Security for the agent-payment economy

Catch the bugs general scanners
never look for.

x402guard checks the web↔chain glue of your x402 / agent-payment integration — replay, allowance, idempotency, unauthenticated treasury broadcast, SSRF webhooks. Slither checks your contract. We check everything around it.

Language:

Runs entirely on the server with the same ruleset as the CLI. Nothing is stored.

Heuristic static analysis — expect some false positives/negatives. It complements, it does not replace, a professional smart-contract / ZK audit.

Scored a D or F? Get a human expert to review your x402 integration — and write the fixes.

Book a security review →

What it checks

15 rules drawn from the “Five Attacks on x402” taxonomy and real-world escrow-audit findings — the integration-layer issues that contract-only tools skip.

Unauthenticated treasury broadcast Replay / missing nonce Idempotency / double-settle Fail-open auth SSRF webhooks Unlimited approvals Reentrancy (CEI) tx.origin owner Raw ERC20 Hardcoded keys Weak randomness Stack-trace leaks

Why this matters now

Agent-payment code moves real USDC over a brand-new attack surface — and money is already being lost.

Real exploits, today

GoPlus flagged critical vulns in x402-based tokens after exploits drained USDC from 200+ wallets.

A known attack class

The academic taxonomy is published — “Five Attacks on x402”: replay, allowance bypass, web-layer idempotency, authorization binding.

The audit gap

80%+ of deployed contracts never get a professional audit. The integration layer gets even less scrutiny.

Where it fits

ToolChecksMisses
Slither / MythXSolidity contract internalsthe x402 web↔chain glue
OZ Defender / Fortaruntime monitoring (general)x402-specific flows
x402guardthe integration layer, in CI(complements a full audit)

Run it in CI

Zero dependencies. Fails the build on any critical/high finding. Drop the GitHub Action into any repo that ships agent-payment code.

npx x402guard ./your-project --html report.html

Text / HTML / JSON reports · SARIF + runtime monitoring on the roadmap.

Pricing

The grader and CLI are free forever — they drive adoption. You pay when real money is on the line and you want a human in the loop.

Free

Grader + CLI

$0
  • Unlimited web grades
  • Open-source CLI
  • GitHub Action / CI gate
  • 15-rule x402 ruleset
Scan now
Coming soon

Continuous

from $199/mo
  • Private-repo CI scanning
  • Runtime monitoring (drain / replay alerts)
  • PR comments + dashboard
  • Early-access pricing locked in
Join early access

Book a security review

Tell me what you're shipping — I'll reply with scope and a fixed quote, usually same day.

Sent straight to me — usually a same-day reply. Prefer email? dario@dmeomaha.com