Points of Focus
- Researchers found 31 vulnerabilities across 15 x402 facilitators from 49 rule violations.
- Six attack paths were validated, including free shopping, gas abuse, and asset theft.
- Coinbase led the activity sample, but the paper didn’t map flaws to individual providers.
Coinbase and 14 other x402 payment facilitators violated at least one security rule in research presented at the 35th USENIX Security Symposium, with 49 violations mapping to 31 vulnerabilities. The tested facilitators represented 99% of observed x402 transactions and 98% of payment volume during the study window. The findings come as x402.org recorded 75.41 million transactions and $24.24 million in volume over the past 30 days as of Aug. 14.
USENIX Security '26 Study Identifies 65,000+ High-Risk Crypto Addresses Linked to $574.8M in Losses
A study presented at USENIX Security '26 identified 65,340 high-risk cryptocurrency addresses involved in abuse across Ethereum and BNB Chain, with estimated losses exceeding… pic.twitter.com/JAX3IR6Kgy
— Wu Blockchain (@WuBlockchain) August 13, 2026
x402 security flaws expose verify-to-settlement gap
The key risk sits between payment verification and final blockchain settlement. Coinbase’s current x402 documentation shows the server returning the paid resource after the facilitator reports the settlement result.
The researchers found that some older merchant SDKs could release resources after verification but before settlement succeeded. All seven Coinbase reference server SDKs they examined lacked rollback for actions taken after verification, while the Flask SDK through version 0.2.1 could return a protected resource before settlement succeeded. A payment could pass verification, expire, or fail onchain after the merchant delivered the service.
The study classified 10 free-shopping cases as high risk and validated two end-to-end paths. It also validated three gas abuse paths and one ERC-6492 route in which an attacker could induce an unnamed high-volume facilitator to submit a token-approval transaction. Researchers stopped after confirming the approval and didn’t move facilitator funds.
Coinbase x402 scale raises security stakes
Coinbase processed 77.17 million transactions and $26.85 million in payment volume in the data set, more than any other facilitator. Across 53,576 merchant servers, more than 93% were tied to only one facilitator.
Researchers measured about $202,000 in Base and Solana network fees from x402 settlement attempts between Oct. 1 and Dec. 26, 2025. About $5,800 was spent on Base transactions that later reverted.
Those failures weren’t established as attacks. The paper withholds the provider mapping for the 31 vulnerabilities, so the findings can’t be read as 31 Coinbase flaws or proof that every issue remains live. Researchers disclosed findings to 14 of 15 affected parties in January 2026.
As of Feb. 6, Coinbase, PayAI, and Mogami had confirmed six vulnerabilities, with some fixed and others still being addressed.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


