Researchers find security flaws in all 15 major x402 payment facilitators

Security researchers tested 15 major x402 payment facilitators and found that every single one violated at least one security rule. These facilitators handle the vast majority of transactions in this emerging market, with Coinbase processing over 77 million transactions during the study period alone.

The analysis covered more than 119 million transactions on the Base and Solana networks between October and December 2025. The findings highlight significant risks for merchants and users, including potential asset theft and unpaid services, while showing that facilitators spent roughly $202,000 on network fees for failed or reverted transactions.

Key facts

  • All 15 tested facilitators, which account for 99% of observed x402 transactions, failed to meet at least one security standard.
  • Researchers identified four main types of attacks: free shopping, asset theft, service disruption, and gas abuse.
  • Coinbase was the largest participant in the study, handling 77.17 million transactions and nearly $27 million in volume.
  • Facilitators incurred approximately $202,000 in network fees for transactions that were either reverted or failed during the three-month window.
  • Coinbase, PayAI, and Mogami confirmed they fixed six collective vulnerabilities by February 6, but it is unclear if these fixes are fully deployed across their live systems.
  • The study mapped 49 specific rule violations to 31 distinct vulnerabilities within the x402 protocol infrastructure.

Why it matters

These results expose widespread technical weaknesses in the infrastructure supporting the growing AI agent economy. Since 93% of merchants rely on a single facilitator, any successful exploit could disrupt a large portion of the market. Users and businesses should be aware that current safeguards may not fully prevent financial loss or service abuse until providers confirm complete deployment of security patches.

Sources