BuildNot yet confirmed elsewhere1 publisher3 min readPublished Updated
Expired contactless cards still clear in-store payments at banks that trust the terminal's expiry date
UMass Amherst researchers showed at USENIX Security 2026 that an expired contactless card still pays in stores once a relay rewrites its expiry date. Issuers that trust the terminal's reported expiry approve the sale, a dev.to write-up says, so a reissued card leaves the old chip usable.
The Engineer · Build desk

Exposed: issuers relying on the terminal's partial check approve the sale; Visa Kernel 3 is primarily exploited; at those issuers an old chip still transacts after reissue. Resisted: Mastercard, AmEx, Discover via data binding. Issuers re-checking expiry themselves close the gap.
- exposure Issuers trusting the terminal Rely on the terminal's partial verification instead of re-checking cryptographic expiry data, so the transaction is approved, claim 4
- exposure Visa Kernel 3 A contactless protocol the vulnerability primarily exploits, claim 5
- exposure Old chips at trusting issuers Reissuing a card does not retire the old chip, which can still transact against the still-active account, claim 14
- capability Mastercard, AmEx, Discover Built-in cryptographic data binding resisted this type of manipulation, claim 5
- capability Issuers that re-check expiry Re-checking cryptographic expiry data on their own end closes the gap without waiting for legacy terminals to change, claim 13
| Who | How | Kind | Claim |
|---|---|---|---|
| Issuers trusting the terminal | Rely on the terminal's partial verification instead of re-checking cryptographic expiry data, so the transaction is approved | exposure | 4 |
| Visa Kernel 3 | A contactless protocol the vulnerability primarily exploits | exposure | 5 |
| Old chips at trusting issuers | Reissuing a card does not retire the old chip, which can still transact against the still-active account | exposure | 14 |
| Mastercard, AmEx, Discover | Built-in cryptographic data binding resisted this type of manipulation | capability | 5 |
| Issuers that re-check expiry | Re-checking cryptographic expiry data on their own end closes the gap without waiting for legacy terminals to change | capability | 13 |
What happened
- The account behind an expired card stays active after the plastic expires so that merchant refunds and other incoming funds can still arrive.
- The attack mainly works on specific protocols such as Visa Kernel 3, while Mastercard, American Express and Discover resisted it through cryptographic data binding.
- Major card companies have been formally notified, but the write-up expects a fix across legacy terminals and bank systems to take considerable time.
Why it matters
- constraint On the affected protocol, expiry and reissue cannot be counted as revocation, because the old chip still reaches an open account until it is physically destroyed.
- exposure Expired cards thrown in household or branch trash become usable payment instruments for whoever recovers them, wherever the issuer accepts the terminal's date.
- decision Affected issuers can add their own cryptographic expiry check now, ahead of a network-wide signature mandate that the write-up expects to take considerable time.
The trust boundary in this attack sits at the issuer. According to the dev.to write-up, the payment terminal does only a partial verification of the expiry date it reads. Many issuing banks rely on that check entirely and do not re-check the card's cryptographic expiration data on their own end, so a rewritten date gets approved [4].
Putting a future date in front of the terminal is the attacker's whole task. One phone picks up the expired card's NFC signal and relays it to a second phone at the store reader, and the date is rewritten to a future one before it reaches the reader [3]. The bill of materials is two standard smartphones and emulator software [3]. The account at the far end is still open. Issuers keep it active after the plastic expires so that merchant refunds and other incoming funds can land [2].
Credit to the three networks that held. Mastercard, American Express and Discover resisted the manipulation because their cards have built-in cryptographic data binding, the write-up says [5]. The attack primarily exploits specific contactless protocols, and the example it gives is Visa Kernel 3 [5]. Of the four networks named, three held up [12].
Card replacement is where an operating assumption breaks. The write-up says an expired card can still make in-store purchases even after a new one has been issued [1]. At an issuer that trusts the terminal's date, reissuing the card does not retire the old chip, and that chip still reaches a live account [14]. The evidence supports this for the affected protocol and for issuers that skip their own check. The write-up does not name the paper's authors or say how many issuers were tested, so its "many" is unquantified.
The long-term fix in the write-up is a mandated end-to-end cryptographic signature on the expiration date for every transaction [6]. Major card companies have been formally notified [15]. The write-up expects a global fix across legacy POS terminals and bank systems to take considerable time, leaving the loophole partly open in the short term [15]. I'd expect affected issuers to move first on their own side. An issuer that re-checks the cryptographic expiry data on its own end stops depending on the terminal's reported date, and that change does not wait on terminals in the field [13].
