ai-bounty-board x402 payment gate accepts self-signed messages without on-chain settlement, enabling escrow bypass.
Security & Exploits ·
A security vulnerability in the ai-bounty-board x402 payment gate has been disclosed, involving improper message validation that could allow bypassing escrow protections. The issue stems from the gate accepting self-signed messages without requiring corresponding on-chain settlement, according to a report referencing code at server.js:534.
The mechanism of the vulnerability centers on the absence of on-chain verification for messages, creating a gap between message authentication and fund settlement. This design flaw enables actors to circumvent escrow safeguards by submitting signed messages that the system processes without confirming actual blockchain-backed transfers.
A bounty of 50 USDC has been offered for fixing the vulnerability, with technical details reportedly available in a public report. It remains unclear whether the issue is currently being exploited in production, what remediation timeline the project has communicated, or how many transactions or users may be affected by the validation gap.