← Back to feed
Vendors & MarketEmerging2 sourcesAug 21, 2026 · 14:03via Malwarebytes Labs

Zombie Card: An expired Visa credit card can be used for purchases

Brief

Did you know there is still a good reason to physically destroy your expired credit card?

Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.

They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.” The result was not universal.

Read more on Malwarebytes Labs

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Malwarebytes LabsPrimary··trust 1.28

Zombie Card: An expired Visa credit card can be used for purchases

Did you know there is still a good reason to physically destroy your expired credit card?

Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering.

University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.

They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.”

The result was not universal. The tested Mastercard, American Express, and Discover configurations rejected the altered expiry data, while issuer behavior differed even among the tested Visa cards: Some transactions were declined or prompted for a replacement card, while others were approved.

The flaw lies in the Visa Kernel 3 contactless flow, where the terminal-facing Application Expiration Date was not effectively bound to the card’s data. In the tested Mastercard, American Express, and Discover kernels, consistency checks or authenticated-data coverage caused modified expiry data to be detected and the transaction to be declined.

How this could be abused

The most credible abuse case is theft or recovery of an expired or replaced card which the owner regards as harmless. Consider cards left in household waste, a drawer, a lost wallet, or an unsecured corporate disposal stream. If the underlying account remains open and issuer-side controls do not validate the exact card lifecycle state, an attacker could attempt contactless purchases using a relay setup.

Read more →
Malware.news··trust 0.88

Zombie Card: An expired Visa credit card can be used for purchases

Did you know there is still a good reason to physically destroy your expired credit card?

Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.

They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.” The result was not universal.

The tested Mastercard, American Express, and Discover configurations rejected the altered expiry data, while issuer behavior differed even among the tested Visa cards: Some transactions were declined or prompted for a replacement card, while others were approved. The flaw lies in the Visa Kernel 3 contactless flow, where the terminal-facing Application Expiration Date was not effectively bound to the card’s data.

In the tested Mastercard, American Express, and Discover kernels, consistency checks or authenticated-data coverage caused modified expiry data to be detected and the transaction to be declined. How this could be abused The most credible abuse case is theft or recovery of an expired or replaced card which the owner regards as harmless.

Consider cards left in household waste, a drawer, a lost wallet, or an unsecured corporate disposal stream.

Read more →