SoK: Blockchain Agent-to-Agent Payments

📅 2026-04-04
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the trust and security challenges inherent in payment interactions among AI agents operating in untrusted environments. It presents the first systematic Agent-to-Agent (A2A) payment framework, introducing a four-phase lifecycle model encompassing discovery, authorization, execution, and accounting, and provides a taxonomic analysis of representative mechanisms within each phase. The work identifies critical issues—including weak intent binding, authorization abuse, decoupling of payment from service delivery, and lack of accountability—that expose fundamental design trade-offs in current architectures. Leveraging blockchain’s capabilities for programmable settlement, transparent accounting, and open interoperability, the paper further outlines promising future directions such as cross-phase consistency and behavior-aware control, thereby laying a theoretical foundation for building a trustworthy, autonomous agent-based economic ecosystem.
📝 Abstract
Agentic AI rivals human capabilities across a wide range of domains. Looking ahead, it is foreseeable that AI agents will autonomously handle complex workflows and interactions. Early prototypes of this paradigm are emerging, e.g., OpenClaw and Moltbook, signaling a shift toward Agent-to-Agent (A2A) ecosystems. However, despite these promising blueprints, critical trust and security challenges remain, particularly in scenarios involving financial transactions. Ensuring secure and reliable payment mechanisms between unknown and untrusted agents is crucial to complete a fully functional and trustworthy A2A ecosystem. Although blockchain-based infrastructures provide a natural foundation for this setting, via programmable settlement, transparent accounting, and open interoperability, trust and security challenges have not yet been fully addressed. Hence, for the first time, we systematize blockchain-based A2A payments, e.g., X402, with a four-stage lifecycle: discovery, authorization, execution, and accounting. We categorize representative designs at each stage and identify key challenges, including weak intent binding, misuse under valid authorization, payment-service decoupling, and limited accountability. We highlight future directions for strengthening cross-stage consistency, enabling behavior-aware control, and supporting compositional payment workflows across agents and systems.
Problem

Research questions and friction points this paper is trying to address.

Agent-to-Agent payments
blockchain
trust
security
financial transactions
Innovation

Methods, ideas, or system contributions that make the work stand out.

Agent-to-Agent payments
blockchain
trust and security
payment lifecycle
compositional workflows
🔎 Similar Papers
No similar papers found.
Yuanzhe Zhang
Yuanzhe Zhang
Institute of Automation, Chinese Academy of Sciences
Natural Language Processing
Y
Yuexin Xiang
Faculty of Information Technology, Monash University, Australia
Y
Yuchen Lei
School of Cyber Science and Engineering, Wuhan University, China
Qin Wang
Qin Wang
ETH Zurich
Domain AdaptationComputer Vision
T
Tian Qiu
Digital Trust Center, Nanyang Technological University, Singapore
Yujing Sun
Yujing Sun
Nanyang Technological University
AI Security & 3DV
S
Spiridon Zarkov
Zark Lab, Singapore
Tsz Hon Yuen
Tsz Hon Yuen
Monash University
CryptographyBlockchainSecurityPrivacy
A
Andreas Deppeler
School of Business, Monash University, Malaysia
J
Jiangshan Yu
School of Computer Science, University of Sydney, Australia
Kwok-Yan Lam
Kwok-Yan Lam
Nanyang Technological University
CybersecurityPrivacy-Preserving technologiesDigital TrustDistributing systemsLegalTech