Home Cyber Security News “Zombie Card” Attack Lets Expired Visa Cards Make Contactless Payments

“Zombie Card” Attack Lets Expired Visa Cards Make Contactless Payments

0

A newly demonstrated practical NFC relay attack can make certain expired Visa contactless cards appear valid at point-of-sale terminals.

Dubbed “Zombie Card,” the technique was presented by researchers at the University of Massachusetts Amherst, Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza, at USENIX Security ’26.

The finding challenges the belief that a card becomes cryptographically unusable once its printed expiry date passes. In the affected payment flow, expiry is handled as a terminal-side policy check rather than as a cryptographic property of the card.

“Zombie Card” Attack Lets Expired Visa Cards

The chip’s private keys can remain operational beyond the printed expiration date, leaving the payment terminal to read and locally validate the Application Expiration Date.

EMV ecosystem (Source: usenix)

USENIX found that Visa’s EMV contactless implementation, Kernel 3, does not adequately bind the expiration field to cryptographically authenticated transaction data.

This creates an opportunity for an attacker to change a past expiration date to a future date while the transaction is in progress. Unlike cloning, the attack requires access to the legitimate physical card.

The attacker does not extract the chip’s secret keys or generate a counterfeit payment credential. Instead, the technique manipulates the communication between a card and terminal, causing the terminal to process a valid card as if it had not expired.

The proof of concept relies on two NFC-capable Android devices connected over Wi-Fi. One device acts like a payment terminal to communicate with the physical expired card, while the other behaves like the card when placed near a merchant’s contactless POS system.

As the devices relay EMV Application Protocol Data Units, or APDUs, between the genuine card and the real terminal, the attacker rewrites the expiration-date field.

Architecture of NFC (Source: usenix)

This modification occurs during the data-retrieval phase of the transaction. Because the altered Visa Kernel 3 field is not protected in the same way as the signed transaction data, the terminal’s expiration check can accept the modified value without detecting tampering.

The team evaluated other major contactless EMV kernels, including Mastercard Kernel 2, American Express Kernel 4, and Discover Kernel 6.

In those implementations, attempts to manipulate expiry-related data disrupted signatures or integrity checks, preventing the transaction from completing.

Visa Kernel 3 was the outlier. The terminal’s expiration value could be modified while preserving the cryptographic checks required to continue the transaction.

Experimental setup (Source: usenix)

Researchers also reported that issuer behavior varied: some banks rejected payments involving expired cards, while at least one issuer reportedly approved transactions because its authorization process validated the account and payment cryptogram without sufficiently enforcing the specific card’s expiration or replacement status.

The research shows that card expiration should not rely solely on terminal-side validation. If the terminal’s result is not reliably reported to the issuer, or if the issuer does not independently enforce expiration and card-replacement status, an old physical card may retain an avenue for authorization.

The researchers disclosed the issue to Visa and affected financial institutions in 2025. Proposed fixes include cryptographically authenticating expiry data, ensuring issuers receive accurate terminal-verification results, and treating expiration and replacement as mandatory issuer-side authorization conditions.

Until payment networks deploy systemic fixes, consumers should securely destroy expired or replaced cards by cutting through both the EMV chip and the magnetic stripe, rather than discarding them intact.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version