x402 Payment Protocol Signs Token Details, Not the Resource Being Purchased
A developer testing the x402 payment protocol found that its payer signature does not cover the URL or resource being purchased, only the amount, recipient, token contract, and blockchain chain. By rebuilding the EIP-712 digest from the official x402 v2 spec example and running secp256k1 public key recovery, the researcher mutated 18 fields one at a time and found that 8 changes — including altering the resource URL — left the signature still valid. This means a payment can be redirected to a different resource without invalidating the cryptographic proof of payment. The researcher proposed a zero-protocol-change fix: encoding the intended resource into the 32-byte nonce that payers already choose and sign. The finding carries practical urgency as Cloudflare announced an x402-based monetization gateway on July 1, 2026, significantly expanding the number of automated agents expected to use the protocol.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in