Hacks & Exploits
Coinbase and 14 x402 Payment Facilitators Fail Security Tests, Exposing Vulnerabilities
A study presented at the 35th USENIX Security Symposium has highlighted significant security flaws among major x402 payment facilitators, including Coinbase, Thirdweb, PayAI, and Mogami. Researchers tested 15 platforms and found that each violated at least one security rule, mapping 49 rule violations to 31 distinct vulnerabilities across systems that accounted for 99% of observed x402 transactions.
The study identified four broad classes of attacks: free shopping, asset theft, service disruption, and gas abuse. Researchers validated six attack paths, including two related to free shopping and three to gas abuse, which could lead to direct financial losses for merchants and theft of facilitator-held assets.
The most concerning vulnerability involved the ERC-6492 Ethereum signature standard, which could allow attackers to exploit malicious metadata to approve unauthorized transactions. Additionally, flaws in the x402 payment process could result in merchants releasing services before payment confirmation, leading to potential losses.
Coinbase emerged as the largest facilitator during the study, processing over 77 million transactions. The concentration of x402 activity raises concerns, as a single provider's failure could impact thousands of merchants.
In response to the findings, some facilitators have begun remediation efforts, but the extent of these fixes remains unclear. Researchers recommend treating all transaction fields as untrusted and implementing safeguards to protect both facilitators and merchants from potential losses.
FAQ
What vulnerabilities were identified in the x402 payment facilitators?
The study identified 49 rule violations mapped to 31 distinct vulnerabilities, including issues related to free shopping, asset theft, service disruption, and gas abuse.
Which payment facilitators were tested in the study?
The study tested 15 platforms, including major facilitators such as Coinbase, Thirdweb, PayAI, and Mogami.
What is the most concerning vulnerability found in the study?
The most concerning vulnerability involves the ERC-6492 Ethereum signature standard, which could allow attackers to exploit malicious metadata to approve unauthorized transactions.
How could the flaws in the x402 payment process affect merchants?
Flaws in the x402 payment process could lead to merchants releasing services before payment confirmation, resulting in potential financial losses.
What recommendations did researchers make to improve security?
Researchers recommend treating all transaction fields as untrusted and implementing safeguards to protect both facilitators and merchants from potential losses.