Security · 6h ago
x402 Payment Signature Fails to Bind to URL, Researcher Finds
A security researcher discovered that x402's EIP-3009-based payment signature does not cover the resource URL, only the amount, recipient, token, and chain. Mutating 8 of 18 fields, including the entire resource object, left the signature valid. The flaw means a signed payment could be redirected to a different URL without invalidating the signature.
Meridian48 take
The finding highlights a fundamental design gap in x402's payment binding, though the proposed nonce fix is simple and protocol-compatible.
x402payment-signature