A July 21 study identified 31 previously unknown vulnerabilities across 15 operators facilitating payments through the x402 protocol, an HTTP-native standard for programmable cryptocurrency transactions. These 15 operators covered 99% of observed transactions during the study period, and each facilitator failed at least one of eight payment verification rules. Researchers validated two free-shopping cases and classified 10 additional cases as high risk. Analysis of over 119 million Base and Solana transactions from October 1 to December 26, 2025, estimated approximately $202,000 in gas and fees spent, including about $5,800 associated with reverts. By February 6, Coinbase, PayAI and Mogami had collectively acknowledged six vulnerabilities and fixed some issues.
Source: Read the original article

