Researchers at the University of Massachusetts have revealed how expired credit cards can be used for contactless payments.
Researchers from the University of Massachusetts have discovered that using expired credit cards creates a significant security vulnerability in contactless payment systems. These “zombie cards,” while physically invalid, can still process transactions under certain technical conditions, posing an unexpected risk to users.
The vulnerability stems from the fact that the portion of the card’s expiration date read by the terminal is not protected by a digital signature. This allows attackers to manipulate the card’s validity period.
How Does the Security Vulnerability Work in Contactless Payments?
Researchers state that this method requires physical access to the old card and two smartphones. A relay system established between two phones allows the terminal to perceive the card as still having a valid expiration date.
Tests on Visa cards showed this method was successful, while other networks such as Mastercard, Discover, and American Express rejected the altered dates. The attack is based more on treating the expiration date as a policy control than on bypassing EMV cryptography.
The contactless transaction involves multiple parties: card, terminal, merchant bank, card network, and issuing bank. Each party has a decision module regarding the approval or rejection of the process, and this complex structure can lead to a lack of clarity about who is responsible and the overlooking of security vulnerabilities.
Some information between the card and the terminal is transmitted as unencrypted text and then subjected to cryptographic verification. This vulnerability is directly related to the fact that the data on the card can be easily altered, rather than simply being read.
In the Visa configuration, the expiration date field read by the terminal is not protected by the card’s digital signature. Therefore, no connection is established between the valid date seen in the online authorization request and the date read by the terminal.
In addition, the expiration date in the digital certificates inside the cards can be longer than the printed date on the plastic. This causes the system to operate as if the clock is set forward, leading to erroneous approvals.
Proposed Solutions and Current Situation
EMV standards already have a protection system called “Relay Resistance Protocol” that can prevent these types of relay attacks. However, since this protocol is optional, it was not active in any of the terminals or cards tested.
The research group shared its findings with Visa and relevant banks in May 2025 and December 2025. While Visa’s security team is investigating the issue, no fix or improvement has yet been confirmed, and Visa has not yet given an official response to press inquiries on the matter.
Experts recommend that expired cards be safely destroyed until a solution is developed. Physically destroying the chip on the card and cutting off the card numbers is critical to preventing such misuse.
Do you think banks and card networks should make stricter security protocols mandatory to prevent the use of old cards?