A new security study found 31 vulnerabilities across Coinbase and 14 other x402 payment facilitators, raising concerns about asset exposure and payment failures as AI-driven commerce expands
Coinbase and 14 other leading x402 payment facilitators have failed to meet key security standards, according to research presented at the 35th USENIX Security Symposium. The study identified 31 distinct vulnerabilities across platforms that collectively processed 99% of observed x402 transactions and 98% of payment volume during the research period. These weaknesses could expose facilitator-held assets and leave merchants unpaid for services, especially as x402 infrastructure is positioned to support autonomous payments by AI agents and software.
Security Risks in x402 Payment Systems
The researchers tested 15 major x402 facilitators, including Coinbase, Thirdweb, PayAI, and Mogami, and found that every platform violated at least one security rule. They mapped 49 rule violations to 31 vulnerabilities, categorizing the main attack vectors as free shopping, asset theft, service disruption, and gas abuse. Six attack paths were directly validated, including scenarios where attackers could receive services without payment, force facilitators to pay excessive blockchain fees, or potentially gain approval to transfer facilitator-controlled assets.
One of the most severe vulnerabilities involved the ERC-6492 Ethereum signature standard, which is designed to support signatures from smart-contract wallets that may not yet exist on-chain. Malicious metadata could trick a facilitator into funding and submitting an arbitrary token-approval transaction, rather than the intended payment, potentially enabling asset theft. The researchers did not move any facilitator funds but classified this as a direct path to loss.
Merchant and Facilitator Exposure
Another set of flaws could allow buyers to receive irreversible services before payment is finalized on-chain. If a merchant releases a product or service immediately after off-chain verification, but the blockchain settlement later fails-due to expired authorization or insufficient buyer funds-the merchant may never be paid. The study validated two such "free shopping" attack paths and identified ten more as high risk. Notably, all seven official Coinbase reference server kits examined lacked explicit mechanisms to reverse actions if settlement failed, and versions of Coinbase's Flask kit through 0.2.1 allowed protected resources to be released after verification regardless of settlement outcome.
Facilitators are also at risk of incurring unbounded network costs. Because facilitators can sponsor blockchain transaction fees for merchants, attackers could exploit this feature to force payment of expensive smart-contract deployments or failed transactions. During the study window from October 1 to December 26, 2025, facilitators spent about $202,000 on network fees, including $5,800 on Base transactions that ultimately reverted or failed. This economic asymmetry means facilitators can lose funds even when payments do not complete.
Market Concentration and Remediation Challenges
The x402 facilitator market is highly concentrated. Coinbase alone processed 77.17 million transactions and nearly $27 million in payment volume during the study period. Over 93% of the roughly 53,500 unique servers observed were tied to a single facilitator, amplifying the potential impact of a vulnerability or outage. This concentration also complicates remediation, as fixing a facilitator's core service may not protect merchants still running outdated software or releasing services before payment finality.
Some facilitators have begun addressing the disclosed vulnerabilities. As of February 6, Coinbase, PayAI, and Mogami had confirmed six vulnerabilities, with some fixes implemented and others in progress. However, the researchers did not publicly map specific vulnerabilities to individual facilitators, making it difficult to assess the full scope of exposure or the reach of remediation efforts. They recommend treating all client-provided transaction fields as untrusted, rechecking payment conditions immediately before settlement, and imposing strict limits on facilitator-sponsored gas costs. For merchants, withholding irreversible services until settlement succeeds or maintaining a way to reverse actions is advised.
Security risks in payment infrastructure are not unique to x402. For example, the challenges of managing large crypto treasuries and counterparty risk have also been highlighted in other contexts, such as when Trump Media's Bitcoin holdings faced options risk and a looming $1 billion debt deadline.
According to the USENIX study, the effectiveness of these safeguards will depend on consistent deployment by facilitators, SDK developers, and merchants across the x402 ecosystem, which remains dominated by a small number of providers.
Across the October-December 2025 measurement window, researchers analyzed more than 119 million x402 transactions on Base and Solana. Facilitators collectively spent $202,000 on network fees, with $5,800 lost to failed or reverted Base transactions. Coinbase processed 77.17 million transactions and nearly $27 million in payment volume, underscoring its dominant role in the x402 facilitator market.
As x402 infrastructure becomes more central to AI-driven and automated commerce, the security and operational risks identified in this study highlight the need for robust settlement controls and careful management of both merchant and facilitator exposure. The concentration of market share among a handful of providers means that a single vulnerability or flawed assumption can have outsized effects, potentially impacting thousands of merchants and millions of transactions. For U.S. users and companies relying on these payment rails, understanding the technical and economic risks is essential as the ecosystem evolves.