Security audits for agent-payment infrastructure

The money moves in milliseconds.
So do the mistakes.

Chokepoint Assurance is the first dedicated security-audit practice for x402 and the adjacent rails that let autonomous agents pay for resources. We run blended web + chain engagements against the attack classes no single-discipline firm catches — the ones that sit exactly where an HTTP request becomes an on-chain settlement.

11+
vulnerabilities found across live x402 SDKs and endpoints in two academic audits
200+
wallets drained in the 402bridge exploit
Most
facilitator volume today rides on unaudited infrastructure

Why this exists

Agent payments broke the audit boundary.

For thirty years the web returned 402 Payment Required and nobody used it. x402 turned it on. Now an HTTP response can carry a machine-readable price, an agent can satisfy it without a human, and a facilitator settles the money on-chain a beat later. That is a genuinely new thing — and it created a seam that neither a classic web-app pentest nor a classic smart-contract audit fully covers.

Web auditors understand headers, replay, and TOCTOU but stop at the wallet. Chain auditors understand settlement and signatures but treat the HTTP layer as someone else's problem. The dangerous bugs live in the handoff: the ordering between granting access and confirming settlement, the binding (or lack of it) between a payment and the exact resource it bought, the idempotency of a /settle call under a race. Two recent academic reviews found eleven-plus issues in live x402 SDKs and endpoints. The 402bridge exploit drained 200+ wallets. The facilitators carrying most of today's volume have never been audited at all.

Chokepoint exists to sit in that seam on purpose. One team, both disciplines, focused on exactly the classes below.

The catalogue

Attack classes we hunt.

Each of these lives in the payment-to-resource handoff and is invisible to a single-discipline review. Plain-language descriptions below; the engagement goes deep on each.

Attack class What goes wrong, in plain language Surface
Grant-before-settle ordering The server hands over the paid resource before settlement is actually confirmed on-chain. If settlement then fails or is reverted, the buyer got the goods for free. Web + Chain
Payment replay & idempotency gaps A single valid payment authorization is accepted more than once — or a retried request settles twice — because the endpoint never enforced one-payment-one-use. Web + Chain
Missing payment-to-resource binding A payment made for one resource is accepted to unlock a different (or more expensive) one, because nothing cryptographically ties the payment to the exact thing it bought. Web + Chain
Solana /settle TOCTOU races Between the time settlement is checked and the time access is granted, concurrent requests slip through — a classic time-of-check/time-of-use race, now with money attached. Chain
Webhook replay Settlement-confirmation webhooks are replayable or unsigned, letting an attacker forge "payment received" events and unlock resources without paying. Web
Prompt-injection-to-payment paths Untrusted content steers an agent into authorizing a payment it never should have — the injection reaches all the way through to a real transfer. Web + Agent
Wallet-policy bypasses Spend limits, allow-lists, or approval rules meant to cap an agent's wallet are circumvented through ordering, encoding, or edge-case inputs. Chain + Agent

Engagements

How we work with you.

Fixed fee · $30K–$150K

Blended web + chain audit

A time-boxed, fixed-fee engagement across your HTTP surface and your settlement path. We model the full request-to-settlement lifecycle, attack every class in the catalogue, and deliver a findings report with severity, reproduction, and concrete remediations.

  • Threat model of the payment-to-resource handoff
  • Hands-on testing of ordering, replay, binding, TOCTOU
  • Prioritized findings with fixes and a re-test
Retainer

Runtime monitoring retainer

Infrastructure changes weekly; a point-in-time audit ages fast. An ongoing retainer watches your live endpoints and SDK releases for regressions in header hygiene, requirement formatting, and the behaviors that precede the deeper classes.

  • Continuous surface monitoring of production endpoints
  • Review of SDK and facilitator changes as they ship
  • Priority response when something looks wrong
Support

Coordinated-disclosure support

Found something, or had something reported to you? We help triage, reproduce, and privately coordinate disclosure across facilitators, wallet vendors, and token projects — so a real bug gets fixed quietly instead of exploited loudly.

  • Triage and reproduction of inbound reports
  • Severity and blast-radius assessment
  • Multi-party coordinated-disclosure facilitation

Free tool

x402 Endpoint Checker

Point it at a paid endpoint. We send a single unauthenticated GET — no payment, no exploitation — and grade what is passively observable: the 402 itself, protocol version, payment-requirement formatting, and header hygiene. It is a smoke test, not an audit.

Try an example:

Passive, unauthenticated surface check only. This tool never sends payments and never attempts exploitation. The attack classes that actually drain funds — replay, grant-before-settle, /settle TOCTOU, resource binding — can only be assessed in an authorized engagement.

Engagement process

What a fixed-fee audit looks like.

  1. 01

    Scope & threat model

    We map your endpoints, SDKs, facilitator, and settlement path, and agree a fixed scope, fixed fee, and timeline before any testing starts.

  2. 02

    Authorized testing

    Hands-on, in a controlled environment: we work the full catalogue against your real handoff — ordering, replay, binding, TOCTOU, webhooks, wallet policy.

  3. 03

    Findings & remediation

    A written report with severity, reproduction steps, and specific fixes. We walk your team through each finding and answer questions directly.

  4. 04

    Re-test & sign-off

    Once you've shipped fixes, we re-test the findings and confirm closure, so you finish with evidence you can share with partners and customers.

Team & credibility

Both disciplines, one team.

Chokepoint pairs web-application security and smart-contract auditing under one roof, specifically to cover the seam between them. Our work is grounded in the public record of this space: the academic reviews that surfaced eleven-plus issues in live x402 SDKs and endpoints, and post-mortems like the 402bridge wallet drain.

Detailed team bios, prior public findings, and references available on request under NDA. Get in touch and we'll share relevant background for your engagement.

Contact

Get an audit on the calendar.

Tell us what you're running — facilitator, wallet or middleware, a token project defending a large market cap, or Foundation infrastructure — and we'll scope a fixed-fee engagement.

Email ebo@testmachine.ai

Prefer to start with data? Run the free endpoint checker and send us the report.