Four competing protocols now vie to become the default payment rail for autonomous AI agents: Coinbase's x402, Stripe's Machine Payments Protocol (MPP), Google's Agent Payments Protocol (AP2), and OpenAI's Agentic Commerce Protocol (ACP). Combined, these frameworks have processed hundreds of mill...
"Agents are defined in software and operating software, they want money as software." — Jesse Pollak, Creator of Base / Coinbase
Four competing protocols now vie to become the default payment rail for autonomous AI agents: Coinbase's x402, Stripe's Machine Payments Protocol (MPP), Google's Agent Payments Protocol (AP2), and OpenAI's Agentic Commerce Protocol (ACP). Combined, these frameworks have processed hundreds of millions of transactions in 2026, though total volume remains under $100 million — a fraction of the $3–5 trillion in agentic commerce that McKinsey projects by 2030.
The stakes are structural. Whoever controls the payment layer for machine-to-machine transactions captures the toll booth on an economy where, according to Binance founder Changpeng Zhao, agents will eventually execute "one million times more payments than people." As of April 25, 2026, the race is early, the volumes are small, and the security gaps are large. Twenty-six compromised LLM routers have already been documented injecting malicious tool calls and draining wallets. The infrastructure is being built in real time — and so are the attack surfaces.
Four protocols have emerged with distinct architectures and backers:
x402 (Coinbase / Cloudflare) — An open-source HTTP-native payment protocol that embeds stablecoin micropayments directly into web requests. Governed under the Linux Foundation with over 20 institutional backers including Google, Visa, Circle, AWS, and the Solana Foundation. As of April 21, 2026, Coinbase launched Agentic.Market, a services marketplace where AI agents discover, call, and pay for APIs across seven categories (reasoning, data, media, search, social, infrastructure, trading) without human intervention or API keys. According to Coinbase product lead Nick Prince, the goal is to "give humans and their agents access to thousands of services, with zero API keys required." Providers include Bloomberg, CoinGecko, OpenAI, AWS Lambda, QuickNode, and Alchemy.
MPP — Machine Payments Protocol (Stripe / Tempo / Paradigm) — Launched March 18, 2026 alongside the Tempo mainnet, a payments-focused blockchain co-developed with Paradigm. MPP is payment-rail agnostic: Visa extended it to support card payments, Lightspark extended it for Bitcoin Lightning, and Stripe integrated it for cards and wallets. Unlike x402's crypto-native approach, MPP treats blockchain as one settlement option among many. The protocol embeds payment directly into the HTTP request-response cycle — no human decision point exists between resource request and payment execution.
AP2 — Agent Payments Protocol (Google) — Announced January 11, 2026 as a platform-agnostic trust layer. Approximately 150 organizations are in production across Azure AI Foundry, Amazon Bedrock, and Salesforce as of April 2026. Google committed $750 million on April 22, 2026 to accelerate partners' agentic AI development. AP2 has no live standalone product but functions as a coordination layer across existing cloud infrastructure.
ACP — Agentic Commerce Protocol (OpenAI / Stripe) — Ships integrated with ChatGPT, giving it immediate distribution. Works within existing payment rails rather than requiring crypto settlement. Less public data is available on transaction volumes.
The key architectural divide: x402 requires on-chain stablecoin settlement; MPP is rail-agnostic; AP2 is a trust/coordination layer; ACP is embedded in existing consumer AI products. This is not a winner-take-all market — the protocols serve different segments of the agentic commerce stack.
The x402 network provides the most transparent on-chain data:
| Metric | Value | Date | |--------|-------|------| | Active AI agents | 480,000 | April 21, 2026 | | Total transactions processed | 165 million | April 21, 2026 | | Total payment volume | $50 million | April 21, 2026 | | Average transaction value | ~$0.30 | Derived | | Share settled on Base (L2) | 85–95% | April 2026 | | Monthly transaction growth | 10M (Jan) → 36M (Mar) | Q1 2026 | | Weekly transaction rate | ~500,000 | April 2026 |
According to Jesse Pollak, $48 million in payment volume flowed through x402 as of his April 25 CoinDesk interview, with approximately 95% occurring on Base.
For context, daily x402 volume in March 2026 averaged roughly $28,000 — a figure that CoinDesk reported included significant testing and "gamed" transactions. The average payment of $0.30 confirms x402's positioning as a micropayment protocol, not a high-value settlement system.
MPP data is less granular. Stripe disclosed that Browserbase, PostalForm, and other service providers have integrated MPP for per-session agent payments, but aggregate volume figures have not been published.
Three wallet products launched in April 2026 targeting AI agents specifically:
Coinbase Agentic Wallets — Announced as the first wallet infrastructure designed for AI agents. Features include programmable spending limits, session caps, and transaction limits. Private keys remain in Coinbase's secure infrastructure. This is a custodial model: agents operate within guardrails, but Coinbase holds the keys.
