Coinbase Among x402 Facilitators Exposed to Widespread Security Flaws
A study presented at the 35th USENIX Security Symposium identified security flaws in 15 major x402 payment facilitators, including Coinbase. The research found that all evaluated platforms violated at least one security rule, with a universe that concentrated 99% of observed transactions and 98% of payment volume during the analyzed period.
The researchers mapped 49 rule violations to 31 distinct vulnerabilities and grouped the risks into four attack classes: purchases without effective payment, asset theft, service disruption, and gas abuse. Six attack paths were directly validated under limited conditions, including two 'free shopping' paths and three gas abuse paths.
In the most serious case described, the issue involves the ERC-6492 signature standard used on Ethereum for smart contract wallets that may not yet have been deployed. The analysis indicated that malicious metadata could lead a facilitator to fund and send an arbitrary token approval transaction instead of the payment it expected to settle.
Coinbase appeared as the largest facilitator, with 77.17 million transactions processed and nearly US$27 million in volume during the measured period. The study analyzed over 119 million x402 transactions on Base and Solana between October 1 and December 26, 2025.