31 newly discovered vulnerabilities expose 99% of x402 crypto payments to asset theft and free shopping
A security study found 31 previously unknown vulnerabilities across 15 major x402 facilitators, covering about 99% of observed transactions. All 15 failed at least one of eight payment-verification or settlement rules, producing 49 violation instances across four attack types: free shopping, asset theft, service denial, and gas abuse. Facilitators act as the middle layer that verifies signed payment proofs, broadcasts settlement, and often sponsors network fees. More than 93% of server addresses in the study were tied to a single facilitator. Two free-shopping cases were demonstrated end to end, and 10 more were judged high risk if merchants release service before settlement finality. The study also reported three gas-abuse cases and one ERC-6492 asset-theft path, though no funds were stolen in the proof of concept. No outage test was run, but all facilitators had high-risk denial or cost-amplification paths. Researchers estimated about $202,000 in gas and fees from Oct. 1 to Dec. 26, 2025, including about $5,800 from reverts. Recommended defenses include tying verification to settlement, reserving nonces, rechecking time and account state, strict ERC-1271/ERC-6492 allowlisting, fee caps, and rejecting uneconomic or non-settleable payments.
