Expired credit cards revived by researchers to make unauthorized payments
Researchers from the University of Massachusetts Amherst have shown that certain expired contactless credit cards can still be used to make payments, exposing a flaw in how card issuers and payment terminals verify expiry dates. The findings, presented at the USENIX Security 2026 conference in a paper titled "Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments," matter because they reveal inconsistent enforcement within the widely used EMV contactless payment standard, potentially allowing fraudulent transactions on cards that should have been rejected.
The team, led by doctoral candidate Raja Hasnain Anwar alongside Gerard DeCunha and Muhammad Taqi Raza, found that Visa's contactless kernel does not cryptographically bind the expiry date shown to the terminal to the one used by the card issuer during authorisation, unlike Mastercard, American Express and Discover, whose systems resisted the attack. Using NFC proxy devices to intercept and tamper with communication between card and terminal, the researchers successfully revived expired Visa cards, though success ultimately depended on how the individual issuing bank handled the transaction, with some banks blocking it and others not.
- Researchers revived expired contactless credit cards to make payments
- Flaw found in Visa's EMV kernel, not Mastercard, Amex or Discover
- Attack relied on NFC proxy devices intercepting card-terminal communication