31 vulnerabilities found in x402 crypto payment network, risking exposure of 99% of trades
July 27, 2026, 9:39 AM
Thirty-one new vulnerabilities have been found at major service providers supporting "x402," an HTTP-based cryptocurrency payment standard, CryptoSlate reported. The study covered 15 companies accounting for 99% of all transactions and found that every provider violated payment verification and settlement rules.
The vulnerabilities fell into four categories: unauthorized use, asset theft, denial of service, and gas fee abuse. Researchers also confirmed two cases of unauthorized use, described as "Free shopping," that exploited a gap allowing services to be provided before settlement was completed.
Major providers including Coinbase and PayAI acknowledged the vulnerabilities and began remediation work. The researchers urged merchants not to rely only on pre-verification and instead provide services only after final settlement is confirmed or adopt explicit rollback logic.
Leave the first comment
You need to log in to leave a comment.
Log In