31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping

NewsMon, 27 Jul 2026 09:30:32 UTC11 hours ago
31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping

A new security study reported 31 previously unknown vulnerabilities across 15 major facilitators supporting x402, an HTTP-native standard for programmatic payments. The tested group represented 99% of observed transactions in the study window, and each facilitator failed at least one of eight rules for payment verification or settlement.

The full findings mapped 49 violation instances to four attack classes: free shopping, asset theft, service denial, and gas abuse.

Related Reading

Coinbase reveals x402 protocol to enable on-chain payments via HTTP

The project allows real-world use cases such as per-play gaming models, per-inference AI services, and per-article paywalls for publishers.
May 6, 2025 · Gino Matos

Facilitators are the shared middle layer. They check a client's signed payment proof, construct and broadcast settlement, and often sponsor network fees; merchants use the response to decide when to release a protected service. More than 93% of server addresses in the study were associated exclusively with one facilitator.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related