A new disclosure names 31 vulnerabilities in x402, the HTTP-style payment protocol used for crypto-native agentic micropayments. Researchers say roughly 99% of live x402 integrations are exposed, with attack paths ranging from wallet draining to letting any user shop for free.
Why it matters
x402 sits beneath the AI-agent commerce stack: autonomous agents settling tiny machine-to-machine payments for data, inference, and API calls. Artemis data cited in the disclosure shows the protocol has settled into millions of low-value transactions, exactly the throughput pattern the sector was designed for. A near-total exposure rate on a primitive this load-bearing is a structural problem, not a peripheral bug.
Market impact
The flaws cluster around approval flows and settlement verification, the two pieces an attacker has to break to either steal funds or skip paying. With 99% of integrations in scope, the practical short-term effect is pressure on every agent-payments project built on x402 to patch, audit, or temporarily pause merchant endpoints until mitigations ship. The longer-term read is harder on the agentic-commerce thesis if the primitives keep landing with this kind of blast radius.
Frequently asked questions
-
What is x402 and why does it matter for AI agents?
x402 is a crypto payment protocol designed for tiny machine-to-machine transactions. It underpins the agentic-commerce stack, where autonomous AI agents pay each other for data, inference, and API calls.
-
How serious are the 31 disclosed x402 vulnerabilities?
Researchers say roughly 99% of live x402 integrations are exposed. Attack paths range from draining user wallets to letting attackers shop for free by skipping settlement.
-
Which parts of x402 are actually broken?
The disclosed flaws cluster around approval flows and settlement verification, the two checks an attacker must defeat to either siphon funds or avoid paying.
-
Has x402 been processing real transaction volume?
Yes. Artemis data cited in the disclosure shows x402 has settled into millions of low-value agentic transactions, making the exposure rate a structural risk on live volume.
-
What should x402-based projects do after the disclosure?
Operators should patch, commission fresh audits, and consider pausing merchant endpoints until mitigations ship, given that nearly every live integration sits in the affected scope.
CryptoSlate