Coinbase and 14 Other Facilitators Fail Security Tests Amid AI-Driven Commerce Push
Researchers have found security flaws in major x402 facilitators, including Coinbase, that could expose facilitator-held assets and leave merchants without payment for services provided.
The study, presented at the 35th USENIX Security Symposium, tested 15 major x402 facilitators and found that every platform violated at least one security rule. The researchers mapped 49 rule violations to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions and 98% of payment volume during the study.
The researchers identified four broad attack classes, including free shopping, asset theft, service disruption, and gas abuse. They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.
Coinbase was the largest facilitator by a wide margin, processing 77.17 million transactions and nearly $27 million in payment volume during the study period. The concentration of x402 activity creates a vulnerability, outage, or flawed software assumption at one large provider that can affect thousands of merchants rather than remain isolated to a small implementation.
The researchers recommended treating all client-provided transaction fields as untrusted, rechecking payment conditions immediately before settlement, and imposing strict limits on facilitator-sponsored gas costs. For merchants, they recommended withholding irreversible services until settlement succeeds or maintaining a way to reverse actions when payment fails.