USENIX Security2026Top-tier venue
When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments
Qinying Wang, Yong Yang, Yuan Chen, Shouling Ji, Mathias Payer
Abstract
x402 is an emerging payment protocol for Web APIs and autonomous AI agents. It is driven by the rise of LLM-based agents that can autonomously purchase access to online services. x402 extends HTTP 402 with a payment negotiation flow and delegates payment proof verification and on-chain settlement to third-party facilitators. As a result, facilitators serve as a shared payment infrastructure for many independent merchants. This centralizes trust and validation in one component, so a single flaw can affect many services. Despite rapid adoption by major vendors and economically meaningful mainnet activity, the security posture of real-world x402 deployments remains poorly characterized. We present the first systematic study of authorization correctness and execution safety in current facilitator-mediated x402 deployments in the wild, identifying eight security rules for facilitators as critical payment infrastructure. Based on our analysis of rule violations, we derive four new attack vectors, including Free Shopping , Asset Theft , Service Denial , and Gas Abuse . These attacks exploit weaknesses in the real-world facilitator and server implementations and cause severe harm, including direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services. To assess the security of x402 deployments at scale, we propose a semi-automated black-box tool and apply it to 15 major x402 facilitators collectively used by over 60K sellers and 360K buyers. Alarmingly, we find violations in all evaluated facilitators. We responsibly disclosed our findings to the affected parties, who acknowledged the issues and adopted mitigations, including changes by Coinbase. Finally, we complement our controlled testing with an empirical measurement of over 119 million recent Base and Solana transactions, quantifying x402 adoption, facilitator centralization, and ecosystem-level risk indicators.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3b19845d-e212-41a4-9aad-d81c6fde367dBuilds on22
- Universal Atomic Swaps: Secure Exchange of Coins Across All BlockchainsSri Aravinda Krishnan Thyagarajan, Giulio Malavolta, Pedro Moreno-SanchezS&P 2022 · 112 citations
- SoK: Security and Privacy of Blockchain InteroperabilityAndré Augusto, Rafael Belchior, Miguel Correia, André Vasconcelos et al.S&P 2024 · 90 citations
- SmartInv: Multimodal Learning for Smart Contract Invariant InferenceSally Junsong Wang, Kexin Pei, Junfeng YangS&P 2024 · 38 citations
- Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation AnalysisYi Chen, Luyi Xing, Yue Qin, Xiaojing Liao et al.USENIX Security 2019 · 33 citations
- Security Certification in Payment Card Industry: Testbeds, Measurements, and RecommendationsSazzadur Rahaman, Gang Wang, Danfeng Daphne YaoCCS 2019 · 31 citations
Related papers
- Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM AgentsZichuan Li, Jian Cui, Xiaojing Liao, Luyi XingNDSS 2026 · 24 citations
- A2ASecBench: A Protocol-Aware Security Benchmark for Agent-to-Agent Multi-Agent SystemsTianhao Li, Chuangxin Chu, Yujia Zheng, Bohan Zhang et al.ICLR 2026
- MCPTox: A Benchmark for Tool Poisoning on Real-World MCP ServersZhiqiang Wang, Yichao Gao, Yanting Wang, Suyuan Liu et al.AAAI 2026 · 6 citations
- Demystifying the (In)Security of Oauth-Based Account Linking in Connector EcosystemsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong LauS&P 2026
- Beyond Detection: Autonomous Anomaly Remediation for MCP Against Tool Poisoning AttacksZhiqiang Wang, Guanquan Shi, Yanting Wang, Yichao Gao et al.WWW 2026
