id: PIR-2026-0019title: Five protocol attacks + 31 facilitator vulnerabilities shown against production x402 infrastructure carrying ~99% of observed transactionsdate_occurred: flaws latent in production x402 deployments from the protocol's 2025 launch; demonstrated 2026date_detected: May-July 2026 (two independent research efforts)date_disclosed: arXiv 2605.11781 submitted 2026-05-12; arXiv 2607.19545 July 2026 (USENIX Security '26); responsible disclosure to maintainers preceded publicationstatus: corroborated (peer-reviewed research + maintainer acknowledgment incl. Coinbase)agent_description: The x402 agentic-payment ecosystem - the revived HTTP 402 flow by which agents pay for APIs, content, and services: open-source SDKs plus facilitator services (Coinbase, Thirdweb, PayAI, Mogami among 15 studied) bridging synchronous HTTP authorization to asynchronous on-chain settlement.operator_type: enterprise + startup facilitator operators; downstream, 60K+ sellers and 360K+ buyers via the studied facilitatorsautonomy_level: autonomous-within-policy (machine-to-machine payments, no human per-transaction)model_stack: n/a (protocol/infrastructure layer, model-agnostic)harness: x402 SDKs + facilitator servicesauthority_scope: funds (agent and sponsor payment flows; facilitator-held assets)funds_at_risk_usd: unknown in aggregate; ~98% of x402 payment volume during the study moved through facilitators each violating at least one security ruleblast_radius: fleet/systemic (v0.1 tier - ecosystem-wide across every deployment on affected SDKs/facilitators)failure_locus: dependency (payment infrastructure agents rely on - not agent reasoning)root_cause: adversarial-other - primary (exploitable protocol/implementation flaws in authorization, binding, replay protection, web-layer handling); no compromise, no injection. Taxonomy strain noted: a "protocol-vulnerability" class is still missing post-v0.1.mechanism: Two unaffiliated teams. (1) "Five Attacks on x402" (Li - Ohio State; Wang - CSIRO; Wang - Manchester): five concrete cross-layer attacks on the design, including free shopping (goods released before settlement) and replay/binding gaps. (2) USENIX Sec '26 study (Wang, Yang, Chen, Ji, Payer - Zhejiang/EPFL HexHive; x402scope tool): tested 15 major live facilitators, mapped 49 rule violations to 31 distinct vulnerabilities - free shopping, facilitator asset theft, service disruption, sponsor-paid gas/cost amplification; every facilitator violated at least one rule.adversary_present: no (researcher demonstrations; no attributed in-wild exploitation of these flaws)exploitation_status: researcher-demonstratedseverity: near-miss (systemic exposure proven on production infrastructure; zero attributed realized loss)direct_loss_usd: 0 attributed to these flaws (the adjacent in-wild sample of this loss surface is 402Bridge, candidate C-015, recorded separately)indirect_loss_usd: unknown (facilitator remediation cost)downtime: none reporteddata_exposure: none (funds-integrity flaws, not data flaws)detected_by: third-party (academic researchers)time_to_detect: unbounded latency - flaws were live in production for months before the 2026 disclosurestime_to_recover: maintainers acknowledged and shipped mitigations post-disclosure (Coinbase among them)remediation: coordinated disclosure; facilitator-side fixescontrols_that_worked: nothing in-protocol bounded the exposure; the effective loss ceiling was researcher ethics plus the responsible-disclosure pipeline working as intendedstructural_fix: facilitator mitigations; x402scope released (github.com/HexHive/x402scope) as a reusable audit tooltelemetry_grade: strong for the demonstrations (public peer-reviewed artifacts, reproducible tooling); none for latent in-wild use - no one can show these flaws were never quietly exploited before disclosuresources:independence: two unaffiliated academic teams; maintainer acknowledgment corroborates validity; trade press derivative of the papers.confidence: high that the vulnerabilities are real and were demonstrated (peer review + vendor acknowledgment); medium on the ecosystem-share framing (coverage percentages rest on one team's scan methodology)