Urgent.News

What's breaking now, across thousands of outlets.

Tech

"paymentPayload is invalid": one dash broke a payment

Our first real x402 purchase on mainnet failed with a schema error caused by one em dash and a bare atob call. The cause, the fix, and how we proved it free. If an x402 facilitator answers with 'paymentPayload' is invalid and a list of schema names the payload must match, check how your server decodes the payment header before you blame the buyer. In our case the buyer was fine. Our server read…

In a recent incident, a single em dash in a payment header caused a payment to fail on the Base main network, marking the first real x402 purchase failure on the network. The error occurred due to a schema mismatch, with the paymentPayload being deemed invalid by the facilitator. Upon investigation, it was discovered that the server was decoding the payment header using a bare atob call, which was sensitive to the presence of the em dash.

The issue was resolved by correcting the server's decoding process, ensuring that the payment could be successfully processed. The full report detailing the incident can be found at AISkills402.

Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Auditing file-serving permission checks, using CVE-2026-100727 as the model

Auditing file-serving permission checks, using CVE-2026-100727 as the model Why this audit is worth running CVE-2026-100727 affects GROWI versions before v7.5.5 and allows a remote unauthenticated…

  • CVE-2026-100727 affects GROWI versions before v7.5.5
  • Unauthorized remote file access possible in non-public pages
  • Patch released in GROWI v7.5.5 on October 5, 2026

How to Test a WordPress Backup Restore (Before You Need It)

Untested backups aren't backups. They're hopes. Here's how to prove yours actually work — the full restore drill I run. What you need A scratch server or local environment (doesn't need to be…

  • Set up testing environment with same PHP version as production
  • Restore database from backup.sql file and verify wpoptions
  • Restore files to web root and update wp-config.php with new DB details

More from Monday 5 October →