Product1 distinct publisher2 min readUpdated
Researchers relayed dead cards through a pair of phones. Whether the payment cleared came down to the issuing bank, not to the date printed on the plastic.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
A relay setup forges nothing. The card is proxied through a man-in-the-middle app that carries its data between two phones [2], so the terminal is holding a conversation with a real card that happens to be somewhere else and out of date [1].
What settled the outcome was not the date. The researchers found that whether an expired card's transaction gets disallowed had been left to cryptography that various card issuers implemented differently [3], and Visa's own check carried a flaw that let out-of-date cards pass [4]. As the researchers describe it, Visa had effectively handed the job of authenticating these transactions to the cardholder's bank [5]. Some banks stopped the revived cards. Others did not [6].
That is the part worth sitting with if you build or run a card product. Expiry is a field you can read off the plastic and out of a token record. The decline is a behaviour, and on this evidence it is a property of the issuing bank rather than of the card or the network [12]. Any rule, reissuance schedule or customer-facing promise that treats the printed month and year as a boundary is inheriting whichever half of that split its issuer landed in, and nobody downstream can see which half that is.
The attack itself is unglamorous and cheap. It wants a card that was discarded intact or left lying around [8], and a checkout with no human at it to notice a phone rig standing in for a card [7]. Neither of those is a rare condition. The mitigation on offer to the cardholder is a pair of scissors [9], which is a reasonable piece of advice and also a statement about where the residual risk has been parked.
Two gaps in the record matter for how hard you should read this. Visa did not respond to requests for comment from The Register, which covered the research [10]. And the account does not name the banks that blocked the technique or say how many issuers were tested [11]. So the defensible conclusion is narrower than "expired Visa cards work everywhere": it is that expiry enforcement cannot be assumed from outside a specific issuer's decline logic, and the network was not the place it was enforced [5][12]. For a control that appears on every card in the wallet and in every product spec that references card lifecycle, that is a large amount of load resting on something no single party owns.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Due to issues in the authentication chain of contactless payments, whether an expired card's transaction would be disallowed was left to cryptography implemented differently by various card issuers.
Visa's cryptography had a particular flaw allowing out-of-date cards to pass its check.
As the researchers describe it, Visa essentially passed the task of authenticating these transactions to the cardholder's bank.
Some banks prevented the use of the zombified cards and others did not.
At the Usenix Cybersecurity Conference, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa.
The technique proxies the expired card through a man-in-the-middle app that relays the card's data through a pair of phones.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named academic disclosure, but only via a secondary round-up
The underlying work is attributable — named institution, named conference, and a second outlet (The Register) reported it — which puts the core mechanism above rumour. But the cluster contains exactly one publisher, summarising rather than citing the primary paper, with no issuer names, no test scope, and no vendor confirmation because Visa declined comment.
No exploitation or remediation uptake reported
The supplied source documents a research disclosure and a divergence in issuer behaviour under test conditions. It reports no observed fraud in the wild, no affected-issuer counts, no Visa or issuer remediation, and no merchant or terminal-side changes, so real-world adoption of either the technique or a fix cannot be measured without guessing.
Vivid framing runs ahead of quantified exposure
The mechanism and the issuer-dependence finding are plausibly reported, but the 'zombified card as key into your bank account' framing implies a broad consumer exposure that the same item does not size: no issuer names, no test counts, no evidence of in-the-wild abuse, and the practical path requires physical possession of the discarded card plus a two-phone relay at an unattended terminal. Modestly overstated rather than fabricated.
Conference-disclosure visibility plus round-up framing; vendor silent
Visible incentives are ordinary and disclosed rather than hidden: academic researchers gain reputational benefit from a Usenix presentation, WIRED packages the finding with a memorable label and a consumer tip inside its weekly security round-up, and Visa's absence from the record leaves the framing uncontested. Nothing in the source indicates commercial sponsorship or product promotion.
Core mechanism credible; scope and impact unresolved
Confidence is moderate: the attribution chain (named researchers, named venue, corroborating outlet named in-text) supports the existence of the flaw and the issuer-dependence conclusion, while single-publisher sourcing, missing test scope, vendor silence, and no adoption data cap how far the finding can be relied upon operationally.
product
PayPal stopped saying no. Payments teams should now plan for a Stripe-owned checkout rail3 distinct publishers
invest
Kraken's Krak Card is a deposit play wearing a debit card's clothes3 distinct publishers
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
product
Cinemas, classrooms and ICE: smart glasses now need a venue-policy contingency1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 22, 2026