An expired Visa contactless card can still pay at a terminal if an attacker relays it and rewrites one field on the way through, according to research from the University of Massachusetts Amherst. Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza of the university’s Khwarizmi Lab presented the attack, which they call Zombie Card, at the 35th USENIX Security Symposium in Baltimore on August 12–14, 2026. Technical write-ups published on August 20, 2026, set out how it works. No algorithm is broken: the attack exploits what the card’s signature covers and what it leaves out.
The expiry date travels twice, and only one copy counts for the terminal
In a contactless EMV transaction, the card sends its expiry date twice. The Application Expiration Date, tag 5F24, is what the terminal compares against its own clock. The Track 2 Equivalent Data, tag 57, carries the date the issuing bank receives in the authorization request. Both describe the same card, but they take different paths and are checked by different parties.
Visa’s contactless kernel, Kernel 3, does not require the two values to match, and the fast Dynamic Data Authentication (fDDA) signature the terminal verifies does not cover 5F24. An attacker running a relay between card and terminal can therefore push the date the terminal reads into the future while leaving the one bound for the issuer untouched. Each check passes on the value it looks at.
Four conditions have to line up for the attack to work:
- Access to the card, or NFC proximity held for the length of the exchange.
- An active relay, built in the study from two NFC-enabled Android phones, that alters tag
5F24in transit. - An account that is still open under the same primary account number (PAN), which the replacement card carried over unchanged.
- An issuer that does not recheck the expiry of the card actually presented.
Visa’s kernel was the only one of four to fail
| Kernel | Network | Result | Weakness or protection |
|---|---|---|---|
| Kernel 3 | Visa | Vulnerable | The signature the terminal verifies excludes 5F24, and nothing forces it to match 57 |
| Kernel 2 | Mastercard | Resistant | The terminal compares the two dates and rejects a mismatch |
| Kernel 4 | American Express | Resistant | The date is cryptographically bound to offline authentication |
| Kernel 6 | Discover | Resistant | Combined dynamic authentication covers the altered data objects |
Mastercard and American Express AMEX do not use stronger cryptography than Visa. Their kernels enforce a consistency check that Visa’s leaves out, and that check alone is enough to defeat the manipulation.
Expired cards paid up to $500 in testing
With an expired card, the team ran $1.00, $100.00, and $500.00 transactions on its own terminal, registered under the Professional Services merchant category, then paid $2.79 at a retailer and $3.19 at a grocery merchant. The relay added 20 to 50 ms of latency per exchange, well inside the 500 ms the EMV specification allows for each command. None of the terminals used had the Relay Resistance Protocol switched on, the optional EMV countermeasure designed to detect that kind of delay.
Issuers split on approving revived cards
Once the terminal accepted the card, the transaction went to the issuer for authorization, and that is where the results diverged. The issuer the paper calls “Bank A” approved every transaction made with its expired card, including all the purchases above. “Bank B” declined every attempt, even though the terminal had accepted each one, and told the cardholder to use the replacement card. According to Help Net Security, one major US bank’s checks “only confirm the account exists and the card number is active, without checking whether that specific card instance is still the one on file.”
No advisory yet from Visa, EMVCo, or SumUp
Visa confirmed that the report had passed initial triage and was being reproduced by its internal red team. As of August 20, 2026, The Hacker News had found no security advisory from Visa, EMVCo, or terminal maker SumUp. The researchers propose four fixes:
- Bind the expiry date to the signature, so it falls inside the signed data.
- Compare `5F24` and `57` at the terminal, and flag any mismatch instead of ignoring it.
- Authorize against the PAN and expiry date together, so the issuer checks the card presented, not just the account.
- Pass the terminal’s verdict to the issuer in the authorization request. Today it is lost along the way.
The findings do not automatically extend to France. The study did not test the application of Cartes Bancaires (CB) CB, France’s domestic card scheme. A co-badged card carries several applications and the terminal selects one, so a result on Visa’s kernel says nothing about CB. Under French law, Article L. 133-18 of the Monetary and Financial Code requires an immediate refund of an unauthorized transaction that the cardholder reports without delay.