Security· August 18, 2026 at 08:20 p.m.
Researchers Revive Expired Contactless Credit Cards for Unauthorized Payments
Key takeaways
- Researchers found a way to revive expired contactless credit cards for unauthorized payments
- Vulnerability exists in Visa's contactless payment protocol
- Different card manufacturers have different protocols leading to compromises in security checks
Researchers affiliated with the University of Massachusetts Amherst have found a way to make expired contactless credit cards appear valid to payment terminals, allowing them to make unauthorized payments. The researchers detailed their findings at the USENIX Security 2026 conference in a paper titled 'Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments'.
The Europay, Mastercard, and Visa (EMV) payment process involves a payment card and a point-of-sale terminal communicating over a direct NFC channel. The transaction process relies on the EMV contactless protocol, which the authors say is fragile due to selective authentication of data.
The researchers demonstrated that they could meddle in a way that revives expired contactless payment cards to make purchases, particularly with Visa contactless cards. They attribute this vulnerability to Visa's kernel not binding the expiration date cryptographically, allowing an attack using NFC proxy devices.
Raja Hasnain Anwar, lead author and a doctoral candidate at UMass Amherst, explained that different card manufacturers have different protocols for handling contactless transactions, leading to compromises in security checks to ensure backward compatibility with old POS terminals.
The authors notified Visa of their findings in May 2025 and followed up in December 2025. Neither Visa nor the banks notified have confirmed that they've mitigated the expiration issue.