Research presented at the 35th USENIX Security Symposium found that 15 x402 payment facilitators, including Coinbase, Thirdweb, PayAI, and Mogami, violated at least one security rule. The systems account for 99% of observed transactions and may be exposed to attacks capable of causing direct losses to merchants, theft of facilitator assets, and abuse of network fees.
The study mapped 49 rule violations, consolidated into 31 vulnerabilities, and validated six attack paths. Among them are two forms of “free shopping,” three involving gas abuse, and one that can expose funds held by facilitators.
Risk of asset exposure
The most serious vulnerability involves the ERC-6492 standard, used for signatures from smart-contract wallets. According to the researchers, malicious metadata can trick a facilitator into sending an arbitrary token approval transaction instead of the expected payment. The flaw was classified as a direct path to asset theft.
The researchers also validated attacks that exploit facilitators’ ability to sponsor transaction fees on behalf of merchants. In these cases, an attacker can force the execution of expensive contract deployments, shifting potentially unlimited network costs to the facilitator.
Free shopping and Coinbase kits
Another group of flaws lets buyers receive products without paying. An x402 transaction can pass off-chain verification but fail to be confirmed on the blockchain, for example due to an expired authorization or insufficient funds. If a merchant releases an irreversible service immediately after verification, the buyer can end up with the product without paying.
The research notes that the seven official Coinbase server reference kits examined had no explicit mechanisms to reverse actions after successful verification. In versions of the Flask kit up to 0.2.1, protected resources could be released regardless of whether the payment was completed.
The analysis covered more than 119 million x402 transactions on the Base and Solana networks between October 1 and December 26, 2025. The facilitators spent about US$202,000 in network fees, including approximately US$5,800 in Base transactions that reverted or failed.
Coinbase was the largest facilitator, with 77.17 million transactions and nearly US$27 million in payment volume. More than 93% of the roughly 53,500 unique servers observed were associated with a single facilitator, which amplifies the impact of a flaw.
The researchers said that Coinbase, PayAI, and Mogami confirmed six vulnerabilities, with some already fixed and others in progress. The study did not publicly map which vulnerabilities affected each facilitator.
As recommendations, the researchers suggest treating all client-supplied transaction fields as untrusted, reassessing payment conditions immediately before settlement, and imposing strict limits on sponsored gas costs. For merchants, the guidance is to withhold irreversible services until payment confirmation or to maintain reversal mechanisms.


