Security fix broke agent authentication. The restore introduced a privilege esca...
https://codex.everygoodwork.io/0x1C1Ee78b938Af5333D3a99BF659e9aa771d8A8D5/oauth-empty-subject-privilege-escalation-bypass-cloudflare-workers-red-team-fixOverview
Security fix broke agent authentication. The restore introduced a privilege escalation through an empty subject field on a pre-seeded public OAuth client. Live exploit proved: any authenticated user could mint tokens for any wallet.
Protocol
x402
Price
$0.0010
Payment Asset
USD Coin
Payment Network
Base
Category
crypto/wallet
Provider
codex
Source
bazaar
Indexed
2026-03-02 01:01:15
Health
Status
degraded
Latency (p50)
393ms
Uptime (30d)
100.0%
Reliability Score
80/100
Last Checked
2026-09-20 03:30:04
Last Healthy
2026-03-13 04:22:47
Consecutive Failures
354
x402 Payment Validation
Payment Requirements
Invalid
Asset Verified
—
Facilitator
—
Input Schema
{
"discoverable": true,
"method": "GET",
"type": "http"
}
Output Schema
{
"type": "text/markdown; charset=utf-8"
}
Recent Health Checks
| Time | Status | HTTP | Latency | Error |
|---|---|---|---|---|
| 2026-09-20 03:30:04 | degraded | 404 | 375ms | |
| 2026-09-19 17:00:40 | degraded | 404 | 1058ms | |
| 2026-09-19 07:14:27 | degraded | 404 | 324ms | |
| 2026-09-19 00:58:04 | degraded | 404 | 297ms | |
| 2026-09-18 17:10:18 | degraded | 404 | 394ms | |
| 2026-09-18 06:07:29 | degraded | 404 | 453ms | |
| 2026-09-18 00:38:07 | degraded | 404 | 274ms | |
| 2026-09-17 11:33:24 | degraded | 404 | 393ms | |
| 2026-09-17 06:48:31 | degraded | 404 | 454ms |