Search papers, labs, and topics across Lattice.
This paper systematically analyzes the security of the emerging x402 payment protocol, which extends HTTP 402 for Web APIs and autonomous AI agents by introducing a payment negotiation flow and third-party facilitators for payment verification. The authors identify critical security rules for these facilitators and uncover four new attack vectors鈥擣ree Shopping, Asset Theft, Service Denial, and Gas Abuse鈥攖hat exploit real-world implementation weaknesses, leading to significant financial risks for merchants and users. Their findings, derived from testing 15 major facilitators and analyzing over 119 million transactions, reveal that all evaluated facilitators exhibit security violations, prompting responsible disclosures and subsequent mitigations by affected parties like Coinbase.
All 15 evaluated x402 facilitators have critical security flaws that could lead to severe financial losses for merchants and users alike.
x402 is an emerging payment protocol for Web APIs and autonomous AI agents. x402 extends HTTP 402 with a payment negotiation flow and delegates payment proof verification and on-chain settlement to third-party facilitators. As a result, facilitators serve as a shared payment infrastructure for many independent merchants. This centralizes trust and validation in one component, so a single flaw can affect many services. Despite rapid adoption by major vendors and economically meaningful mainnet activity, the security posture of real-world x402 deployments remains poorly characterized. We present the first systematic study of authorization correctness and execution safety in current facilitator-mediated x402 deployments in the wild, identifying eight security rules for facilitators as critical payment infrastructure. Based on our analysis of rule violations, we derive four new attack vectors, including Free Shopping, Asset Theft, Service Denial, and Gas Abuse. These attacks exploit weaknesses in the real-world facilitator and server implementations and cause severe harm, including direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services. To assess the security of x402 deployments at scale, we propose a semi-automated black-box tool and apply it to 15 major x402 facilitators collectively used by over 60K sellers and 360K buyers. Alarmingly, we find violations in all evaluated facilitators. We responsibly disclosed our findings to the affected parties, who acknowledged the issues and adopted mitigations, including changes by Coinbase. Finally, we complement our controlled testing with an empirical measurement of over 119 million recent Base and Solana transactions, quantifying x402 adoption, facilitator centralization, and ecosystem-level risk indicators.