当HTTP 402遇上区块链:新兴x402支付的风险
When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments
浏览论文内容
中文总结 AI 辅助
研究x402支付协议,通过系统研究确定促进者的安全规则,基于规则违规分析得出新攻击向量,提出半自动黑盒工具评估安全性,发现部署均有违规,还通过实证测量量化相关指标,揭示其安全风险。
中文摘要 AI 辅助
x402是一种用于Web API和自主AI代理的新兴支付协议。它通过支付协商流程扩展了HTTP 402,并将支付证明验证和链上结算委托给第三方促进者。促进者成为许多独立商家的共享支付基础设施,集中了信任和验证。尽管被主要供应商迅速采用且主网活动具有经济意义,但现实世界中x402部署的安全状况仍未得到很好的描述。我们首次对当前促进者介导的x402野外部署中的授权正确性和执行安全性进行了系统研究,确定了促进者的八项安全规则。基于对规则违规的分析,得出四个新攻击向量,包括免费购物、资产盗窃、服务拒绝和燃气滥用。为评估x402部署的安全性,提出半自动黑盒工具并应用于15个主要促进者,发现均有违规。向受影响方披露结果,其认可问题并采取缓解措施。最后,通过对超1.19亿笔交易的实证测量补充控制测试,量化x402采用情况、促进者集中化和生态系统级风险指标。
英文摘要
x402 is an emerging payment protocol for Web APIs and autonomous AI agents. x402 extends HTTP 402 with a payment negotiation flow and delegates payment proof verification and on-chain settlement to third-party facilitators. As a result, facilitators serve as a shared payment infrastructure for many independent merchants. This centralizes trust and validation in one component, so a single flaw can affect many services. Despite rapid adoption by major vendors and economically meaningful mainnet activity, the security posture of real-world x402 deployments remains poorly characterized. We present the first systematic study of authorization correctness and execution safety in current facilitator-mediated x402 deployments in the wild, identifying eight security rules for facilitators as critical payment infrastructure. Based on our analysis of rule violations, we derive four new attack vectors, including Free Shopping, Asset Theft, Service Denial, and Gas Abuse. These attacks exploit weaknesses in the real-world facilitator and server implementations and cause severe harm, including direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services. To assess the security of x402 deployments at scale, we propose a semi-automated black-box tool and apply it to 15 major x402 facilitators collectively used by over 60K sellers and 360K buyers. Alarmingly, we find violations in all evaluated facilitators. We responsibly disclosed our findings to the affected parties, who acknowledged the issues and adopted mitigations, including changes by Coinbase. Finally, we complement our controlled testing with an empirical measurement of over 119 million recent Base and Solana transactions, quantifying x402 adoption, facilitator centralization, and ecosystem-level risk indicators.