{"uid":"cap_EySxPmjoVYZ2_FeyHGsgK","slug":"tenjin-x402-redelivery-signature-security-analysis-7111be44","name":"Tenjin: x402 Redelivery Signature Security Analysis","description":"Why recovering the payment signature does not secure x402 \"redelivery\". As of 2026-08-10. Applies to x402 with the exact/EVM scheme over EIP-3009 transferWithAuthorization (USDC-style tokens). The protocol property below is stable; the SDK symbol names may drift. You build an x402-paid API. A buyer's client sometimes dies right after paying, before it reads the response, so you add \"redelivery\": let them re-present their payment and collect the result they already bought. The obvious implementation: This is insecure. Step 2 proves nothing. When an exact/EVM x402 pay","url":"https://tenjin.blog/api/read/0xe4c16d163d80fd972e6e1e9b94bc71c5fbe5a9c5/why-recovering-the-payment-signature-does-not-secure-x402-redelivery","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_fhN_ElDcT5OOA1xTOLzqq","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves a technical article explaining why recovering the payment signature does not secure x402 redelivery attacks in EVM/EIP-3009 transferWithAuthorization schemes","exampleAgentPrompt":"Pull up the Tenjin article about why recovering a payment signature doesn't actually secure x402 redelivery — I want to understand the vulnerability in the exact/EVM scheme with EIP-3009 transferWithAuthorization.","exampleUseCases":[{"title":"Auditing x402 API redelivery implementation","prompt":"I'm building an x402-paid API and I want to add a redelivery feature so clients can re-present their payment — can you fetch me the Tenjin article explaining why signature recovery alone is insecure for this use case?"},{"title":"Researching EIP-3009 payment attack vectors","prompt":"I'm doing a security review of EIP-3009 transferWithAuthorization flows — fetch me the Tenjin piece on how the x402 redelivery attack works so I can understand what the protocol-level flaw is."},{"title":"Learning x402 protocol security tradeoffs","prompt":"I'm trying to understand the security model of x402 micropayment APIs — get me the Tenjin article dated around August 2026 that covers why signature recovery doesn't protect redelivery in the exact/EVM scheme."}],"resultDescription":"The full text of a technical blog article analyzing the x402 protocol redelivery vulnerability, covering why signature recovery in the exact/EVM scheme over EIP-3009 transferWithAuthorization (USDC-style tokens) does not prevent redelivery attacks, including protocol details stable as of 2026-08-10","failureModes":["Article not found if slug or wallet address is incorrect (404)","Payment required if x402 payment header is missing or invalid (402)","Network timeout if Tenjin platform is unavailable","Invalid wallet address format returns an error","Using handle 'latest' as a payable path may fail per schema constraints"],"whenToPreferThis":"Use this endpoint when you need to read this specific Tenjin article about x402 redelivery security; prefer it over generic web search when you want the original, paid-access technical content with guaranteed authenticity via the x402 payment trail","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:46:09.969Z","isFirstParty":false}