Researchers at the University of Massachusetts Amherst have developed an attack, dubbed "Zombie Card," that enables expired Visa contactless credit cards to be used for real in-store purchases. The method involves rewriting the expiration date that a point-of-sale (POS) terminal reads via near-field communication (NFC), without compromising the card's cryptography. This attack was presented at the 35th USENIX Security Symposium in Baltimore.
Executing the Zombie Card attack requires physical possession of the expired card or sustained NFC proximity, along with a man-in-the-middle (MitM) relay positioned between the card and the terminal. The attack relies on the card account remaining open under the same primary account number (PAN) and the issuing bank not independently re-checking the expiry during authorization. Visa's Kernel 3 does not mandate consistent binding between the terminal-facing Application Expiration Date (Tag 5F24) and the issuer-verified expiry in Track 2 Equivalent Data (Tag 57). The relay modifies the terminal-facing date to a future value while leaving Track 2 untouched, ensuring the card's signature and cryptogram remain valid.
An evaluation across five major US banks included experiments with expired and replaced physical cards from three banks. One of these three banks approved the revived transactions, another declined all attempts, and the third used a different EMV kernel where the modification failed. The researchers disclosed their findings to Visa and affected banks in May and December 2025. As of August 20, 2026, no advisory, specification bulletin, or mitigation guidance has been published by Visa, EMVCo, Mastercard, Discover, American Express, or terminal vendor SumUp, and no exploitation of this technique has been reported.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Researchers at the University of Massachusetts Amherst demonstrated a "Zombie Card" attack that allows expired Visa contactless credit cards to be used for in-store purchases by rewriting the expiration date read by a point-of-sale terminal. This attack requires physical access to the card and a man-in-the-middle relay, and it exploits how Visa's Kernel 3 processes expiration dates, which could lead to unauthorized transactions if banks do not re-check expiry during authorization.