to-end. They classified an additional 10 cases as high risk because the actual loss depended on whether the seller released the service after validation without waiting for settlement or rollback on failure.
The paper also reports three gas abuse cases and one ERC-6492 asset theft route. Although a controlled proof of concept resulted in token approval, the team did not make any subsequent transfers or steal any funds.


Although all 15 facilitators exhibited high-risk denial-of-service or cost-amplification paths, the researchers performed no outgassing experiments or load tests that reduced availability, and demonstrated no outages. Their separate address-based analysis covered more than 119 million transactions in Base and Solana and estimated approximately $202,000 in gas and fees from October 1 to December 26, 2025, including approximately $5,800 related to reversals.
Researchers disclosed their findings to 14 of the 15 affected parties in January. As of February 6th, Coinbase, PayAI, and Mogami had collectively acknowledged six vulnerabilities and fixed some issues, but others were still ongoing. The results are anonymized, so this paper does not specify which fixes belonged to each vendor.
CryptoSlate previously discussed x402’s facilitator model, discussed authorization constraints, and announced x402 integration through Proofivy.
The authors recommend that before merchants rely on x402 at scale, they tie validation to payments, reserve nonces, double-check time and account status, strictly allowlist ERC-1271 and ERC-6492 transaction types, cap sponsored fees, and reject uneconomic or non-settleable payments.
Merchants must release the service only after a successful payment or implement an explicit rollback. Open protocols still require hard controls around intermediaries that decide what can be done safely for a fee.