For cardholders, the advice turns on the chip. "The 'Zombie Card' exploit operates strictly through the wireless antenna of the embedded EMV chip," said Jarrod Wright, SVP Marketing at Chargebacks911 [11]. On the standard tip of slicing a card along the magnetic stripe, Wright said "it is completely irrelevant to this specific vulnerability" [7]. "Once the chip is severed, it is permanently dead, and the exploit is completely neutralized," he said [8]. The write-up also recommends digital wallets, which use device-bound, randomized tokens instead of the static card details on physical plastic [10].
What to watch
- Whether Visa or affected issuers announce an end-to-end signature requirement on expiry data, or issuer-side re-checks of the card's cryptographic expiry.
- Publication of the USENIX Security 2026 paper itself, with the count of issuers tested and which ones approved rewritten dates.
- Whether the same terminal-trust gap turns up in contactless protocols other than Visa Kernel 3.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence30
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researchers at UMass Amherst, in work presented at USENIX Security 2026, showed that an expired physical card, even after a new one has been issued, can still be used to make in-store purchases via its contactless (NFC) chip.
- [2]
While the physical card has a printed expiration date, the underlying credit card account remains active to facilitate incoming funds such as merchant refunds.
- [3]
The attack uses a relay system requiring two standard smartphones and emulator software to intercept the NFC signal from an expired card and rewrite the expiration date to a future one before it reaches the store reader.
- [4]
Many issuing banks rely entirely on the terminal's partial verification instead of re-checking the cryptographic expiration data on their end, so the transaction gets approved.
- [5]
The vulnerability primarily exploits specific contactless protocols like Visa Kernel 3, whereas Mastercard, American Express and Discover have built-in cryptographic data binding that resisted this type of manipulation.
- [6]
The long-term fix requires card companies and issuing banks to mandate a strict end-to-end cryptographic signature on the expiration date for every transaction.
- [7]
While this remains a decent rule of thumb for legacy security, it is completely irrelevant to this specific vulnerability.
ReportedSupportedSource: Jarrod Wright, SVP Marketing at Chargebacks911, quoted in the dev.to write-up, on slicing a card along the magnetic stripeView cited source - [8]
Once the chip is severed, it is permanently dead, and the exploit is completely neutralized.
ReportedSupportedSource: Jarrod Wright, SVP Marketing at Chargebacks911, quoted in the dev.to write-upView cited source - [9]
Otherwise, a compromised card could easily be retrieved from a branch trash bin the moment an employee looks away.
ReportedSupportedSource: Jarrod Wright, quoted in the dev.to write-up, on handing old cards to bank staff without seeing the chip destroyedView cited source - [10]
Digital wallets such as Apple Pay or Google Pay use device-bound, randomized tokens instead of broadcasting the static card details exposed by physical plastic.
- [11]
The 'Zombie Card' exploit operates strictly through the wireless antenna of the embedded EMV chip.
ReportedSupportedSource: Jarrod Wright, SVP Marketing at Chargebacks911, quoted in the dev.to write-upView cited source - [12]
Of the four card networks the write-up names, three (Mastercard, American Express, Discover) resisted the expiry-rewrite manipulation.
- [13]
An issuer that re-checks the card's cryptographic expiration data on its own end no longer depends on the terminal's reported date, so it can close the gap for its cards without waiting for legacy terminals to change.
- [14]
At issuers that trust the terminal's reported expiry, reissuing a card does not retire the old chip, which can still transact against the still-active account.
- [15]
Major card companies have been formally notified; implementing a global fix across legacy POS terminals and banking systems takes considerable time, leaving the loophole partially open in the short term.
- [16]
Old cards are often discarded in household garbage, where they can be harvested by bad actors.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toThe Threat of "Zombie Credit Cards"
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Payment tokenizationFollow
- Payment card securityFollow
- Contactless PaymentsFollow
Entities
- University of Massachusetts AmherstFollow
- USENIX SecurityFollow
- VisaFollow
- Visa Kernel 3Follow
- MastercardFollow
- American ExpressFollow
- DiscoverFollow
- Chargebacks911Follow
- Jarrod WrightFollow
- EMVFollow