Coinbase and x402 Facilitators Exposed to Critical Security Flaws
Researchers have discovered critical security flaws in 15 major x402 payment facilitators, including Coinbase and Thirdweb. The study found that every platform violated at least one security rule, exposing facilitator-held assets and potentially causing direct financial loss to merchants.
The researchers tested the platforms using simulations of real-world attacks and identified four broad attack classes: free shopping, asset theft, service disruption, and gas abuse. They directly validated six attack paths under bounded conditions, including two free-shopping attacks, three gas-abuse attacks, and one path that could expose facilitator-held assets.
The study focused on x402, a payment standard being promoted as infrastructure for machine-driven commerce, allowing websites and APIs to request payments that software and AI agents can complete autonomously. Facilitators sit between buyers and merchants, checking signed payment authorizations before submitting transactions to blockchains.