you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 17 min ago 255 onions tracked
home / news / security
24 August 2026 security 5 min read

Zombie Card Attack: Researchers Revive Expired Visa Cards for Contactless Payments

The conventional wisdom about an expired payment card is simple: once the printed date passes, the plastic is inert. Research presented at the 35th USENIX Security Symposium in August 2026 shows that this assumption depends on which part of the payment chain you ask. A team at the University of Massachusetts Amherst demonstrated what they call the Zombie Card attack: an expired Visa contactless card completing genuine in-store purchases because the terminal was shown a future expiry date while every cryptographic check on the card itself still passed.

It bears stating up front that nothing here involves breaking card cryptography. No keys were extracted and no signatures were forged. The finding is about a gap between two records of the same fact, and about banks that assume someone else already checked.

Two expiry dates, one card

Card expiry appears twice in a Visa contactless transaction, and different parties consume each copy. The terminal evaluates its processing restrictions against the Application Expiration Date carried in TLV tag 5F24. The issuing bank, by contrast, derives expiry from the Track 2 Equivalent Data in tag 57, which travels inside the online authorization request. According to the researchers, Visa's Kernel 3 does not require those two representations to be consistently bound, and the fast Dynamic Data Authentication signature the terminal verifies excludes tag 5F24 entirely. The date the terminal reads is, as lead author Raja Hasnain Anwar put it in a university release covered by The Hacker News, not cryptographically protected. That asymmetry is the whole trick. An attacker who can sit between the card and the terminal rewrites the terminal-facing date to a future value and leaves Track 2 untouched. The card signs exactly what it would sign in any legitimate transaction, so its responses remain valid, and the issuer receives a cryptogram that looks ordinary.

The relay: two phones and patience

The experimental setup used two ordinary Android smartphones as an NFC relay. One phone powers and interrogates the expired card, harvesting its genuine responses; the other presents them to a commercial point-of-sale terminal, altering the expiry value in flight. The added latency stayed within the payment system's normal response allowances, so no timeouts occurred. In testing across real merchants and commercial terminals, the underlying issue surfaced at $1, $100, and $500 transactions when terminal and issuer conditions aligned. The team used their own cards, informed the merchants involved, and paid every charge in full.

A familiar playbook for EMV researchers

Relay-based tampering against EMV is not new. In 2020 and 2021, researchers at ETH Zurich showed that an Android man-in-the-middle app could tell a terminal that PIN verification had happened on the cardholder's device, enabling high-value Visa contactless payments without a PIN, as documented in ETH Zurich's coverage of the work. The same line of research demonstrated a second attack in which a terminal accepts an unauthentic offline transaction, complete with a wrong Application Cryptogram, only for the issuer to decline it after the goods have left the store. The common thread is that EMV distributes trust decisions across card, terminal, acquirer, network, and issuer, and each party holds only a fragment of the picture. The Zombie Card result applies that structure to card lifecycle rather than cardholder verification.

Why the carding scene pays attention

Any technique that changes what counts as a usable card ripples into the trade in stolen payment data. Card shops and dump vendors price inventory largely on validity, and expired records are normally written off as worthless stock, a dynamic we described in the card shop ecosystem landscape. A demonstration that expired plastic can transact, even under narrow conditions, is therefore newsworthy to that audience even though the economics barely move: this attack needs the physical card and sustained NFC proximity to it, not a dump file sold by number. There is no bulk angle, and the researchers reported no exploitation in the wild as of publication.

Where the attack stops

The limits are substantial. The tested configuration affected Visa contactless only; the Mastercard, American Express, and Discover configurations in the study rejected altered expiry data. Results varied sharply by bank: some issuers declined the modified transactions or prompted for the replacement card, while others approved them. The attack also presupposes that the account remains open under the same primary account number, which is standard when an issuer ships a replacement, and that the bank does not independently re-check the specific card's status during authorization. It further requires physical possession of an intact expired card, meaning a card cut through the chip is useless. Digital wallets such as Apple Pay and Google Pay fared better in testing because their payment tokens are managed centrally. Finally, the optional Relay Resistance Protocol can detect an inserted relay, but it was not enabled on any tested card or terminal.

What issuers can actually do

The paper's core recommendation is to make expiry an end-to-end property instead of a local terminal check. Concretely, that means binding the terminal-facing expiry date into authenticated data, having issuers verify the status of the exact card rather than merely the account during online authorization, and treating terminal offline approvals with appropriate skepticism. Merchants gain little to configure themselves; the fix lives in kernel specifications and issuer logic. For cardholders, the guidance is unchanged and mundane: destroy the chip and magnetic stripe of expired cards, or return them through your bank's approved channel. As of publication, Visa's red team was still reproducing the report, no CVE had been assigned, and neither Visa nor the notified banks had confirmed a mitigation, according to the USENIX Security '26 paper. Until expiry checks are consistent across the chain, the drawer full of old cards deserves slightly more respect than it usually gets.

more notes

all news ›