Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Crypto

Coinbase and 14 x402 facilitators found vulnerable in security tests

Newsroom by Newsroom
August 14, 2026
in Crypto, Industry
coinbase
Share on FacebookShare on TwitterShare on Linkedin

A study presented at the USENIX Security Symposium identified 31 distinct vulnerabilities across the leading x402 protocol facilitators, including Coinbase, with validated attack paths that expose facilitator assets and enable unpaid purchases

Researchers tested 15 of the leading x402 facilitators – including Coinbase, Thirdweb, PayAI and Mogami – and found that every platform violated at least one security rule. The study, presented at the 35th USENIX Security Symposium, mapped 49 rule violations across 31 distinct vulnerabilities in systems that accounted for 99% of observed x402 transactions and 98% of payment volume during the period analysed.

The researchers identified four attack classes: free shopping, asset theft, service disruption, and network fee abuse. They directly validated six attack paths, including two free-shopping paths, three gas-abuse paths, and one that could expose assets held by facilitators. The most serious attack involved ERC-6492, an Ethereum signature standard for smart contract wallets: malicious metadata could lead a facilitator to fund and submit an arbitrary token-approval transaction in place of the expected payment.

Three further validated attacks exploited the network-fee sponsorship function: an attacker could force vulnerable implementations to pay for the deployment or initialisation of costly smart contracts. The researchers wrote that if facilitators sponsor fees without reliable reconciliation or chargeback capability, attacker-induced settlement can translate into a direct loss for the sponsor. The analysis covered more than 119 million x402 transactions on Base and Solana between 1 October and 26 December 2025: facilitators spent roughly 202,000 dollars in network fees, of which approximately 5,800 dollars were on Base transactions that were subsequently reversed or failed.

On the free-shopping front, all seven official Coinbase reference server kits examined lacked explicit mechanisms to roll back actions initiated after a successful verification. In Flask kit versions up to 0.2.1, protected resources could be released following verification regardless of whether the subsequent settlement succeeded. Merchant adoption of x402 was concentrated: more than 93% of the approximately 53,500 unique servers observed were associated with a single facilitator, with Coinbase alone processing 77.17 million transactions. A remediation update dated 6 February noted that Coinbase, PayAI and Mogami had collectively confirmed six vulnerabilities, some already resolved and others still in progress. The researchers did not publish a per-facilitator breakdown of vulnerabilities. Recommended countermeasures include treating all client-supplied transaction fields as untrusted, re-verifying payment conditions immediately before settlement, and enforcing strict limits on sponsored gas. The study also recommends that merchants delay irreversible services until settlement confirmation.

Previous Post

Apple alerts users to government spyware attacks on the lock screen

Latest News

coinbase
Crypto

Coinbase and 14 x402 facilitators found vulnerable in security tests

by Newsroom
August 14, 2026
0

A study presented at the USENIX Security Symposium identified 31 distinct vulnerabilities across the leading x402 protocol facilitators, including Coinbase,...

Read moreDetails
Apple avvisa gli utenti di attacchi spyware governativi sullo schermo
Industry

Apple alerts users to government spyware attacks on the lock screen

by Newsroom
August 14, 2026
0

The notification appears directly on the iPhone lock screen and flags a targeted attack: Apple has already reached users in...

Read moreDetails
tether
Bitcoin

Tether completes first full audit by KPMG

by Newsroom
August 14, 2026
0

For the first time in Tether's history, a Big Four auditor has examined the entire annual financial statements - not...

Read moreDetails
Dollaro-Yen: come l’inflazione viene usata per la politica estera
Feature

Dollar-yen: how inflation is used as foreign policy

by Federico Rivi
August 13, 2026
0

The dollar-yen exchange rate manoeuvre reveals that money creation has become a variable of foreign policy

Read moreDetails
Safe 3: Trezor launches its new hardware wallet
Bitcoin

Trezor: ShipMonk breach affects 13,689 customers

by Newsroom
August 13, 2026
0

Unauthorised access to logistics partner ShipMonk's systems exposed the names and contact details of nearly 13,700 buyers. Trezor states that...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team
  • Podcast
  • Home redesign preview

Follow Us

Italiano
No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • Podcast
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.