Who paid the x402 doors?
Wash-adjusted x402 activity on Base, 2026-09-25 (UTC).
Published by Council of AI (CSOAI Ltd, registered in England and Wales, no. 16939677). Record as of 2026-09-26 15:22:43 UTC; signed with the board key and timestamped.
Measurement, not endorsement or accusation. This page names no seller, payer or index, and scores none. Every class below is a structural fact about addresses and amounts, such as “the payer is the payee”. None says why anyone paid. Where public chain data cannot answer a question, we say UNCHECKABLE and give no number.
Summary
We asked one question. Of the USDC payments on Base that reached a payee listed in the two public x402 Bazaars on 2026-09-25, how many came from distinct outside wallets? The rest came from the payee itself, a sibling payee of the same seller, another listed payee, or an amount below any price the payee lists.
Settlements to listed payees
28,122
Distinct payers
1,073
Settlements from outside wallets (EXTERNAL)
27,809 (98.9%)
Distinct outside payers
1,047
USDC settled, all classes
713.62 USDC
USDC from outside wallets
711.13 USDC (99.7%)
The payees come from 1,757 addresses that 2,481 listed hosts name for USDC on Base. 453 of them received at least one settlement that day, and 439 received one from an outside wallet.
Read this with the next section. “Outside wallet” means only that the address is not linked to the payee in any way public data shows. Someone who pays themselves from a fresh address looks exactly like a customer. So the external share above is an upper bound on real outside demand. It is not an estimate of it.
Every settlement, by class
Each settlement gets the first class that fits, in this order.
| Class | What it means | Settlements | Share | USDC | Distinct payers |
|---|---|---|---|---|---|
SELF_SAME_ADDRESS | payer == payee | 63 | 0.2% | 1.12 USDC | 7 |
SELF_SAME_LISTING | payer is another payee listed by a host that also lists this payee | 18 | 0.1% | 0.04 USDC | 4 |
ESTATE_SELF | payer or payee is a wallet CSOAI declares its own (estate_wallets) | 0 | 0.0% | 0.00 USDC | 0 |
PAYER_IS_LISTED_PAYEE | payer is itself a listed payee anywhere in either Bazaar | 42 | 0.1% | 0.26 USDC | 9 |
ZERO_VALUE | value == 0 | 0 | 0.0% | 0.00 USDC | 0 |
BELOW_SMALLEST_PRICE | 0 < value < the smallest price any Bazaar listing asks of this payee | 190 | 0.7% | 1.07 USDC | 19 |
EXTERNAL | none of the above | 27,809 | 98.9% | 711.13 USDC | 1,047 |
Also excluded before classing: 358 inbound USDC transfers (42,500.95 USDC) to listed payees that did not come through EIP-3009 transferWithAuthorization. That is the path the x402 “exact” scheme uses for USDC, so these transfers are not counted as x402 settlements.
Repeat payers and concentration
Paying the same seller again is normal. A buyer who comes back is the best sign a service is useful. So repeat payers are flagged, not excluded. What the flags show is how much of the activity comes from a few wallet-and-payee pairs.
| Flag | All classes: settlements | Share of all | EXTERNAL: settlements | Share of EXTERNAL |
|---|---|---|---|---|
| Payer paid this payee 2 or more times that day | 27,318 | 97.1% | 27,015 | 97.1% |
| Payer paid this payee 100 or more times that day | 16,945 | 60.3% | 16,823 | 60.5% |
- Outside payers who paid exactly once that day: 446 of 1,047.
- The single largest outside payer sent 3.4% of the outside USDC. The ten largest sent 28.9%.
- Outside payers above a size floor. Our class rule has no fixed “test amount” cut-off. It compares each payment with the payee’s own smallest listed price. For readers who want a fixed floor, here are the counts: 828 paid at least 0.01 USDC in one settlement; 378 paid at least 0.10 USDC in one settlement; 29 paid at least 1.00 USDC in one settlement.
What we cannot see
Public chain data cannot answer these questions. Each one is UNCHECKABLE, and none is estimated:
- common control of payer and payee through different addresses (only same-address, same-listing and listed-payee links are observable).
- whether any service was delivered after payment.
- whether a person, an agent or a script initiated a payment.
- whether an EIP-3009 transfer answered an x402 challenge rather than another EIP-3009 flow.
- payments to payees that neither Bazaar lists.
Not measured in this record:
- every network other than Base mainnet (see population.accepts_entries_not_measured).
- facilitator identity (transaction sender) - not read.
- the x402 schemes other than exact (e.g. batch-settlement escrows).
| Network | asset | scheme | Listings |
|---|---|
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp|other-asset|exact | 7,961 |
eip155:137|other-asset|exact | 3,211 |
eip155:42161|other-asset|exact | 2,554 |
eip155:84532|other-asset|exact | 1,173 |
eip155:143|other-asset|exact | 886 |
xrpl:0|other-asset|exact | 717 |
eip155:8453|usdc-base|upto | 706 |
eip155:4663|other-asset|exact | 704 |
Method
- Payees. We walked both public x402 Bazaar discovery indexes (Coinbase CDP and PayAI) to their stated totals: 24,556 listings read, CDP complete: true, PayAI complete: true. We kept every payment option with scheme “exact”, network Base mainnet and asset native USDC. Its payTo address is a listed payee, and the smallest amount any listing asks of that address is its smallest listed price.
