We tested the payment-gateway callback spoof exploit on a staging Stripe account—successfully forged ‘payment_intent.succeeded’ events. Seller warned about narrow patch window; indeed fixed ~10 days later. Still closed a critical finding for our client. Great ROI at $3k.