19.08.2026 11:11

Share with others:

Share

How can expired contactless cards become a means of payment again?

Photo: Pixabay
Photo: Pixabay

Experts from UMass Amherst University presented a study titled “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments". It detailed how expired contactless payment cards can be reused for point-of-sale purchases.

Contactless payments are based on the EMV protocol, where a card or smartphone communicates with a point-of-sale terminal using NFC technology. Messages then travel through the payment network to the bank and card issuer. Researchers warn that this process is vulnerable, as some data is transmitted between the card and the terminal in an unencrypted form and is only later combined with cryptographic verification.

This security vulnerability is open to abuse. Using two smartphones acting as NFC proxy devices, the researchers successfully carried out a man-in-the-middle attack. They found that contactless transactions on the Visa network were vulnerable to such attacks because they lacked adequate data integrity protections.

The problem lies in the so-called core EMV protocol. While Mastercard, American Express and Discover use stricter rules, Visa’s system is more “open”. With Visa cards, the expiration date read by the terminal is not cryptographically protected by a digital signature. The terminal does check the date on the card, but the issuing bank checks another piece of date information when approving. Because the two pieces of information are not cryptographically linked, an attacker can change the information seen by the terminal during transmission, while the other security elements appear to be completely valid.

Whether the attack will be successful in practice depends on the individual bank and its transaction processing. However, such findings rightly raise doubts about how thoroughly financial institutions check security standards before releasing the technology into widespread use. Research leader Raja Hasnain Anwar explained that this is a conscious adjustment between a high level of security and the speed of older terminals.

The authors notified Visa of the vulnerability in May 2025 and again in December 2025. To date, neither Visa nor any of the notified banks have confirmed that they have fixed the flaw.


Interested in more from this topic?
information security Visa card

Connections



What are others reading?