started · updated
University of Massachusetts researchers reveal Zombie Card contactless payment exploit
Researchers at the University of Massachusetts Amherst have identified a security vulnerability dubbed the “Zombie Card” attack, which allows expired Visa contactless credit cards to be used for real in-store purchases. The exploit does not involve breaking the card’s cryptography but instead utilizes a man-in-the-middle (MitM) relay attack via near-field communication (NFC).
By using two smartphones to create a digital bridge between an expired card and a point-of-sale (POS) terminal, attackers can intercept the data exchange and rewrite the expiration date to a current one. This works because the expiration data in certain Visa contactless implementations is not cryptographically bound to the transaction, allowing it to be modified without detection.
The study, presented at the 35th USENIX Security Symposium, found that while major networks like Mastercard, American Express, and Discover were resistant, the vulnerability specifically impacts Visa contactless (Kernel 3) implementations. Testing across five major US banks showed varying levels of protection; some banks detected the modification, while others accepted the altered expiration dates and even allowed transactions from multiple cards simultaneously.
Entities
Muhammad Taqi Raza · Raja Hasnain Anwar · USENIX Security Symposium · University of Massachusetts Amherst · Visa