Saved in:
Bibliographic Details
Main Authors: Zhang, Yuanzhe, Xiang, Yuexin, Lei, Yuchen, Wang, Qin, Qiu, Tian, Sun, Yujing, Zarkov, Spiridon, Yuen, Tsz Hon, Deppeler, Andreas, Yu, Jiangshan, Lam, Kwok-Yan
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2604.03733
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908936912764928
author Zhang, Yuanzhe
Xiang, Yuexin
Lei, Yuchen
Wang, Qin
Qiu, Tian
Sun, Yujing
Zarkov, Spiridon
Yuen, Tsz Hon
Deppeler, Andreas
Yu, Jiangshan
Lam, Kwok-Yan
author_facet Zhang, Yuanzhe
Xiang, Yuexin
Lei, Yuchen
Wang, Qin
Qiu, Tian
Sun, Yujing
Zarkov, Spiridon
Yuen, Tsz Hon
Deppeler, Andreas
Yu, Jiangshan
Lam, Kwok-Yan
contents Agentic AI rivals human capabilities across a wide range of domains. Looking ahead, it is foreseeable that AI agents will autonomously handle complex workflows and interactions. Early prototypes of this paradigm are emerging, e.g., OpenClaw and Moltbook, signaling a shift toward Agent-to-Agent (A2A) ecosystems. However, despite these promising blueprints, critical trust and security challenges remain, particularly in scenarios involving financial transactions. Ensuring secure and reliable payment mechanisms between unknown and untrusted agents is crucial to complete a fully functional and trustworthy A2A ecosystem. Although blockchain-based infrastructures provide a natural foundation for this setting, via programmable settlement, transparent accounting, and open interoperability, trust and security challenges have not yet been fully addressed. Hence, for the first time, we systematize blockchain-based A2A payments, e.g., X402, with a four-stage lifecycle: discovery, authorization, execution, and accounting. We categorize representative designs at each stage and identify key challenges, including weak intent binding, misuse under valid authorization, payment-service decoupling, and limited accountability. We highlight future directions for strengthening cross-stage consistency, enabling behavior-aware control, and supporting compositional payment workflows across agents and systems.
format Preprint
id arxiv_https___arxiv_org_abs_2604_03733
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SoK: Blockchain Agent-to-Agent Payments
Zhang, Yuanzhe
Xiang, Yuexin
Lei, Yuchen
Wang, Qin
Qiu, Tian
Sun, Yujing
Zarkov, Spiridon
Yuen, Tsz Hon
Deppeler, Andreas
Yu, Jiangshan
Lam, Kwok-Yan
General Finance
Agentic AI rivals human capabilities across a wide range of domains. Looking ahead, it is foreseeable that AI agents will autonomously handle complex workflows and interactions. Early prototypes of this paradigm are emerging, e.g., OpenClaw and Moltbook, signaling a shift toward Agent-to-Agent (A2A) ecosystems. However, despite these promising blueprints, critical trust and security challenges remain, particularly in scenarios involving financial transactions. Ensuring secure and reliable payment mechanisms between unknown and untrusted agents is crucial to complete a fully functional and trustworthy A2A ecosystem. Although blockchain-based infrastructures provide a natural foundation for this setting, via programmable settlement, transparent accounting, and open interoperability, trust and security challenges have not yet been fully addressed. Hence, for the first time, we systematize blockchain-based A2A payments, e.g., X402, with a four-stage lifecycle: discovery, authorization, execution, and accounting. We categorize representative designs at each stage and identify key challenges, including weak intent binding, misuse under valid authorization, payment-service decoupling, and limited accountability. We highlight future directions for strengthening cross-stage consistency, enabling behavior-aware control, and supporting compositional payment workflows across agents and systems.
title SoK: Blockchain Agent-to-Agent Payments
topic General Finance
url https://arxiv.org/abs/2604.03733