Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

Security flaws across major x402 payment facilitators could expose facilitator-held assets and leave merchants without receiving payment for services provided, according to new research presented at the 35th USENIX Security Symposium.

Researchers tested 15 major x402 facilitators, including Coinbase, Thirdweb, PayAI and Mogami, and found that every platform violated at least one security rule.

They mapped 49 rule violations to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions and 98% of payment volume during the study.

The researchers identified four broad attack classes, including free shopping, asset theft, service disruption, and gas abuse.

They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.

Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy

The findings do not mean that 99% of x402 transactions were themselves vulnerable. Rather, the paper said the attacks could cause “direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services.”

The findings come as x402 is being promoted as infrastructure for machine-driven commerce, allowing websites and APIs to request payments that software and AI agents can complete autonomously. Facilitators sit between buyers and merchants, checking signed payment authorizations before submitting transactions to blockchains.

Can crypto protect us against the growing web of economic AI agents?
Related Reading

Can crypto protect us against the growing web of economic AI agents?

AI agents can talk, use tools, and pay — But crypto wants to control the escrow moment.
Mar 11, 2026
·
Gino Matos

That position gives facilitators significant control over settlement while also concentrating risk.

Facilitator funds could be exposed

The most severe attack path involved ERC-6492, an Ethereum signature standard designed to support signatures from smart-contract wallets that may not yet have been deployed.

Researchers found that malicious metadata could cause a facilitator to fund and submit an arbitrary token-approval transaction rather than the payment it expected to settle.

The researchers stopped short of moving facilitator funds, but classified the flaw as a direct path to asset theft because an attacker could potentially use that authority to approve transfers of assets controlled by the facilitator.

Three other validated attacks exploited the same economic feature that makes facilitators useful to merchants: facilitators can sponsor blockchain transaction fees on their behalf.

Attackers could force affected implementations to pay for expensive smart-contract deployment or initialization, shifting potentially unbounded network costs onto the facilitator.

“If facilitators sponsor fees without reliable reconciliation or chargeback, attacker-induced settlement can become direct sponsor loss,” the researchers wrote.

That exposure is already visible in normal settlement activity, even though the study did not establish that historical failures were malicious.

Researchers analyzed more than 119 million x402 transactions across Base and Solana between Oct. 1 and Dec. 26, 2025. Facilitators spent about $202,000 on network fees, including roughly $5,800 on Base transactions that ultimately reverted or failed.

The failed transactions show the economic asymmetry built into sponsored settlement: a facilitator can incur blockchain costs even when the payment itself never completes.

Merchants can release services before payment lands

A second group of flaws creates the opposite problem, shifting losses from facilitators to merchants. The researchers dubbed the attack “free shopping.”

An x402 payment can pass an initial off-chain verification but still fail when submitted to the blockchain, including because an authorization has expired or the buyer no longer has sufficient funds.

If a merchant releases an irreversible service immediately after verification, the buyer can receive the product even though settlement later fails.

Researchers directly validated two free-shopping attack paths and classified another 10 as high risk.

The problem extended beyond individual facilitators to software supplied to merchants. All seven official Coinbase reference server kits examined by the researchers lacked explicit mechanisms for reversing actions taken after a successful verification.

In versions of Coinbase’s Flask kit through 0.2.1, protected resources could be released after verification regardless of whether the subsequent settlement succeeded.

AI agents can now pay APIs with USDC in 200 ms as Coinbase activates x402 Bazaar
Related Reading

AI agents can now pay APIs with USDC in 200 ms as Coinbase activates x402 Bazaar

GENIUS Act and MiCA create the regulatory window for x402’s web-native rails.
Sep 10, 2025
·
Liam 'Akiba' Wright

That design is especially consequential for AI-driven commerce, where autonomous software may request and consume APIs, data, or other digital services within seconds. McKinsey has estimated that AI agents could mediate $3 trillion to $5 trillion of global consumer commerce by 2030.

Coinbase dominates a concentrated facilitator market

The potential blast radius is amplified by the concentration of x402 activity during the researchers’ measurement window.

Coinbase was the largest facilitator by a wide margin, processing 77.17 million transactions and nearly $27 million in payment volume.

Concentration also appeared on the merchant side. More than 93% of the roughly 53,500 unique servers observed in the study were associated with a single facilitator.

That structure creates a vulnerability, outage, or flawed software assumption at one large provider that can affect thousands of merchants rather than remain isolated to a small implementation.

It also makes remediation uneven. Fixing a facilitator’s core service may not eliminate exposure if merchants continue running older software development kits or release products before settlement finality.

Fixes have started, but deployment remains unclear

The disclosures have prompted remediation by some of the facilitators examined, though the public record does not show how widely those fixes have been applied to live x402 infrastructure.

The paper’s latest remediation update, dated Feb. 6, said Coinbase, PayAI and Mogami had collectively confirmed six vulnerabilities. Some had been fixed, while work continued on others.

The researchers did not publicly map individual vulnerabilities to specific facilitators, making it difficult to determine which providers were exposed to each attack or how broadly fixes have reached production systems.

Instead, they recommended treating all client-provided transaction fields as untrusted, rechecking payment conditions immediately before settlement, and imposing strict limits on facilitator-sponsored gas costs.

For merchants, the researchers recommended withholding irreversible services until settlement succeeds or maintaining a way to reverse actions when payment fails.

Those safeguards address the attack paths identified in the study. Their effectiveness will depend on whether facilitators, SDK developers, and merchants deploy them consistently across an x402 market whose activity is already concentrated among a small group of providers.

The post Coinbase and 14 other x402 facilitators failed security tests built for the coming AI-agent economy appeared first on CryptoSlate.

Read Entire Article


Add a comment