Skip to content
research

Visa's Undead Card Exploit

A critical flaw in Visa's system allows expired cards to be used for new purchases, a problem the company has known about for months. This 'zombie card' attack bypasses standard security checks, leaving millions of old cards vulnerable.

Aki Tanaka
Visa's Undead Card Exploit

Your Expired Card Isn't Dead, It's a Zombie

University of Massachusetts researchers recently unearthed a critical vulnerability, revealing that expired Visa cards can still facilitate new contactless payments. This exploit, aptly named the 'Zombie Card' attack, allows transactions to proceed long after a card's official expiration date, fundamentally challenging payment security. The core flaw lies within Visa's contactless protocol configuration, where the expiry date field sits unprotected, outside the card's cryptographic signature, making it susceptible to manipulation.

This isn't a theoretical concern confined to academic papers. Researchers rigorously demonstrated the Zombie Card attack's efficacy, successfully processing payments on live, commercial payment terminals. Their real-world transactions confirm this vulnerability as a tangible threat, proving that a physically possessed, expired Visa card can indeed initiate new purchases if exploited.

Crucially, this specific protocol weakness is exclusive to Visa. The research team conducted comprehensive tests against other major payment networks using the same exploit methodology. Mastercard, American Express, and Discover systems all successfully rejected attempts to process payments with manipulated expiry data, demonstrating their resilience. This highlights a distinct security gap within Visa's architecture, isolating the problem to their cardholders.

Anatomy of a Contactless Heist

Visa's contactless payment system harbors a critical design flaw, unearthed by university of Massachusetts researchers. Ordinarily, a card's cryptographic signature locks down the entire transaction payload, preventing tampering. However, in Visa's specific contactless configuration, the card's expiry date field sits conspicuously outside this signature-protected data. This leaves the expiry date uniquely exposed to manipulation, even as all other security checks successfully pass.

To exploit this vulnerability, researchers orchestrated a sophisticated man-in-the-middle relay attack. Their setup involved two Android phones: one phone acted as a fake card, interfacing with a live payment terminal, while the second phone established a connection with the real, expired Visa card. This dual-phone architecture created a transparent conduit, allowing attackers to intercept and modify transaction data in transit.

Mid-relay, the system executed a simple but devastating data swap. Researchers intercepted the card's actual, expired date and seamlessly replaced it with a valid future date, fabricating legitimacy. Critically, the card's authentic cryptogram—the core cryptographic proof of transaction validity—remained entirely untouched. The terminal then processed the request, receiving the genuine cryptogram alongside the counterfeit expiry date, resulting in initial authorization approval. This deceptive maneuver effectively resurrected the "Zombie Card."

The Broken Chain of Trust

Once the terminal accepts the tampered expiry date, the authorization request proceeds to the card's issuing bank. Here, the Zombie Card attack's success hinges on the bank's internal systems. If an issuer's system fails to perform a secondary, specific check for the card's expired status, it can approve the transaction, treating it as legitimate. Researchers demonstrated this across five major US banks, with some systems detecting the fraud while others did not.

Critically, an existing defense mechanism, the Relay Resistance Protocol (RRP), could detect and block such relay attacks. However, RRP remains an optional feature, and none of the tested cards or terminals had it enabled. This lack of mandatory implementation leaves a significant gap. Other payment networks, like Mastercard, American Express, and Discover, successfully rejected transactions with altered expiry data during the tests, highlighting Visa's specific vulnerability.

Researchers responsibly disclosed the vulnerability to Visa and the affected banks in May and again in December 2025. Visa's security team successfully reproduced the issue internally, confirming its validity. Despite this, Visa has yet to issue a patch or assign a Common Vulnerabilities and Exposures (CVE) identifier. This inaction echoes a previous incident where Visa similarly downplayed another security flaw related to Apple Transit mode. For a deeper dive into the technical specifics, read Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments.

Enjoying this? Get one like it in your inbox each morning.

one email a day · unsubscribe in two clicks · no third-party tracking

How to Kill a Zombie Card for Good

Visa has yet to deploy a system-wide fix for this critical vulnerability, despite researchers from the university of Massachusetts identifying and reporting it months ago. The crucial Relay Resistance Protocol, an optional defense mechanism capable of detecting the relay-based nature of this attack, remains largely unactivated across both cards and payment terminals. Consequently, the Zombie Card vulnerability persists as an active threat; any expired Visa card, provided its EMV chip and magnetic stripe are physically intact, holds the potential for illicit contactless transactions.

Merely letting an expired card languish in a desk drawer or consigning it to the recycling bin is insufficient. The underlying hardware retains its functionality, ready to be exploited by a sophisticated relay attack. Only through complete physical destruction can consumers truly neutralize this dormant financial threat, safeguarding against unauthorized use of their seemingly defunct cards.

To definitively kill a Zombie Card, target its core communication and data storage components. You must make a precise cut directly through the EMV chip – the metallic square on the card's front – and ensure a corresponding cut severs the magnetic stripe on the card's reverse. This action physically incapacitates the card, preventing any future data transmission or transaction authorization.

Frequently Asked Questions

What is the 'Zombie Card' attack?

It's a security exploit discovered by researchers that allows expired Visa credit cards to be used for new contactless transactions by manipulating the expiry date during the payment process.

Does this vulnerability affect all credit cards?

No. The researchers found this is a Visa-specific problem. Tests on Mastercard, American Express, and Discover cards showed they successfully rejected the tampered transaction data.

How does the attack work technically?

Attackers use a 'relay' system (e.g., two phones) to intercept the data between the expired card and the payment terminal. Because Visa's protocol doesn't cryptographically protect the expiry date, attackers can change it to a future date while passing along the card's otherwise valid security signature, fooling the terminal.

How can I protect myself from this exploit?

Since the vulnerability remains unpatched, the only guaranteed way to protect your old cards is to physically destroy them. Ensure you cut through both the EMV chip and the magnetic stripe.

Found this useful? Share it.

For builders

Want Stork to write one of these about your product?

Send us a URL. We use the product, form a view, and publish what we actually think — in 8 languages, labeled Sponsored, with no copy approval on your side. That last part is what makes it worth quoting.

See how it works$500 · AI tools & software only