Friday, September 11, 2026

New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments

Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC payments.

This attack exploits a vulnerability in Visa’s EMV Kernel 3 regarding the handling of card expiry data. An attacker, positioned between the card and the payment terminal, can modify the expiry information sent to the terminal without compromising the transaction’s cryptographic checks.

Researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza from the University of Massachusetts Amherst presented their findings in a paper at the 35th USENIX Security Symposium.

Their work highlights that expiry enforcement can fail when the terminal and issuer use different, inconsistently validated representations of a card’s expiration date.

How the Attack Works

The exploit requires an active NFC man-in-the-middle relay between an expired physical card and a point-of-sale terminal.

In the researchers’ proof of concept, two NFC-capable Android phones served as a card emulator near the terminal and a POS emulator near the expired card, relaying contactless payment traffic between them.

Zombie Card Attack Flow (Source: Usenix)
Zombie Card Attack Flow (Source: Usenix)

During the transaction, the attacker intercepts the Application Expiration Date data object, known as EMV tag 5F24, and alters it from a past date to a future date. This modification is sufficient for the terminal’s local expiry check to pass.

Importantly, the researchers leave the Track 2 Equivalent Data unchanged. This data, which also includes an expiry value, is typically sent to the issuer during online authorization.

Under Visa Kernel 3, the terminal-facing 5F24 value is not consistently cryptographically bound to the signed data verified during the transaction, allowing for in-flight modifications without compromising the fast Dynamic Data Authentication or the issuer-verifiable application cryptogram.

As a result, the terminal erroneously believes the card is valid despite it being expired.

EMV contactless payments distribute security decisions across the card, terminal, acquirer, payment network, and issuing bank. The study found that Visa Kernel 3 creates a particularly permissive environment because the terminal relies on a single expiry value. In contrast, the issuer may use a different one.

For an issuer to approve the payment, the expired card must still have valid cryptographic material, and the account associated with its Primary Account Number (PAN) must remain active.

The researchers observed that issuer behavior varied: one bank approved altered transactions for different amounts and merchant types. At the same time, another consistently declined them and advised customers to use their replacement cards.

The attack does not defeat EMV cryptography or forge a payment card. Instead, it exploits a failure in lifecycle enforcement: an old card can still generate a valid transaction cryptogram. At the same time, an issuer might authorize based on an active account or PAN, rather than verifying the expiration date of the specific physical card.

The researchers tested real-world transactions involving various EMV kernels, terminals, merchants, and five major U.S. banks.

Their findings suggest that this issue is not a universal failure across all EMV systems: similar modifications did not work against Mastercard Kernel 2, American Express Kernel 4, or Discover Kernel 6 because those implementations either checked for consistency between expiry representations or cryptographically protected the relevant data.

Zombie Card Attack (Source: Usenix)

The threat model also has substantial constraints. An attacker needs access to an expired, replaced, lost, or stolen card, as well as the ability to establish an NFC relay position between the card and the payment terminal.

Thus, the technique is operationally more demanding than simple card skimming. However, it demonstrates that expired cards should not be automatically deemed harmless.

The paper suggests that payment networks and terminal vendors should cryptographically bind expiry-critical data to authenticated transaction fields and enforce consistency between terminal-facing and issuer-facing expiry values.

Issuers should treat the PAN and expiry date as a combined credential identity and decline authorization when the presented card lifecycle state does not match the active instrument.

Banks should consistently revoke old card credentials after issuing replacements, including for low-value and online authorizations. Payment systems could further reduce exposure by conveying meaningful terminal validation results to issuers instead of masking them with all-zero Terminal Verification Results.

For cardholders, the practical advice is clear: physically destroy expired or replaced cards by cutting through the EMV chip and magnetic stripe, or return them through an issuer-approved disposal channel.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News