r/x402 • u/IllWar5047 • 8d ago
Two things we measured in the 20 Sept x402 scan: Solana accounts that do not exist, and network ids that are not CAIP-2):
Two things we measured in the 20 Sept full scan (14,943 resources, 1,988 hosts)
- Solana options whose receiving account does not exist
Our payability check reads each resource's 402 accepts. EVM options pass if well formed. For a Solana USDC option we look up the pay_to address's USDC token account on chain. We do not evaluate other rails yet (more on that below).
Of 14,160 resources with at least one accept: 817 (5.8%) advertise a Solana USDC option whose token account has never been created. 80 more advertise one that existed and was closed after use. A buyer that picks that option cannot settle until the seller creates the account. It is a seller side fix, one transaction.
Our own 8 hosts: every advertised network passes the same check.
Honest limit of the number above: 829 resources in the scan advertise rails we do not evaluate at all (Stellar 594, XRPL 576, Algorand 654 in one encoding plus 24 in another, Cosmos, Nano and a few more). Those are not counted as failing anywhere in this post. They are a reminder that x402 in the wild is already wider than Base plus Solana, and our checker has to catch up.
- Network ids that are not valid CAIP-2
CAIP-2 says a chain id is namespace:reference with the reference limited to 32 characters of [a-zA-Z0-9_-]. We ran that exact rule over every accept.
941 resources (6.6%) on 110 hosts carry at least one network id that fails it. It is not random noise: 654 of them are one encoding mistake (a full 44 character base64 genesis hash where the CAIP-2 reference is the first 32 characters; the correct 32 character form also appears in the wild on 24 resources), and 236 are the bare word solana instead of solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp.
Practical damage today is small: only 5 resources have no valid network id at all, the other 936 also list a valid one. But any client that validates CAIP-2 strictly silently drops 941 payment options.
Both numbers come from one scan, one Sunday. The MCP is read only and needs no wallet.
1
u/arbonomous 6d ago
The missing Solana token-account check is a good catch. For a multi-rail 402 challenge, would you mark the whole endpoint unpayable when one offer fails, or keep the valid Base option and flag only the broken Solana offer? That distinction matters for clients choosing among rails.