S&P 5007,798.99▲0.7% Nasdaq26,803.03▲0.8% Dow53,839.99▲0.1% Russell 2K3,052.85▲0.2% 10-Yr4.64%−4bp VIX14.63+0.08 WTI$81.19▼2.5% Gold$4,408.20▼0.0% EUR/USD1.153▼0.1% BTC$63,421▲0.0% Nikkei67,524▲0.8%
At close · Thu, Aug 13, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket Structurex402 payment facilitators show security flaws that cou…

x402 payment facilitators show security flaws that could impact merchants

A USENIX study tested 15 major x402 facilitators and found 49 rule violations tied to 31 vulnerabilities, including attack paths that could cause direct financial loss to merchants and potential asset theft by exploiting how facilitators handle transaction fees.

A new security study presented at the 35th USENIX Security Symposium found that major x402 payment facilitators, including Coinbase, Thirdweb, PayAI, and Mogami, failed security tests designed for the emerging AI agent economy.

Researchers tested 15 x402 facilitators and reported that every platform violated at least one security rule. Across the systems, they mapped 49 rule violations to 31 distinct vulnerabilities that they said covered 99% of observed x402 transactions and 98% of payment volume in the study.

The research identified four broad attack classes, including free shopping, asset theft, service disruption, and gas abuse. It also directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one route that could expose facilitator-held assets.

The most severe validated path involved ERC-6492, an Ethereum signature standard intended to support signatures from smart contract wallets. According to the paper, malicious metadata could lead a facilitator to submit an arbitrary token approval transaction instead of the payment it expected to settle, and the findings warned this could enable theft of assets controlled by the facilitator, even though researchers stopped short of moving facilitator funds. The paper also said x402 facilitators can sponsor blockchain transaction fees, and three other validated attacks exploited that same economic feature to potentially shift unbounded network costs.

The report said the findings do not mean that 99% of x402 transactions were themselves vulnerable, but that the attacks could still result in direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas and fees, and disruption of payment services, as x402 is promoted as infrastructure for machine driven commerce.

Latest closeEthereum $1,885.62 ▲0.4%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.