← Back to News
Fraud

Zombie Card attack lets expired Visa cards pay contactless

UMass Amherst researchers showed that a relay can rewrite the expiry date a Visa contactless card sends to the terminal, so an expired card passes the terminal check. Whether the payment then clears is up to the issuer, and issuers disagree.

Networks mentionedAMEXCB

An expired Visa contactless card can still pay at a terminal if an attacker relays it and rewrites one field on the way through, according to research from the University of Massachusetts Amherst. Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza of the university’s Khwarizmi Lab presented the attack, which they call Zombie Card, at the 35th USENIX Security Symposium in Baltimore on August 12–14, 2026. Technical write-ups published on August 20, 2026, set out how it works. No algorithm is broken: the attack exploits what the card’s signature covers and what it leaves out.

The expiry date travels twice, and only one copy counts for the terminal

In a contactless EMV transaction, the card sends its expiry date twice. The Application Expiration Date, tag 5F24, is what the terminal compares against its own clock. The Track 2 Equivalent Data, tag 57, carries the date the issuing bank receives in the authorization request. Both describe the same card, but they take different paths and are checked by different parties.

Visa’s contactless kernel, Kernel 3, does not require the two values to match, and the fast Dynamic Data Authentication (fDDA) signature the terminal verifies does not cover 5F24. An attacker running a relay between card and terminal can therefore push the date the terminal reads into the future while leaving the one bound for the issuer untouched. Each check passes on the value it looks at.

🔑
The cryptography holds; its coverage doesn’t
The card’s cryptography is not at fault. The weak point is its scope: the date the terminal reads falls outside the signature, and any field left unsigned can be changed in transit.

Four conditions have to line up for the attack to work:

  • Access to the card, or NFC proximity held for the length of the exchange.
  • An active relay, built in the study from two NFC-enabled Android phones, that alters tag 5F24 in transit.
  • An account that is still open under the same primary account number (PAN), which the replacement card carried over unchanged.
  • An issuer that does not recheck the expiry of the card actually presented.
A card payment terminal on a store counter
The attack takes place between the card and the terminal and never touches the card network.

Visa’s kernel was the only one of four to fail

KernelNetworkResultWeakness or protection
Kernel 3VisaVulnerableThe signature the terminal verifies excludes 5F24, and nothing forces it to match 57
Kernel 2MastercardResistantThe terminal compares the two dates and rejects a mismatch
Kernel 4American ExpressResistantThe date is cryptographically bound to offline authentication
Kernel 6DiscoverResistantCombined dynamic authentication covers the altered data objects
How the four contactless EMV kernels handled a rewritten expiry date (source: USENIX Security 2026)

Mastercard and American Express AMEX do not use stronger cryptography than Visa. Their kernels enforce a consistency check that Visa’s leaves out, and that check alone is enough to defeat the manipulation.

Expired cards paid up to $500 in testing

With an expired card, the team ran $1.00, $100.00, and $500.00 transactions on its own terminal, registered under the Professional Services merchant category, then paid $2.79 at a retailer and $3.19 at a grocery merchant. The relay added 20 to 50 ms of latency per exchange, well inside the 500 ms the EMV specification allows for each command. None of the terminals used had the Relay Resistance Protocol switched on, the optional EMV countermeasure designed to detect that kind of delay.

50 ms
maximum latency the relay added per exchange
USENIX Security 2026, via The Hacker News
500 ms
EMV time limit per command
USENIX Security 2026, via The Hacker News
1 of 4
contactless kernels that failed
USENIX Security 2026, via The Hacker News
0
terminals tested with the *Relay Resistance Protocol* enabled
USENIX Security 2026, via The Hacker News

Issuers split on approving revived cards

Once the terminal accepted the card, the transaction went to the issuer for authorization, and that is where the results diverged. The issuer the paper calls “Bank A” approved every transaction made with its expired card, including all the purchases above. “Bank B” declined every attempt, even though the terminal had accepted each one, and told the cardholder to use the replacement card. According to Help Net Security, one major US bank’s checks “only confirm the account exists and the card number is active, without checking whether that specific card instance is still the one on file.”

May 2025
Initial disclosure
The researchers notify Visa and the banks concerned.
December 2025
Follow-up
The team contacts the same recipients a second time.
Aug. 12–14, 2026
Public presentation
The research is presented in Baltimore.
Aug. 20, 2026
Technical write-ups
The mechanism is published. No CVE has been assigned, and no exploitation has been reported.

No advisory yet from Visa, EMVCo, or SumUp

Visa confirmed that the report had passed initial triage and was being reproduced by its internal red team. As of August 20, 2026, The Hacker News had found no security advisory from Visa, EMVCo, or terminal maker SumUp. The researchers propose four fixes:

  • Bind the expiry date to the signature, so it falls inside the signed data.
  • Compare `5F24` and `57` at the terminal, and flag any mismatch instead of ignoring it.
  • Authorize against the PAN and expiry date together, so the issuer checks the card presented, not just the account.
  • Pass the terminal’s verdict to the issuer in the authorization request. Today it is lost along the way.

The findings do not automatically extend to France. The study did not test the application of Cartes Bancaires (CB) CB, France’s domestic card scheme. A co-badged card carries several applications and the terminal selects one, so a result on Visa’s kernel says nothing about CB. Under French law, Article L. 133-18 of the Monetary and Financial Code requires an immediate refund of an unauthorized transaction that the cardholder reports without delay.

⚠️
An expired card is not a revoked card
An expiry check is not a revocation. As long as the account behind the PAN stays open and the card is physically intact, it keeps producing valid responses. Cutting through the chip and the magnetic stripe before throwing out a replaced card removes the attack’s precondition.

Provenance

Published August 20, 2026

3 sources, 3 distinct domains

↗ The Hacker News, “Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments” · thehackernews.com↗ Help Net Security, “Researchers find a loophole that lets expired credit cards make unauthorized payments” · helpnetsecurity.com↗ GBHackers, “New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments” · gbhackers.com
← All news