
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@agentbadge/circle-payments
Advanced tools
Circle Gateway nanopayments + x402 payment rails (Base Sepolia, Arc) for AgentBadge — trusted agent payments
Circle Gateway nanopayments + x402 payment rails for AgentBadge — trusted agent payments on Base Sepolia and Arc.
This package is the single boundary for everything payment-related in the AgentBadge server: x402 scheme registration, payment routing, Hono middleware, identity extensions, failure ledger, pricing, payment status / history, and the ERC-8183 agentic-commerce escrow stack on Arc.
All Circle SDK (@circle-fin/x402-batching) and x402 (@x402/core,
@x402/evm) usage stays inside this package. Server code imports only
from @agentbadge/circle-payments — never from the underlying SDKs directly.
BatchFacilitatorClient + GatewayEvmScheme)exact scheme via a facilitator
(Base Sepolia)eip3009-client-broadcast — Arc self-settle: the buyer broadcasts
transferWithAuthorization themselves (gas paid in USDC, Arc's native
token — zero ETH, no facilitator), the server verifies the on-chain
receiptrequirePayment Hono middleware — 402 challenge → verify → settle →
receipt headers, with identity extension injectionpassportTokenId, readinessScore, verifyUrl) into 402 responsescreateJob → setBudget → fund → submit → evaluate → complete), evaluator with verdict store, and
commission split to treasuryflowchart LR
subgraph Server["Hono server"]
MW["requirePayment()<br/>middleware"]
RT["createPaymentRouter()<br/>router.ts"]
PR["PRICE_TABLE<br/>pricing.ts"]
ID["identityExtension()<br/>identity.ts"]
LG["FailureStore<br/>ledger.ts"]
end
subgraph Schemes["Scheme handles (schemes/)"]
GW["Gateway batch<br/>gateway.ts"]
EX["Exact EIP-3009<br/>exact.ts"]
AS["Arc self-settle<br/>arc-self-settle.ts"]
end
subgraph Escrow["Agentic commerce (escrow/)"]
E8["createErc8183()<br/>erc8183.ts"]
EV["createEvaluator()<br/>evaluator.ts"]
CM["createCommissionSplitter()<br/>commission.ts"]
end
subgraph Ext["External"]
FAC["x402.org facilitator"]
CGW["Circle Gateway"]
ARC["Arc testnet<br/>USDC 0x3600…0000"]
E8183["ERC-8183 AgenticCommerce<br/>0x0747…4583"]
end
MW --> RT
MW --> ID
MW --> LG
RT --> GW & EX & AS
GW --> CGW
EX --> FAC
AS --> ARC
E8 --> E8183
EV --> E8
CM --> E8183
sequenceDiagram
participant A as Buyer agent
participant S as Server (requirePayment)
participant R as PaymentRouter
participant F as Facilitator / Arc RPC
A->>S: GET /resource (no payment)
S->>R: buildAccepts(price, payTo)
R-->>S: accepts[] (gateway, exact, arc-broadcast)
S-->>A: 402 + PAYMENT-REQUIRED (+ agentbadge ext)
A->>A: pick rail, sign EIP-3009
alt Arc self-settle
A->>F: broadcast transferWithAuthorization (gas in USDC)
F-->>A: txHash
end
A->>S: GET /resource + payment-signature
S->>R: verify(payload, requirements)
alt exact / gateway
R->>F: facilitator verify+settle
else arc self-settle
R->>F: getTransactionReceipt(txHash)<br/>check Transfer log + replay
end
F-->>R: settled
R-->>S: SettleResult
S-->>A: 200 + PAYMENT-RESPONSE + body
stateDiagram-v2
[*] --> Open: client createJob(provider,<br/>evaluator, expiredAt, description)
Open --> Funded: provider setBudget +<br/>client approve USDC + fund
Funded --> Submitted: provider submit(deliverable)
Funded --> Expired: claimRefund (past expiredAt)
Submitted --> Completed: evaluator complete<br/>(escrow → provider, fee → treasury)
Submitted --> Rejected: evaluator reject<br/>(escrow → client)
Submitted --> Expired: claimRefund (past expiredAt)
Completed --> [*]
Rejected --> [*]
Expired --> [*]
npm install @agentbadge/circle-payments
# peer: hono ^4.7.0
import { createPaymentRouter, requirePayment } from "@agentbadge/circle-payments";
const router = createPaymentRouter({
gateway: true, // Circle Gateway batch rail
exact: true, // EIP-3009 exact via facilitator
arcSelfSettle: true, // eip3009-client-broadcast on Arc
facilitatorUrl: "https://x402.org/facilitator",
payTo: "0x…", // seller EOA
identityLookup, // optional: seller → passport
});
app.get("/api/paid", requirePayment(router, { price: "$0.001" }), (c) =>
c.json({ data: "premium" }),
);
import { createErc8183, createEvaluator, splitPayout } from "@agentbadge/circle-payments";
const escrow = createErc8183({ read: publicClient });
const { jobId } = await escrow.createJob(clientWallet, {
provider, evaluator, expiredAt, description,
});
// provider: setBudget → client: approve + fund → provider: submit
const evaluator = createEvaluator({ escrow, wallet: evaluatorWallet, verify });
const verdict = await evaluator.evaluate(jobId); // → complete / reject / expired
| Export | Purpose |
|---|---|
createPaymentRouter, buildAccepts | Rail registry + 402 accepts generation |
requirePayment | Hono middleware: 402 → verify → settle → receipt |
registerGatewayScheme, registerExactScheme, registerArcSelfSettleScheme | Scheme registration on x402ResourceServer |
BASE_SEPOLIA, ARC_TESTNET, ARC_CONTRACTS, getChain | Chain configs (CAIP-2, USDC, RPC) |
identityExtension | AgentBadge passport extension for 402 responses |
PRICE_TABLE, getPrice, validatePriceTable | Route pricing config |
createPaymentStatusLookup | Payment status by tx hash / gateway transfer |
createMemoryFailureStore | Failure ledger (alerts on repeated failures) |
createErc8183, createJobRegistry, jobDescription | ERC-8183 job lifecycle + registry |
createEvaluator, createEvaluationStore | Evaluator verdicts + on-chain settle |
splitPayout, createCommissionSplitter | Fee split to treasury (BPS) |
createErc8004Mirror | Passport registration in ERC-8004 registry |
verifyPassport | Buyer-side helper: 402 response → trust score |
createMemoClient | Arc Memo contract metadata on settlement txs |
eip155:5042002 · USDC: 0x3600000000000000000000000000000000000000{name:"USDC", version:"2", chainId:5042002, verifyingContract: USDC}maxFeePerGas ≥ 20 Gwei, maxPriorityFeePerGas 0–1 Gwei,
~65k gas per transferWithAuthorization — paid in USDC (6 dec)0x0747EEf0706327138c69792bF28Cd525089e45830x5294E9927c3306DcBaDb03fe70b92e01cCede505MIT
Part of AgentBadge — support@agentbadge.xyz
FAQs
Circle Gateway nanopayments + x402 payment rails (Base Sepolia, Arc) for AgentBadge — trusted agent payments
The npm package @agentbadge/circle-payments receives a total of 1,209 weekly downloads. As such, @agentbadge/circle-payments popularity was classified as popular.
We found that @agentbadge/circle-payments demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.