Coinbase Among 15 x402 Facilitators Hit by 31 Security Flaws

By Muhammad Hassan // August 14, 2026 @ 07:39 PM Make AlphaWire Logo preferred on Google News

Share

Coinbase Among 15 x402 Facilitators Hit by 31 Security Flaws

Share

Points of Focus

  • Researchers found 31 vulnerabilities across 15 x402 facilitators from 49 rule violations.
  • Six attack paths were validated, including free shopping, gas abuse, and asset theft.
  • Coinbase led the activity sample, but the paper didn’t map flaws to individual providers.

 

 

Coinbase and 14 other x402 payment facilitators violated at least one security rule in research presented at the 35th USENIX Security Symposium, with 49 violations mapping to 31 vulnerabilities. The tested facilitators represented 99% of observed x402 transactions and 98% of payment volume during the study window. The findings come as x402.org recorded 75.41 million transactions and $24.24 million in volume over the past 30 days as of Aug. 14.

 

 

x402 security flaws expose verify-to-settlement gap

The key risk sits between payment verification and final blockchain settlement. Coinbase’s current x402 documentation shows the server returning the paid resource after the facilitator reports the settlement result.

The researchers found that some older merchant SDKs could release resources after verification but before settlement succeeded. All seven Coinbase reference server SDKs they examined lacked rollback for actions taken after verification, while the Flask SDK through version 0.2.1 could return a protected resource before settlement succeeded. A payment could pass verification, expire, or fail onchain after the merchant delivered the service.

The study classified 10 free-shopping cases as high risk and validated two end-to-end paths. It also validated three gas abuse paths and one ERC-6492 route in which an attacker could induce an unnamed high-volume facilitator to submit a token-approval transaction. Researchers stopped after confirming the approval and didn’t move facilitator funds.

 

Coinbase x402 scale raises security stakes

Coinbase processed 77.17 million transactions and $26.85 million in payment volume in the data set, more than any other facilitator. Across 53,576 merchant servers, more than 93% were tied to only one facilitator.

Researchers measured about $202,000 in Base and Solana network fees from x402 settlement attempts between Oct. 1 and Dec. 26, 2025. About $5,800 was spent on Base transactions that later reverted.

Those failures weren’t established as attacks. The paper withholds the provider mapping for the 31 vulnerabilities, so the findings can’t be read as 31 Coinbase flaws or proof that every issue remains live. Researchers disclosed findings to 14 of 15 affected parties in January 2026. 

As of Feb. 6, Coinbase, PayAI, and Mogami had confirmed six vulnerabilities, with some fixed and others still being addressed.

Share

Default avatar

Muhammad Hassan

Muhammad Hassan is a tech writer with over 11 years of experience in the crypto space. He specializes in crafting data-driven strategic content that helps blockchain and fintech brands grow their organic reach. He has led editorial initiatives for global crypto media outlets, where his strategies and article series have reached millions of readers worldwide.

Table of content

Ad

Related Articles