← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Zombie Card Attack Revives Expired Visa Contactless Cards for Purchases

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attack revives expired Visa contactless cards for purchases.
  • Requires physical card access and a man-in-the-middle relay.
  • Exploits Visa Kernel 3's handling of expiration dates.
  • One of three tested banks approved revived transactions.

Zombie Card Attack Details

Researchers at the University of Massachusetts Amherst have developed an attack, dubbed "Zombie Card," that enables expired Visa contactless credit cards to be used for real in-store purchases. The method involves rewriting the expiration date that a point-of-sale (POS) terminal reads via near-field communication (NFC), without compromising the card's cryptography. This attack was presented at the 35th USENIX Security Symposium in Baltimore.

Technical Requirements and Vulnerability

Executing the Zombie Card attack requires physical possession of the expired card or sustained NFC proximity, along with a man-in-the-middle (MitM) relay positioned between the card and the terminal. The attack relies on the card account remaining open under the same primary account number (PAN) and the issuing bank not independently re-checking the expiry during authorization. Visa's Kernel 3 does not mandate consistent binding between the terminal-facing Application Expiration Date (Tag 5F24) and the issuer-verified expiry in Track 2 Equivalent Data (Tag 57). The relay modifies the terminal-facing date to a future value while leaving Track 2 untouched, ensuring the card's signature and cryptogram remain valid.

Testing and Industry Response

An evaluation across five major US banks included experiments with expired and replaced physical cards from three banks. One of these three banks approved the revived transactions, another declined all attempts, and the third used a different EMV kernel where the modification failed. The researchers disclosed their findings to Visa and affected banks in May and December 2025. As of August 20, 2026, no advisory, specification bulletin, or mitigation guidance has been published by Visa, EMVCo, Mastercard, Discover, American Express, or terminal vendor SumUp, and no exploitation of this technique has been reported.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 15 stories · Aug 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Researchers at the University of Massachusetts Amherst demonstrated a "Zombie Card" attack that allows expired Visa contactless credit cards to be used for in-store purchases by rewriting the expiration date read by a point-of-sale terminal. This attack requires physical access to the card and a man-in-the-middle relay, and it exploits how Visa's Kernel 3 processes expiration dates, which could lead to unauthorized transactions if banks do not re-check expiry during authorization.