Expired credit cards revived by researchers to make unauthorized payments
Researchers affiliated with the University of Massachusetts Amherst have found that you can get payments out of certain expired contactless credit cards, a process detailed at the recent USENIX Security 2026 conference.
Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza describe their findings in a paper titled "Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments." Credit cards, the authors explain in their paper, have expiration dates, but the way these dates get checked and enforced isn't consistent.
Thus, they were able to devise an attack that makes expired contactless cards appear to be valid to payment terminals.
The Europay, Mastercard, and Visa (EMV) payment process involves a payment card (card or digital wallet in a phone) and a point-of-sale terminal communicating over a direct NFC channel, linked to a payment network (eg, Visa, Mastercard, Discover) that links the merchant to a bank and a card issuer.
The transaction process relies on the EMV contactless protocol, which the authors say is fragile because the transaction flow is selectively authenticated – some of the data gets sent between the card and terminal in plaintext and is only later linked to cryptographic verification using Offline Data Authentication (ODA) and issuer-verified cryptograms.
This leaves an opening for unwanted intermediary interference, which requires only the necessary knowledge and mobile phones acting as NFC proxies.
And indeed, the researchers demonstrated that they could meddle in a way that revives expired contactless payment cards to make purchases.
"Our results show that Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection," the authors state in their paper.
What's more, they say, the wallet Card Transaction Qualifiers settings steer transactions toward online authorization checks instead of rejecting the transaction immediately.
That shifts the enforcement burden to the card issuer where behavior varies and may rely on the POS terminal evaluation rather than conducting a full security check during transaction authorization.
The EMV protocol is implemented in EMV kernels.
American Express, Discover, Mastercard, and Visa each run their own kernels.
Visa's kernel, the authors observe, is a bit more permissive than others.
It doesn't bind the expiration date cryptographically.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.