# PIR-2026-0019 - Researchers demonstrate systemic exploitability of the x402 agentic-payment stack

- `id`: PIR-2026-0019
- `title`: Five protocol attacks + 31 facilitator vulnerabilities shown against production x402 infrastructure carrying ~99% of observed transactions
- `date_occurred`: flaws latent in production x402 deployments from the protocol's 2025 launch; demonstrated 2026
- `date_detected`: May-July 2026 (two independent research efforts)
- `date_disclosed`: arXiv 2605.11781 submitted 2026-05-12; arXiv 2607.19545 July 2026 (USENIX Security '26); responsible disclosure to maintainers preceded publication
- `status`: corroborated (peer-reviewed research + maintainer acknowledgment incl. Coinbase)

### The agent
- `agent_description`: The x402 agentic-payment ecosystem - the revived HTTP 402 flow by which agents pay for APIs, content, and services: open-source SDKs plus facilitator services (Coinbase, Thirdweb, PayAI, Mogami among 15 studied) bridging synchronous HTTP authorization to asynchronous on-chain settlement.
- `operator_type`: enterprise + startup facilitator operators; downstream, 60K+ sellers and 360K+ buyers via the studied facilitators
- `autonomy_level`: autonomous-within-policy (machine-to-machine payments, no human per-transaction)
- `model_stack`: n/a (protocol/infrastructure layer, model-agnostic)
- `harness`: x402 SDKs + facilitator services

### Authority
- `authority_scope`: funds (agent and sponsor payment flows; facilitator-held assets)
- `funds_at_risk_usd`: unknown in aggregate; ~98% of x402 payment volume during the study moved through facilitators each violating at least one security rule
- `blast_radius`: fleet/systemic (v0.1 tier - ecosystem-wide across every deployment on affected SDKs/facilitators)

### The failure
- `failure_locus`: dependency (payment infrastructure agents rely on - not agent reasoning)
- `root_cause`: adversarial-other - primary (exploitable protocol/implementation flaws in authorization, binding, replay protection, web-layer handling); no compromise, no injection. Taxonomy strain noted: a "protocol-vulnerability" class is still missing post-v0.1.
- `mechanism`: Two unaffiliated teams. (1) "Five Attacks on x402" (Li - Ohio State; Wang - CSIRO; Wang - Manchester): five concrete cross-layer attacks on the design, including free shopping (goods released before settlement) and replay/binding gaps. (2) USENIX Sec '26 study (Wang, Yang, Chen, Ji, Payer - Zhejiang/EPFL HexHive; x402scope tool): tested 15 major live facilitators, mapped 49 rule violations to 31 distinct vulnerabilities - free shopping, facilitator asset theft, service disruption, sponsor-paid gas/cost amplification; every facilitator violated at least one rule.
- `adversary_present`: no (researcher demonstrations; no attributed in-wild exploitation of these flaws)
- `exploitation_status`: researcher-demonstrated

### Impact
- `severity`: near-miss (systemic exposure proven on production infrastructure; zero attributed realized loss)
- `direct_loss_usd`: 0 attributed to these flaws (the adjacent in-wild sample of this loss surface is 402Bridge, candidate C-015, recorded separately)
- `indirect_loss_usd`: unknown (facilitator remediation cost)
- `downtime`: none reported
- `data_exposure`: none (funds-integrity flaws, not data flaws)

### Detection and recovery
- `detected_by`: third-party (academic researchers)
- `time_to_detect`: unbounded latency - flaws were live in production for months before the 2026 disclosures
- `time_to_recover`: maintainers acknowledged and shipped mitigations post-disclosure (Coinbase among them)
- `remediation`: coordinated disclosure; facilitator-side fixes
- `controls_that_worked`: nothing in-protocol bounded the exposure; the effective loss ceiling was researcher ethics plus the responsible-disclosure pipeline working as intended
- `structural_fix`: facilitator mitigations; x402scope released (github.com/HexHive/x402scope) as a reusable audit tool

### Evidence
- `telemetry_grade`: strong for the demonstrations (public peer-reviewed artifacts, reproducible tooling); none for latent in-wild use - no one can show these flaws were never quietly exploited before disclosure
- `sources`:
  - https://arxiv.org/abs/2605.11781 (Five Attacks on x402 Agentic Payment Protocol, 2026-05-12)
  - https://arxiv.org/abs/2607.19545 (When HTTP 402 Meets the Blockchain - USENIX Sec '26 facilitator study)
  - https://cryptoslate.com/31-newly-discovered-vulnerabilities-expose-99-of-x402-crypto-payments-to-asset-theft-and-free-shopping/
  - https://cryptoslate.com/coinbase-and-14-other-x402-facilitators-failed-security-tests-built-for-the-coming-ai-agent-economy/
  - All four URLs verified resolving 2026-08-15.
  - `independence`: two unaffiliated academic teams; maintainer acknowledgment corroborates validity; trade press derivative of the papers.
- `confidence`: high that the vulnerabilities are real and were demonstrated (peer review + vendor acknowledgment); medium on the ecosystem-share framing (coverage percentages rest on one team's scan methodology)

### Verification notes (corrections)
1. Intake claimed "~99% of live x402 deployments exposed." Corrected: the 15 tested facilitators carried ~99% of observed x402 *transactions* (~98% of volume), and every one violated at least one security rule. The deployment-count framing was an inflation and does not appear in the research.
2. Date corrected: "first half of 2026" -> May-July 2026 (Five Attacks 2026-05-12; facilitator study July 2026, USENIX Security '26).
3. The "31 vulnerabilities" finding is the arXiv 2607.19545 paper itself (Wang, Yang, Chen, Ji, Payer), not merely "a CryptoSlate report" as the intake had it.
4. Intake's "13,000+ registered resource servers in the Bazaar" could not be independently verified; replaced with the facilitator study's verified scale figures (15 facilitators, 60K+ sellers, 360K+ buyers).
