PipeRoll - Agent Incident Registry

PIR-2026-0019

Researchers demonstrate systemic exploitability of the x402 agentic-payment stack
Cite as: PipeRoll PIR-2026-0019, Researchers demonstrate systemic exploitability of the x402… (2025) - https://piperoll.org/pir/2026-0019

PIR-2026-0019 - Researchers demonstrate systemic exploitability of the x402 agentic-payment stack

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes (corrections)

  1. Intake claimed "~99% of live x402 deployments exposed." Corrected: the 15 tested facilitators carried ~99% of observed x402 transactions (~98% of volume), and every one violated at least one security rule. The deployment-count framing was an inflation and does not appear in the research.
  2. Date corrected: "first half of 2026" -> May-July 2026 (Five Attacks 2026-05-12; facilitator study July 2026, USENIX Security '26).
  3. The "31 vulnerabilities" finding is the arXiv 2607.19545 paper itself (Wang, Yang, Chen, Ji, Payer), not merely "a CryptoSlate report" as the intake had it.
  4. Intake's "13,000+ registered resource servers in the Bazaar" could not be independently verified; replaced with the facilitator study's verified scale figures (15 facilitators, 60K+ sellers, 360K+ buyers).