vape-x402.vapex402.workers.dev/scan/exploit_check
1.Catalog declaration
| Resource URL | https://vape-x402.vapex402.workers.dev/scan/exploit_check |
| Source | cdp_bazaar |
| Declared method | GET |
| Network | eip155:8453 |
| Receiving address | 0x8aab9a6d28e9aba2a15a613c90f24f352f0cce15 |
| Declared price (base units) | 10000 |
| Catalog status | active |
| First seen / last seen | 2026-08-14 08:39 UTC / 2026-09-29 01:02 UTC |
| Catalog-reported calls / payers (30d) | 2 / 2 |
2.Probe history
| Probed at | Method | Verdict | HTTP | Latency | Reason |
|---|---|---|---|---|---|
| 2026-09-29 04:40 UTC | GET | pass | 402 | 558 ms | — |
| 2026-09-28 13:40 UTC | GET | pass | 402 | 774 ms | — |
| 2026-09-27 16:40 UTC | GET | pass | 402 | 7301 ms | — |
| 2026-09-26 22:40 UTC | GET | pass | 402 | 1305 ms | — |
| 2026-09-26 04:40 UTC | GET | pass | 402 | 514 ms | — |
| 2026-09-25 13:40 UTC | GET | pass | 402 | 2552 ms | — |
| 2026-09-24 16:40 UTC | GET | fail | — | 10004 ms | timeoutNo response headers arrived within 10 seconds. |
| 2026-09-23 22:40 UTC | GET | pass | 402 | 8530 ms | — |
| 2026-09-23 04:40 UTC | GET | pass | 402 | 1232 ms | — |
| 2026-09-22 13:40 UTC | GET | pass | 402 | 293 ms | — |
| 2026-09-21 16:40 UTC | GET | pass | 402 | 866 ms | — |
| 2026-09-20 22:40 UTC | GET | pass | 402 | 699 ms | — |
| 2026-09-20 04:40 UTC | GET | pass | 402 | 754 ms | — |
| 2026-09-19 13:40 UTC | GET | pass | 402 | 561 ms | — |
| 2026-09-18 16:40 UTC | GET | pass | 402 | 623 ms | — |
| 2026-09-18 04:40 UTC | GET | pass | 402 | 647 ms | — |
| 2026-09-17 13:40 UTC | GET | pass | 402 | 614 ms | — |
| 2026-09-16 16:40 UTC | GET | pass | 402 | 577 ms | — |
| 2026-09-15 16:40 UTC | GET | pass | 402 | 6978 ms | — |
| 2026-09-15 04:40 UTC | GET | pass | 402 | 641 ms | — |
| 2026-09-14 13:40 UTC | GET | pass | 402 | 1088 ms | — |
| 2026-09-13 22:40 UTC | GET | pass | 402 | 299 ms | — |
| 2026-09-13 04:40 UTC | GET | pass | 402 | 285 ms | — |
| 2026-09-12 16:40 UTC | GET | pass | 402 | 393 ms | — |
| 2026-09-11 22:40 UTC | GET | fail | — | 10000 ms | timeoutNo response headers arrived within 10 seconds. |
| 2026-09-11 13:40 UTC | GET | fail | — | 10002 ms | timeoutNo response headers arrived within 10 seconds. |
| 2026-09-10 17:40 UTC | GET | pass | 402 | 331 ms | — |
| 2026-09-10 05:40 UTC | GET | pass | 402 | 165 ms | — |
| 2026-09-09 17:40 UTC | GET | pass | 402 | 561 ms | — |
| 2026-09-09 05:40 UTC | GET | pass | 402 | 406 ms | — |
3.L1 — real purchases
2 of 2 paid attempts settled on-chain, and 2 of those also returned a 2xx response (delivered). Each settled row carries its on-chain transaction hash, and that transaction is the evidence. On this page a receipt means the seller's own settlement receipt (PAYMENT-RESPONSE); a settled row can have none (see “tx from our index”). A settled row reads as nonce-bound when the on-chain re-read also matched the one-time signature nonce we generated for that purchase, and amount + payee when it matched amount, payee, asset and chain with no nonce on record — the binding shipped on 2026-09-04, so earlier rows carry the weaker evidence and keep their label rather than being demoted (methodology). settled is the transfer we confirmed on-chain; delivered is the response arriving. A settled row whose paid request answered 5xx counts as settled and not as delivered — definitions.
Terms in this table
settled (nonce-bound)- vet402 confirmed the USDC transfer on-chain, and the on-chain re-read also matched the one-time nonce vet402 signed for that purchase.
settled (amount + payee)- vet402 confirmed the USDC transfer on-chain; the on-chain re-read matched amount, payee, asset and chain; no nonce was on record (rows before 2026-09-04).
L2 no_declaration- the listing declares no output schema to check the response against.
Whose side- the same words as the seller page: seller's side only after failures on two different days (UTC), marked “under re-check”; vet402's side; or not sorted (the rules).
| Attempted at | Result | HTTP | On-chain tx | Latency |
|---|---|---|---|---|
| 09-11 01:022026-09-11 01:02 UTC | settled (nonce-bound) | 200 | 0x52015bb0…ea7a | 1799 ms |
| 10000 units (≈ $0.01 USDC) · L2 no_declarationWhose side: no failure (delivered) | ||||
| 09-03 01:012026-09-03 01:01 UTC | settled (amount + payee) | 200 | 0x63d5e607…5a73 | 1488 ms |
| 10000 units (≈ $0.01 USDC) · L2 no_declarationWhose side: no failure (delivered) | ||||
Embed this record
Run this endpoint? Show the settle-through record vet402 measured — the badge reads 2/2 settled · 2 delivered and updates as the record grows. It carries the host it is about and the date it was last measured, so a saved copy cannot pass itself off as current. It states a measurement, not a rating.
[](https://vet402.com/observatory/e/5a79e482-8645-4729-be5c-bad699e4e4fe)4.Catalog listing events
| Detected on | Event | Before | After |
|---|---|---|---|
| 2026-09-09 | relisted | {"status":"delisted"} | {"status":"active"} |
| 2026-09-08 | delisted | {"status":"active"} | {"status":"delisted"} |
unverified is not a failure; a fail is published only after two consecutive failing probes. Definitions: methodology.
5.Dispute this record
Think a measurement above is wrong? Say which probe or purchase and what you observed instead. One person reads it and replies. The record is never deleted on dispute: if it was wrong, the correction is published with the same weight; if it was right, it stands. Operators who control the receiving address can also sign a dispute via POST /api/v1/observatory/disputes (API reference), which re-measures through the normal publication gate.