started · updated
Visa contactless cards vulnerable to expiration date tampering
Researchers at the University of Massachusetts Amherst have demonstrated a vulnerability that allows expired Visa contactless credit cards to complete real-world purchases. Presented at USENIX Security 2026, the study, titled “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments,” details how a man-in-the-middle (MitM) attack can exploit weaknesses in the EMV contactless protocol.
The attack utilizes two NFC-enabled smartphones acting as a relay. One device activates the expired card to pull payment data, while the second device intercepts the data via Wi-Fi and rewrites the unprotected expiration date to a future value before passing it to the payment terminal. Because the expiration date field in Visa’s Kernel 3 software is not end-to-end integrity protected, the terminal can be fooled into accepting the transaction.
While the researchers successfully performed transactions at live retail and grocery merchants, the scope appears limited to Visa. Other major payment networks, including Mastercard, American Express, and Discover, reportedly rejected the tampered transactions during testing.
Entities
USENIX Security · University of Massachusetts Amherst · Visa