Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished Updated

Expired contactless cards still clear in-store payments at banks that trust the terminal's expiry date

UMass Amherst researchers showed at USENIX Security 2026 that an expired contactless card still pays in stores once a relay rewrites its expiry date. Issuers that trust the terminal's reported expiry approve the sale, a dev.to write-up says, so a reissued card leaves the old chip usable.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Expired contactless cards still clear in-store payments at banks that trust the terminal's expiry date
Generated illustration
Expired cards still pay where issuers trust the terminal How the expired contactless card exploit reaches issuers, cardholders and card protocols, and which checks resisted it or close the gap.

Exposed: issuers relying on the terminal's partial check approve the sale; Visa Kernel 3 is primarily exploited; at those issuers an old chip still transacts after reissue. Resisted: Mastercard, AmEx, Discover via data binding. Issuers re-checking expiry themselves close the gap.

Expired cards still pay where issuers trust the terminal
WhoHowKindClaim
Issuers trusting the terminalRely on the terminal's partial verification instead of re-checking cryptographic expiry data, so the transaction is approvedexposure4
Visa Kernel 3A contactless protocol the vulnerability primarily exploitsexposure5
Old chips at trusting issuersReissuing a card does not retire the old chip, which can still transact against the still-active accountexposure14
Mastercard, AmEx, DiscoverBuilt-in cryptographic data binding resisted this type of manipulationcapability5
Issuers that re-check expiryRe-checking cryptographic expiry data on their own end closes the gap without waiting for legacy terminals to changecapability13

What happened

  • The account behind an expired card stays active after the plastic expires so that merchant refunds and other incoming funds can still arrive.
  • The attack mainly works on specific protocols such as Visa Kernel 3, while Mastercard, American Express and Discover resisted it through cryptographic data binding.
  • Major card companies have been formally notified, but the write-up expects a fix across legacy terminals and bank systems to take considerable time.

Why it matters

  • constraint On the affected protocol, expiry and reissue cannot be counted as revocation, because the old chip still reaches an open account until it is physically destroyed.
  • exposure Expired cards thrown in household or branch trash become usable payment instruments for whoever recovers them, wherever the issuer accepts the terminal's date.
  • decision Affected issuers can add their own cryptographic expiry check now, ahead of a network-wide signature mandate that the write-up expects to take considerable time.

The trust boundary in this attack sits at the issuer. According to the dev.to write-up, the payment terminal does only a partial verification of the expiry date it reads. Many issuing banks rely on that check entirely and do not re-check the card's cryptographic expiration data on their own end, so a rewritten date gets approved [4].

Putting a future date in front of the terminal is the attacker's whole task. One phone picks up the expired card's NFC signal and relays it to a second phone at the store reader, and the date is rewritten to a future one before it reaches the reader [3]. The bill of materials is two standard smartphones and emulator software [3]. The account at the far end is still open. Issuers keep it active after the plastic expires so that merchant refunds and other incoming funds can land [2].

Credit to the three networks that held. Mastercard, American Express and Discover resisted the manipulation because their cards have built-in cryptographic data binding, the write-up says [5]. The attack primarily exploits specific contactless protocols, and the example it gives is Visa Kernel 3 [5]. Of the four networks named, three held up [12].

Card replacement is where an operating assumption breaks. The write-up says an expired card can still make in-store purchases even after a new one has been issued [1]. At an issuer that trusts the terminal's date, reissuing the card does not retire the old chip, and that chip still reaches a live account [14]. The evidence supports this for the affected protocol and for issuers that skip their own check. The write-up does not name the paper's authors or say how many issuers were tested, so its "many" is unquantified.

The long-term fix in the write-up is a mandated end-to-end cryptographic signature on the expiration date for every transaction [6]. Major card companies have been formally notified [15]. The write-up expects a global fix across legacy POS terminals and bank systems to take considerable time, leaving the loophole partly open in the short term [15]. I'd expect affected issuers to move first on their own side. An issuer that re-checks the cryptographic expiry data on its own end stops depending on the terminal's reported date, and that change does not wait on terminals in the field [13].

For cardholders, the advice turns on the chip. "The 'Zombie Card' exploit operates strictly through the wireless antenna of the embedded EMV chip," said Jarrod Wright, SVP Marketing at Chargebacks911 [11]. On the standard tip of slicing a card along the magnetic stripe, Wright said "it is completely irrelevant to this specific vulnerability" [7]. "Once the chip is severed, it is permanently dead, and the exploit is completely neutralized," he said [8]. The write-up also recommends digital wallets, which use device-bound, randomized tokens instead of the static card details on physical plastic [10].

What to watch

  • Whether Visa or affected issuers announce an end-to-end signature requirement on expiry data, or issuer-side re-checks of the card's cryptographic expiry.
  • Publication of the USENIX Security 2026 paper itself, with the count of issuers tested and which ones approved rewritten dates.
  • Whether the same terminal-trust gap turns up in contactless protocols other than Visa Kernel 3.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence30
Adoption
Insufficient
Hype gap+25
Incentives40
Confidence30
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Researchers at UMass Amherst, in work presented at USENIX Security 2026, showed that an expired physical card, even after a new one has been issued, can still be used to make in-store purchases via its contactless (NFC) chip.

    ReportedSupportedSource: dev.to write-up of UMass Amherst researchView cited source
  2. [2]

    While the physical card has a printed expiration date, the underlying credit card account remains active to facilitate incoming funds such as merchant refunds.

    ReportedSupportedSource: dev.to write-upView cited source
  3. [3]

    The attack uses a relay system requiring two standard smartphones and emulator software to intercept the NFC signal from an expired card and rewrite the expiration date to a future one before it reaches the store reader.

    ReportedSupportedSource: dev.to write-upView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 9, 2026

    The Threat of "Zombie Credit Cards"

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories