Back to News
SecurityAI Understanding briefing

Researchers report an attack that can revive some expired Visa contactless cards

A University of Massachusetts Amherst research team says a relay can alter the expiry date shown to a contactless terminal while leaving the card’s cryptographic responses intact. The finding was limited to the Visa configuration tested and did not work on the other networks examined.

By 6 min read
A controlled payment-security test setup with an expired contactless card, a generic checkout terminal and two relay phones on a laboratory workbench.
The short version

A University of Massachusetts Amherst research team says a relay can alter the expiry date shown to a contactless terminal while leaving the card’s cryptographic responses intact. The finding was limited to the Visa configuration tested and did not work on the other networks examined.

What happened

Researchers at the University of Massachusetts Amherst report that some expired Visa contactless cards can still be accepted when a relay changes the expiry date presented to a checkout terminal. Their controlled tests used real cards, commercial terminals, merchants and cards from five major U.S. banks. Mastercard, American Express and Discover configurations tested rejected the altered date.

The primary source is a research page from the Khwarizmi Lab at the University of Massachusetts Amherst describing a paper titled “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments.” The researchers say they tested their finding with real cards, commercial payment terminals, informed merchants and cards from five major U.S. banks. Their test scope included Visa, Mastercard, Discover and American Express contactless configurations, as well as Apple Pay and Google Pay. The reported result was specific: the Visa configuration tested could be affected, while the Mastercard, American Express and Discover configurations tested rejected the changed expiry information.

The reported mechanism is a mismatch between what the terminal reads and what the bank uses to authorize a transaction. In the Visa configuration examined, the expiry date presented to the terminal was not covered by the same digital signature as other card-security information. In a controlled relay setup, two Android phones passed the card-terminal conversation between the card and the terminal while changing the expiry value visible to the terminal. The card’s normal cryptographic responses continued to travel between the devices, so the researchers say the attack did not break the card’s keys, forge its security responses or defeat EMV cryptography in the usual sense.

The researchers describe the result as dependent on the issuer and the rest of the payment chain. Some tested banks declined the payment or requested the replacement card, while others approved it. The source says the underlying expiry issue was observed at $1, $100 and $500 when the relevant terminal and issuer conditions allowed it, although separate rules such as PIN requirements may stop a particular transaction. In the reported tests, payment amount, merchant type and terminal brand did not by themselves explain the outcome. The source does not establish that every Visa card, bank, terminal or payment application is affected.

The study also reports different behavior for digital wallets. Apple Pay and Google Pay were described as better positioned to handle replacement because payment tokens can be updated remotely, and the researchers say their testing found centralized lifecycle management reduced the chance that an expired physical credential remained usable. The source does not describe that result as a guarantee of immunity. It also says the team did not establish whether the issue applies to chip-insert transactions, and it has not established the same behavior for debit cards as a category.

Read the primary source: khwarizmilab.github.io

Why it matters

The finding exposes a gap between the terminal’s expiry check and the issuer’s decision about whether a specific physical card remains valid. It requires access to an expired card and a relay setup, so it is not a remote attack against all cardholders, but it challenges the assumption that an expired card is automatically unusable.

The practical significance is that expiry can fail as an end-to-end security promise even when the card’s cryptographic checks appear valid. Consumers commonly treat an expired card as worthless, but the researchers say the physical card can remain a starting point if it was discarded without being destroyed. The attack described is not a remote compromise: an attacker would need to obtain an expired physical card and operate a relay close enough to the transaction equipment. That makes the reported risk narrower than a vulnerability reachable over the internet, while still making careless disposal relevant.

The source’s central concern is responsibility split across the payment system. A terminal can evaluate one expiry value, the network can process a valid card cryptogram, and the issuing bank can make its decision using information that does not reliably identify the card as expired. A bank that checks the status of the exact physical card may decline the transaction; a bank that mainly sees an active underlying account may approve it. This variation means the outcome cannot be inferred from the card brand, the fact that a card is expired or the existence of contactless capability alone.

The finding is consequential for payment-network security because it concerns lifecycle enforcement rather than a single defective consumer device. The researchers say they notified Visa and the relevant banks in May and December 2025, providing a reproduction guide, transaction traces and a video demonstration. They say Visa’s report passed initial triage and was being reproduced by its red team, but that neither Visa nor the notified banks had confirmed a mitigation at the time of publication. The supplied source contains no independent confirmation of the vendors’ status, no public CVE and no evidence that the behavior is widespread.

The source also limits what ordinary cardholders should conclude. It says people do not need to change how they use contactless payments, and that an expired card securely destroyed by cutting through the chip and magnetic stripe cannot be used in the reported way. The researchers did not release exploit-capable relay code because they say it could lower the barrier to live financial fraud. Their disclosure provides sanitized transaction logs and protocol details, but the source does not provide a measured estimate of attempted attacks, losses, affected cards or real-world exploitation.

What to watch next

The key open questions are whether Visa and issuers have mitigated the reported behavior, how broadly it applies across cards and payment applications, and whether independent testing reproduces the result. Cardholders should follow their issuer’s disposal instructions, including cutting through the chip and magnetic stripe or returning the card through an approved channel.

The first priority is evidence of remediation across the payment chain. The researchers identify several possible control points: binding the terminal’s expiry information more tightly to authenticated card data, ensuring the issuer receives a trustworthy expiry signal, and having banks check the status of the exact card rather than only the related account. A meaningful mitigation would need to address the interaction among terminals, the payment network and issuers. A change at only one point may not resolve the mismatch described by the study.

Independent replication will determine the breadth of the claim. The source anonymizes the five banks as Banks A through E and reports only the cards and transactions tested. Further testing would need to examine more issuers, card products, payment applications, terminals and regions, while preserving responsible disclosure. The source does not establish prevalence, whether other Visa implementations behave the same way, or whether updated cards and terminals already reject the altered expiry value.

Relay Resistance Protocol is another specific area to monitor. The researchers say it can detect an added relay and stop a transaction, but that it is optional and was not enabled on the cards or terminals they tested. Future testing and deployment information could clarify whether that protection is broadly available, enabled by default or effective under the conditions described. The source reports that relay latency stayed within the payment system’s normal response allowance in its setup, so the test did not time out.

Consumers should follow the issuer’s existing replacement-card disposal guidance while these questions remain unresolved. Cutting through the chip and magnetic stripe, or using an issuer-approved return process, removes the physical credential required by the reported attack. People should not infer that every expired card is vulnerable, that chip-insert payments are affected, or that digital wallets are universally immune. The supplied material leaves those questions open and provides no independently established estimate of individual cardholder exposure.

Related guides & quizzes

Found this useful?
The Weekly Briefing

Get the AI stories that actually matter.

One useful email a week — what changed in AI, why it matters, plus tools, guides, opportunities, and practical ways to take action.

Free · No spam · Unsubscribe in one click