Crypto
Home›Crypto›Market Structure›Study finds 31 vulnerabilities in x402 payment facilit…
Study finds 31 vulnerabilities in x402 payment facilitators
Researchers mapped 49 rule-violation instances across four attack classes, including free shopping and asset theft, and said the tested facilitators covered 99% of observed x402 transactions in the study window.
A new security study identified 31 previously unknown vulnerabilities across 15 major facilitators that support x402, an HTTP-native standard for programmatic crypto payments, according to CryptoSlate. The researchers said the tested group accounted for 99% of observed transactions during the study window.
The report describes facilitators as a shared middle layer that verifies a client’s signed payment proof, constructs and broadcasts settlement, and often sponsors network fees, while merchants use the facilitator response to decide when to release protected services. It found each facilitator failed at least one of eight payment verification or settlement rules, and it mapped 49 violation instances to four attack classes.
Those attack classes include free shopping, where a merchant opens access after one clean payment without waiting for settlement, and asset theft, where an attacker gains a route to facilitator-controlled value. The study also covered service denial, which jams payment lanes with failing or resource-hungry settlements, and gas abuse, where the facilitator pays the attacker’s execution bill.
The researchers validated two free-shopping cases end to end, and categorized 10 additional cases as high risk, saying actual loss depended on a merchant releasing service after verification without waiting for settlement or rolling back failures. They also reported three gas-abuse instances and one ERC-6492 asset-theft path, and estimated gas and fees of about $202,000 from Oct. 1 to Dec. 26, 2025, including about $5,800 tied to reverts, per the study described by CryptoSlate.