Build1 distinct publisher3 min readUpdated
UMass Amherst researchers rewrote the expiration date on dead contactless cards in flight. Terminals for three networks caught the edit. Five banks' backends caught nothing.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Delegation is the mechanism worth dwelling on. A contactless card hands over its data, the terminal decides whether the date on it is still valid, and the issuer treats that decision as done. According to the research team, that is the normal arrangement: banks leave the check to the point-of-sale device and trust its verdict [5]. Nobody had probed it because the assumption ran the other way, that the backend was the authority and would notice a date that did not match its own records [4].
The edit is possible at all because the payment data crossing the NFC interface is not fully encrypted, and some fields can be changed without invalidating the card's hash and signature [2]. The researchers' rig sits in the middle of that exchange, updates the expiration date, and relays the altered transaction onward to the terminal [3].
The split in the results is the interesting part. On terminals for Mastercard, American Express and Discover, changing the date produced a signature mismatch and the transaction failed [6]. On Visa terminals it went through [7]. One network in four accepted the rewrite [13], which points at terminal code rather than any scheme-level rule about what the signature must cover. If the protection were in the standard, it would not be a per-network coin flip.
Then the number that matters more than the terminal split: the study used five banks, and the altered transactions were not caught by any of their backends [7][8], a detection rate of zero out of five [12]. Every layer that was supposed to be redundant turned out to be the same layer.
Scale honesty first. Four networks and five banks is a small sample. It establishes that the delegation pattern is real and that at least one network's terminals do not bind the expiry field, not that the failure is universal.
What is not small is the cost of running the attack. No specialised hardware is needed; the kit is basic NFC emulators and POS terminals available for purchase online [9]. The gating factor is supply of dead plastic, pulled from the trash or taken from people who never destroyed their old cards [10]. That is a scavenging problem, not an engineering one.
Which is why the study's headline advice lands where it does. The researchers' main recommendation was not that Visa and the banks fix their terminals and backends, though they note that should be happening anyway, but that cardholders cut expired cards into tiny pieces [11]. It is a realistic reading of who can act this week. It is also an admission that the control everyone believed was enforced server-side is currently enforced by scissors.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A team of academics from the University of Massachusetts Amherst developed an attack that revives old expired contactless cards to perform new illegal transactions.
The attack exploits the fact that NFC card data is not fully encrypted when making a payment, and some parameters can be modified without breaking the card's digital hash/signature.
The researchers built a rig that intercepts transaction data through an NFC man-in-the-middle attack, updates the expiration date, and relays the modified payment to a point-of-sale terminal.
The attack is simple and nobody thought to investigate it because everyone assumed banks enforce the expiration date check and would catch modifications that do not align with their backend systems.
The research team says banks typically leave the expiration date check to the point-of-sale terminal device where the transaction occurs and trust its decision.
The study found that three of the four major card payment providers, Mastercard, American Express and Discover, used POS terminals where modifying the expiration date caused a card hash/signature mismatch and the transaction failed.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Thin: one secondary summary of an uncited study
All substantive findings — the mutable signed fields, the Visa terminal acceptance, and the zero-of-five bank backend detections — rest on a single newsletter item summarising an academic study that is not linked, dated, or attributed to a venue. The reported network split is specific and internally consistent, which lifts the score above the floor, but there is no paper, no reproduction, no named terminal models or issuers, and no comment from Visa or the banks.
No adoption or exploitation signal
The supplied material contains no evidence of real-world use of the technique, no vendor fix, terminal update, network bulletin, or issuer control change, and no disclosure of affected transaction volumes. The only observable event is the publication of the write-up itself, which does not measure uptake or impact.
Mildly overstated relative to preconditions
The headline framing that expired cards can be used for new transactions is broader than the reported result, which needs physical possession of a discarded expired card, an NFC man-in-the-middle rig, and a Visa-branded terminal path, and which three of four tested networks' terminals already blocked. The write-up does add restraint — it names the precondition and the failed cases — so the overstatement is modest rather than severe, though shifting the primary mitigation onto consumers with scissors understates the issuer-side control gap it just documented.
Sponsored newsletter, low direct stake in the finding
The publisher discloses commercial sponsorship and cross-promotes its own podcast and RSS in the same item, and the piece is aggregation with an attention incentive in the striking 'expired cards still work' framing. Against that, the outlet has no evident stake in Visa, the unnamed banks, or the research team, and the item names the cases where the attack failed. No incentive information about the researchers or affected vendors is available in the supplied material.
Low-moderate: coherent but uncorroborated
The account is technically coherent and specific enough to act on as a control-verification prompt, but it is single-sourced, the underlying study is uncited, the affected banks and terminals are unnamed, no vendor has responded, and adoption cannot be assessed at all. Confidence would rise materially with the paper, a Visa or issuer statement, or an independent reproduction.
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
product
PayPal stopped saying no. Payments teams should now plan for a Stripe-owned checkout rail3 distinct publishers
invest
1,051 trades in one month, and a $185 million window where the number should be1 distinct publisher
invest
Over 1,000 trades in June, the big ones on one day: what the Trump filings do and do not show1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026