31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping

1 hour ago 1



A new security study reported 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, an HTTP-native standard for programmatic payments. The tested group represented 99% of observed transactions in the study window, and each facilitator failed at least one of eight rules for payment verification or settlement.The full findings mapped 49 violation instances to four attack classes: free shopping, asset theft, service denial, and gas abuse.Facilitators are the shared middle layer. They check a client's signed payment proof, construct and broadcast settlement, and often sponsor network fees; merchants use the response to decide when to release a protected service. More than 93% of server addresses in the study were associated exclusively with one facilitator.The findings do not show that every x402 payment was vulnerable, that each facilitator was exploitable in every way, or that Coinbase was breached.What the four attack classes provedIn a free-shopping attack, the merchant opens the door before one clean, unique payment has settled. Asset theft gives an attacker a route to facilitator-controlled value. Service denial jams the payment lane with failing or ...

Read Entire Article