WEDNESDAY, JULY 29, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 6h ago

x402 Payment Signature Fails to Bind to URL, Researcher Finds

By Meridian48 News Desk · Summarised from DEV Community ·

A security researcher discovered that x402's EIP-3009-based payment signature does not cover the resource URL, only the amount, recipient, token, and chain. Mutating 8 of 18 fields, including the entire resource object, left the signature valid. The flaw means a signed payment could be redirected to a different URL without invalidating the signature.

Meridian48 take
The finding highlights a fundamental design gap in x402's payment binding, though the proposed nonce fix is simple and protocol-compatible.
Read the full reporting
x402 Signs the Money, Not the URL. I Checked 18 Fields. →
DEV Community
x402payment-signature
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan