Skip to content
Back to Guavy Wire
Crypto

Coinbase and x402 Facilitators Exposed to Critical Security Flaws

Share

Researchers have discovered critical security flaws in 15 major x402 payment facilitators, including Coinbase and Thirdweb. The study found that every platform violated at least one security rule, exposing facilitator-held assets and potentially causing direct financial loss to merchants.

The researchers tested the platforms using simulations of real-world attacks and identified four broad attack classes: free shopping, asset theft, service disruption, and gas abuse. They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.

The study focused on x402, a payment standard being promoted as infrastructure for machine-driven commerce, allowing websites and APIs to request payments that software and AI agents can complete autonomously. Facilitators sit between buyers and merchants, checking signed payment authorizations before submitting transactions to blockchains.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc