Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

by

Security flaws across major x402 payment facilitators could expose facilitator-held assets and leave merchants without receiving payment for services provided, according to new research presented at the 35th USENIX Security Symposium.

Researchers tested 15 major x402 facilitators, including Coinbase, Thirdweb, PayAI and Mogami, and found that every platform violated at least one security rule.

They mapped 49 rule violations to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions and 98% of payment volume during the study.

The researchers identified four broad attack classes, including free shopping, asset theft, service disruption, and gas abuse.

They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.

Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

The findings do not mean that 99% of x402 transactions were themselves vulnerable. Rather, the paper said the attacks could cause “direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services.”

The findings come as x402 is being promoted as infrastructure for machine-driven commerce, allowing websites and APIs to request payments that software and AI agents can complete autonomously. Facilitators sit between buyers and merchants, checking signed payment authorizations before submitting transactions to blockchains.

Can crypto protect us against the growing web of economic AI agents?
Related Reading

Can crypto protect us against the growing web of economic AI agents?

AI agents can talk, use tools, and pay — But crypto wants to control the escrow moment.

Mar 11, 2026 · Gino Matos

That position gives facilitators significant control over settlement while also concentrating risk.

Facilitator funds could be exposed

The most severe attack path involved ERC-6492, an Ethereum signature standard designed to support signatures from smart-contract wallets that may not yet have been deployed.

Researchers found that malicious metadata could cause a facilitator to fund and submit an arbitrary token-approval transaction rather than the payment it expected to settle.

The researchers stopped short of moving facilitator funds, but classified the flaw as a direct path to asset theft because an attacker could potentially use that authority to approve transfers of assets controlled by the facilitator.

Three other validated attacks exploited the same economic feature that makes facilitators useful to merchants: facilitators can sponsor blockchain transaction fees on their behalf.

Attackers could force affected implementations to pay for expensive smart-contract deployment or initialization, shifting potentially unbounded network costs onto the facilitator.

“If facilitators sponsor fees without reliable reconciliation or chargeback, attacker-induced settlement can become direct sponsor loss,” the researchers wrote.

That exposure is already visible in normal settlement activity, even though the study did not establish that historical failures were malicious.

Researchers analyzed more than 119 million x402 transactions across Base and Solana between Oct. 1 and Dec. 26, 2025. Facilitators spent about $202,000 on network fees, including roughly $5,800 on Base transactions that ultimately reverted or failed.

The failed transactions show the economic asymmetry built into sponsored settlement: a facilitator can incur blockchain costs even when the payment itself never completes.

Merchants can release services before payment lands

A second group of flaws creates the opposite problem, shifting losses from facilitators to merchants. The researchers dubbed the attack “free shopping.”

An x402 payment can pass an initial off-chain verification but still fail when submitted to the blockchain, including because an authorization has expired or the buyer no longer has sufficient funds.

If a merchant releases an irreversible service immediately after verification, the buyer can receive the product even though settlement later fails.

Researchers directly validated two free-shopping attack paths and classified another 10 as high risk.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.