Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

1 week ago 17



Security flaws across major x402 payment facilitators could expose facilitator-held assets and leave merchants without receiving payment for services provided, according to new research presented at the 35th USENIX Security Symposium.Researchers tested 15 major x402 facilitators, including Coinbase, Thirdweb, PayAI and Mogami, and found that every platform violated at least one security rule.They mapped 49 rule violations to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions and 98% of payment volume during the study.The researchers identified four broad attack classes, including free shopping, asset theft, service disruption, and gas abuse.They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.The findings do not mean that 99% of x402 transactions were themselves vulnerable. Rather, the paper said the attacks could cause “direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services.”The findings come as x402 is being promoted as infra...

Read Entire Article