Nikolife/pulsefeed-x402-security
PulseFeed — x402 Agent-Payment Security & Trust (open data) Independent, daily-updated trust & safety data for the x402 agent-payment economy (HTTP 402 + stablecoins on Base) and the MCP server ecosystem — by PulseFeed. AI agents increasingly pay for APIs autonomously over x402 and connect to MCP servers that can run code on install. But 20% of listed x402 endpoints are dead or invalid, and "live" is not the same claim as "payable": of 33724 endpoints that return a valid 402… See the full description on the dataset page: https://huggingface.co/datasets/Nikolife/pulsefeed-x402-security.
PulseFeed — x402 Agent-Payment Security & Trust (open data)
Independent, daily-updated trust & safety data for the x402 agent-payment economy (HTTP 402 + stablecoins on Base) and the MCP server ecosystem — by PulseFeed.
AI agents increasingly pay for APIs autonomously over x402 and connect to MCP servers that can run code on install. But 20% of listed x402 endpoints are dead or invalid, and "live" is not the same claim as "payable": of 33724 endpoints that return a valid 402, only 31741 across 2429 operators are things an agent can actually buy — the rest are documentation placeholders, testnet sandboxes priced in dollars, or payment schemes outside the x402 spec. Both figures are in ecosystem.json as healthyEndpoints and payableEndpoints; compare the payable one. This dataset is the free, public slice of PulseFeed's continuous audit. Last updated: 2026-10-10T02:45:05+00:00.
Methodology correction — 2026-07-30. Snapshots dated before 2026-07-30 understate liveness. Our prober read x402 payment requirements only from the HTTP response body; x402 v2 moved them into thePAYMENT-REQUIREDheader. 1,869 endpoints across 166 operators were live and recorded as dead, and 3,920 fabricatedmalformedobservations were removed from their history — records repaired this way carryhistoryRepairedAt. The dead share moved from 74–76% to 20%: a change in the measuring instrument, not in the market. Series before and after this date are not directly comparable, and each snapshot now carriesprobeVersion. The scam/anomaly findings are unaffected. Full write-up, including four further errors of the same kind and a checklist for deciding whether an endpoint is genuinely payable: https://pulsefeed.dev/correction
The audit, incident feed and reports are free and open. Live pages: /incidents · /status · /reports. Machine feeds: /incidents.json · /incidents.rss. Full per-service cross-domain data feed (paid, x402): /data.
Files
incidents schema
Honesty note
Findings are stated as facts from the data, not accusations of intent. "bait-and-switch" = advertised price != amount actually charged; "unverified receiver" = payTo has no on-chain USDC history (a risk signal, not a conviction); "possible hijack" = receiver changed on an established baseline (could be a legitimate key rotation). By-design receiver rotation is excluded.
Why it's unique
The signals here (receiver-stability over time, payTo/price change history, on-chain receiver profiles) are longitudinal — derived from continuously re-probing endpoints and recording changes as they happen. This history cannot be reconstructed after the fact.
License & attribution
CC-BY-4.0. Attribution: "x402/MCP trust data by PulseFeed (pulsefeed.dev)". The full per-service cross-domain feed is a separate paid product at pulsefeed.dev/data.
Writeup: I audited the entire x402 agent-payment economy — 76% is dead, and the live half has scams. The "76% dead" headline in that article is superseded — see the methodology correction above. The scam taxonomy stands.
