Session
Your Agent Just Paid for Nothing (6 Attacks on x402 Payments)
Agents can now discover paid APIs and authorize machine-to-machine payments without a human in the loop. Protocols like x402 make this work over plain HTTP. But a payment that settles correctly is not the same as a payment that should have happened.
I will demonstrate live attacks against an autonomous payment agent: price manipulation, malicious service discovery, prompt injection into the payment decision, duplicate payments, budget exhaustion and payment-resource mismatch. Where the agent pays for one resource and receives another. Every one of them produces a technically valid transaction.
Then the controls that actually constrain the surface, all of them are deterministic(none of them a model call): spending limits, recipient allowlists, resource binding, nonce checks, retry limits and pre-payment validation.
Attendees leave with a threat model, a benchmark and a local simulation and testnet harness for testing their own payment agents without risking real funds.
Key Takeaways:
- A working threat model for autonomous agent payments, with six demonstrated attack classes
- Deterministic controls that do not require another model in the loop
- A local simulation and testnet harness for safe testing
- Why "the payment succeeded" and "the payment was correct" are different assertions
Ishween Kaur
Senior Engineer, Crypto and AI @SoFi
Santa Clara, California, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top