🤖 FiniPot AI Insights
The discovered vulnerabilities in X402 payment facilitators represent a significant systemic risk. The fact that the tested operators handle 99% of transactions means that widespread exploitation could lead to substantial financial losses for merchants through ‘free shopping’ and ‘asset theft.’ The reliance on a middle layer (facilitators) introduces a single point of failure. The recommendation to bind verification to settlement and implement rollbacks is critical for merchants to reduce their exposure. The ongoing fixes by some vendors are positive, but the existence of unaddressed vulnerabilities and unexploited high-risk paths means the ecosystem remains under threat.
Quick Summary
- A new study uncovered **31 previously unknown vulnerabilities** in 15 major X402 payment facilitators.
- These operators handle **99% of observed X402 transactions**, raising concerns about widespread asset theft and free shopping.
- Researchers identified risks like “free shopping” and “asset theft,” though not all paths were fully exploited.
A new security study has revealed **31 previously unknown vulnerabilities** impacting 15 key facilitators within the X402 payment standard. This HTTP-native system is designed for programmatic crypto payments, and the tested facilitators collectively handle **99% of all observed transactions**.
The findings, released on **July 27, 2026**, highlight a critical middle layer in the X402 ecosystem. These facilitators verify payment proofs, broadcast settlements, and often cover network fees. Merchants rely on their responses to release services, making any failure in this layer potentially far-reaching.
Researchers mapped **49 violation instances** across four attack categories: free shopping, asset theft, service denial, and gas abuse. The study validated two end-to-end “free shopping” scenarios, where merchants might release services before a payment has fully settled, effectively giving away goods or services for free. Another 10 were classified as high-risk due to reliance on merchant behavior post-verification.
While the study did not demonstrate a complete breach of any specific entity like Coinbase, nor did it exploit every possible attack vector, the implications are significant. Several instances of gas abuse were reported, and a path for ERC-6492 asset theft was identified, though no funds were ultimately stolen in the proof-of-concept tests.
All 15 facilitators showed vulnerabilities related to service denial or cost amplification. However, the researchers did not conduct full load tests to demonstrate outages or conduct extensive gas-draining experiments.
The findings were disclosed to **14 of the 15 affected parties in January**. As of **February 6**, Coinbase, PayAI, and Mogami had acknowledged six vulnerabilities, with some fixes in progress. The anonymized nature of the report means specific fixes cannot be attributed to individual vendors.
To mitigate these risks, authors of the study recommend that merchants strictly bind service release to successful settlement. They also advise implementing rollback procedures, reserving nonces, rechecking account states, and carefully allowing only specific transaction types. Capping sponsored fees and rejecting non-settleable payments are also key recommendations.
Critical Concern: Are My Crypto Payments Secure?
The study’s findings suggest that the current implementation of X402 payment facilitators, responsible for processing **99% of observed transactions**, may expose merchants to risks like asset theft and “free shopping.” While not all vulnerabilities were fully exploited, the identified weaknesses in the verification and settlement process warrant careful consideration by merchants and users of the X402 standard. Binding service release to confirmed settlement is a crucial step recommended to bolster security.

Leave a Reply