When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments

📅 2026-07-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses critical security vulnerabilities in the x402 payment protocol, which relies on centralized third-party coordinators and consequently suffers from flaws in authorization correctness and execution safety, posing systemic risks. We present the first systematic security analysis of real-world x402 deployments, establishing eight essential security rules and uncovering four novel attack vectors—including Free Shopping and Asset Theft. To scalably detect violations, we develop a semi-automated black-box methodology integrating smart contract audits with cross-chain transaction analysis on Base and Solana. Applying this approach to 15 prominent coordinators, we identify rule violations affecting over 60,000 merchants and 360,000 buyers. Our findings have prompted remediation efforts by major vendors such as Coinbase and provide the first quantitative assessment of the security risks inherent in ecosystem centralization.
📝 Abstract
x402 is an emerging payment protocol for Web APIs and autonomous AI agents. x402 extends HTTP 402 with a payment negotiation flow and delegates payment proof verification and on-chain settlement to third-party facilitators. As a result, facilitators serve as a shared payment infrastructure for many independent merchants. This centralizes trust and validation in one component, so a single flaw can affect many services. Despite rapid adoption by major vendors and economically meaningful mainnet activity, the security posture of real-world x402 deployments remains poorly characterized. We present the first systematic study of authorization correctness and execution safety in current facilitator-mediated x402 deployments in the wild, identifying eight security rules for facilitators as critical payment infrastructure. Based on our analysis of rule violations, we derive four new attack vectors, including Free Shopping, Asset Theft, Service Denial, and Gas Abuse. These attacks exploit weaknesses in the real-world facilitator and server implementations and cause severe harm, including direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services. To assess the security of x402 deployments at scale, we propose a semi-automated black-box tool and apply it to 15 major x402 facilitators collectively used by over 60K sellers and 360K buyers. Alarmingly, we find violations in all evaluated facilitators. We responsibly disclosed our findings to the affected parties, who acknowledged the issues and adopted mitigations, including changes by Coinbase. Finally, we complement our controlled testing with an empirical measurement of over 119 million recent Base and Solana transactions, quantifying x402 adoption, facilitator centralization, and ecosystem-level risk indicators.
Problem

Research questions and friction points this paper is trying to address.

x402
payment security
facilitator centralization
HTTP 402
blockchain payments
Innovation

Methods, ideas, or system contributions that make the work stand out.

x402
payment protocol security
facilitator-mediated payments
blockchain payment attacks
black-box security analysis
🔎 Similar Papers
No similar papers found.