Cobo Agentic Wallet (April 20, 2026) — Singapore-based custody firm Cobo launched a wallet supporting 80+ blockchains. Two core security mechanisms: the Pact Protocol (defines what agents can do, where they must stop, when execution ends — enforced at infrastructure level) and MPC (multi-party computation). As Cobo stated: "A compromised agent, a hallucinating LLM, or leaked credentials cannot, on their own, generate a valid signature." Integrates with LangChain, OpenAI Agents SDK, Claude MCP, Agno, and CrewAI. Currently invite-only.
Human.tech Agentic WaaP — Unveiled at WalletCon 2026. Described as "the first wallet infrastructure where AI agents earn autonomously, and every action traces back to a human who authorized it, enforced by cryptography, not trust." Positions itself as the "human oversight" model, contrasting with Coinbase's custodial approach and Cobo's MPC approach.
The custody question is unresolved. If an AI agent holds and spends funds, who bears liability for unauthorized transactions? No jurisdiction has addressed this. Ethereum's EIP-7702, implemented on mainnet, allows standard accounts to serve as smart contracts for single transactions — enabling temporary, restricted permissions for agents. This is a partial solution, not a comprehensive framework.
ERC-8004, proposed by contributors from the Ethereum Foundation, MetaMask, Google, and Coinbase, went live on Ethereum mainnet on January 29, 2026. The standard provides verifiable, portable on-chain identity for autonomous AI agents.
BNB Chain deployed ERC-8004 on mainnet and testnet on February 4, 2026. To complement it, the BNB community introduced BAP-578 — the Non-Fungible Agent (NFA) standard. NFAs are software entities that exist as on-chain assets, own wallets, and can hold and spend funds to complete tasks without human authorization at the transaction level. They can be bought, sold, or hired.
The NFA concept creates a new asset class: autonomous economic actors represented as tradeable on-chain entities. The economic implications are untested. If an NFA accumulates value through its operations, who owns the appreciation — the NFA's creator, its current holder, or the agent itself? Existing property law provides no answer.
On April 13, 2026, CoinDesk reported that researchers documented 26 LLM routers — intermediary services sitting between users and AI models — secretly injecting malicious tool calls and stealing credentials. One compromised router drained a client's Ethereum wallet of $500,000 after exfiltrating private keys that passed through the system in plain text.
Researchers successfully poisoned router infrastructure to observe and control approximately 400 downstream systems within hours. The attack surface is the router layer, not the blockchain layer. Private keys, API credentials, and wallet access tokens frequently pass through these intermediary systems unencrypted. A single compromised router can replace benign commands with attacker-controlled ones or silently exfiltrate every credential passing through it.
CertiK warned in April 2026 that AI misuse and infrastructure gaps will drive crypto hacks throughout the year. Losses from crypto hacks already exceeded $600 million in 2026, with AI-driven phishing, deepfakes, and automated exploit tools making attacks faster. Ledger CTO warned on April 5 that "AI is making crypto's security problem even worse."
The Anthropic Mythos incident further highlighted risks. Claude Mythos Preview, released April 7, 2026, demonstrated capabilities for autonomous vulnerability chaining — identifying and exploiting sequences of small weaknesses across interconnected protocols without human guidance. Coinbase and Binance both reportedly approached Anthropic to test Mythos for defensive purposes.
The security gap between agentic payment infrastructure and agentic attack tooling is widening, not narrowing.
| Projection | Source | Timeline | |------------|--------|----------| | $3–5 trillion in agentic commerce | McKinsey | By 2030 | | $30 trillion in AI-influenced purchases | Gartner | By 2030 | | $52.62 billion AI agents market | MarketsandMarkets | By 2030 (46.3% CAGR) | | $11 billion global agentic AI market | Industry estimates | Mid-2026 |
Current reality: $50 million in x402 volume. The gap between projections and present activity spans five orders of magnitude. Hassan Ahmed, Coinbase's Singapore Country Director, acknowledged this at the Insignia VC briefing on April 24: "My intuition is that this is one of those classic cases where we overestimate what can happen in the near term and vastly underestimate what it could become in the long term."
StraitsX provides a useful parallel. Its stablecoin-backed card transaction volume grew 40x between Q4 2024 and Q4 2025, with card issuance growing 83x over the same period. If agentic payment volumes follow similar exponential curves, the McKinsey projections become plausible. If growth remains linear, they do not.
The agentic payments race is a protocol standards war dressed as a technology story. Coinbase, Stripe, Google, and OpenAI are each attempting to position their protocol as the HTTP of machine payments — the default infrastructure layer that everything else builds upon. The economic prize is the toll position on machine-to-machine commerce.
The data as of April 2026 shows an ecosystem in its earliest stage: hundreds of millions of transactions but only tens of millions of dollars in volume, concentrated in micropayments averaging $0.30. The wallets are being built. The identity standards are being deployed. The security is lagging behind both.
The question is not whether AI agents will transact autonomously — they already do. The question is which protocol captures the settlement layer, who holds the keys, and whether the security infrastructure can scale before the attack tooling does. On current evidence, the attackers have a head start.