- Window. Blocks 51,752,527 to 51,795,726 (43,200 blocks). These are the first and last Base blocks of 2026-09-25 UTC, checked at both boundaries.
- Unit. one USDC Transfer log to a listed payee, in a transaction that also carries a USDC AuthorizationUsed log whose authorizer is the transfer's sender (EIP-3009 transferWithAuthorization).
- Classes. First match wins, in the order of the table above. CSOAI’s own wallets are listed in the record and classed ESTATE_SELF, so our own test payments never count as outside demand.
- Headline rule. distinct_external_payers = distinct senders with >= 1 EXTERNAL settlement.
- Reads. Public RPC (
https://mainnet.base.org, https://base.drpc.org), 122 calls, in chunks of 2,000 blocks. A chunk that errors is split, never skipped. The run fails closed if either Bazaar read is short. - Schedule. The record is produced every day after the x402 conformance read, for the previous full UTC day. This page shows the signed record for 2026-09-25.
What others have measured
Their findings, not ours. The methods, networks and windows differ, so these figures cannot be combined with each other or with ours. We quote each source word for word, from the bytes we read (sha256 given).
Visa (with Artemis Analytics): Agentic Payments: What Onchain Data Reveals
Last updated on July 14, 2026. Read 2026-09-26 15:20:16 UTC; sha256 7a1c5e0a4911eb91…
- “it has processed roughly $15.0 million in adjusted volume across 109.6 million transactions.”
- “All transaction figures in this article are adjusted totals that exclude identified wash and test activity, taken from the joint Visa and Artemis report and based on Artemis Analytics onchain data as of April 21, 2026.”
Visa (with Artemis Analytics): Agentic payments report (PDF linked from the page above)
JULY 2026 (cover). Read 2026-09-26 15:11:48 UTC; sha256 0d6a4a20419053f3…
- “has processed over $135.7M in volume across 178.3M transactions since May 2025.”
- “All transaction figures cited in this section are cumulative raw onchain totals from Artemis Analytics as of April 21, 2026.”
Derived by us: share of raw x402 dollar volume not in Visa/Artemis's adjusted total = 1 - 15.0 / 135.7 = 88.9%. CSOAI, from the two figures quoted above; Visa and Artemis state the two totals, the subtraction is ours.
TRM Labs: Who's Actually Paying? Measuring AI Agent Payments Onchain
September 9, 2026. Read 2026-09-26 15:20:16 UTC; sha256 0f1403572e2783c1…
- “TRM identified roughly USD 52.7 million across 198.9 million settlement transactions mediated by known x402 facilitators since May 2025.”
- “About half of settled volume falls away once self-payment, bulk flows, and thin-buyer sellers are removed.”
- “Applied to the USD 25.62 million of screened x402 commerce, the two tests put the share that appears to be agentic at between 0.6% and 7.5% .”
x402.org (project site): x402.org home page counters
counters labelled 'Last 30 Days'. Read 2026-09-26 15:20:15 UTC; sha256 359d4427b1e63dc1…
- Shown on the page: “75.41M · Transactions · $24.24M · Volume · Last 30 Days”
The same two figures appear in every capture we read, from 2026-09-01 (earliest capture read) to 2026-09-26 (live read): 20260901, 20260903, 20260907, 20260910, 20260917, 20260922. We state only that the figures did not change across these reads. We do not know why.
Our own doors
CSOAI runs x402 doors too. Our own count of distinct outside payers, which excludes our own wallets and any settlement of zero, is served live at /api/revenue as one_number. It comes from our facilitator-confirmed settlement records, not from this chain read. We give the link rather than a copy, so the figure is never stale.
How to verify
- Record: x402-activity-2026-09-25.json. Signature: .signed.json. Timestamp: .json.ots (an OpenTimestamps calendar commitment until Bitcoin confirms it).
- Every settlement is one line in x402-activity-2026-09-25.rows.jsonl.gz (sha256
6a1771ef57a7d543cee8e19b47e987d0d4e0da908f77f58525217b1cc2e1d875). Every payee is one line in x402-activity-2026-09-25.payees.jsonl.gz (sha256951d0026e14af408da138b8c4be65f4ec9212934a7a6a77e3fd27dcef168fba1). Both hashes are in the record, so the signature covers them. - Check the signature. Canonicalise the
payloadin the .signed.json: JSON, keys sorted, no whitespace, UTF-8. Its sha256 must equalsignature.payload_sha256, andpayload.artifact.sha256must equal the sha256 of the record file. Then verifysig_ed25519with the Ed25519 key#board-attestation-1in csoai.org/.well-known/did.json. - Re-run it: the verify note in the record lists the steps. The code is the file named in
method.code, with its sha256. - Context sources: context.json (signed: context.signed.json).
Object, or ask for a re-check
If a class is wrong for a payment you made or received, or a figure here is wrong, email nicholas@csoai.org. You can also use the crawler page at /census, which explains what we read and how to object or opt out, or /dispute. Corrections are dated in our corrections ledger.