University of Massachusetts Amherst researchers have discovered that expired Visa cards can be surreptitiously used for contactless payments by proxying them through mobile applications. This flaw stems from inconsistent authentication protocols among financial institutions, leaving some accounts vulnerable to fraudulent charges if physical cards are not properly destroyed.
The Mechanism of 'Zombification'
At the recent Usenix Cybersecurity Conference, researchers from the University of Massachusetts Amherst unveiled a concerning security flaw affecting expired Visa credit cards. This vulnerability allows an attacker to perform unauthorized contactless transactions using a card that should technically be inactive. The attack involves a 'man-in-the-middle' approach where the data from the expired card is captured and relayed through a pair of smartphones using a specialized application. By functioning as a proxy, this digital setup tricks payment terminals into recognizing the expired card as a valid payment method, bypassing the expected expiration checks that should invalidate the physical token.
Inconsistent Authentication Protocols
The underlying cause of this security risk is a lack of standardization in how contactless payment authentication is handled at the issuing bank level. Researchers observed that while the payment network infrastructure supports the transaction, the actual validation of whether an expired card is permitted to complete a purchase is inconsistently implemented across different card issuers. In some instances, the responsibility to block these 'zombified' cards falls entirely on the bank's internal cryptography. Consequently, some financial institutions have successfully implemented safeguards to stop these fraudulent transactions, while others remain exposed, allowing the transactions to clear despite the card's expired status.
Real-World Fraud Implications
The practical application of this research suggests that discarded or lost credit cards represent a more significant security risk than previously assumed. If an individual disposes of an expired card without destroying the chip or the magnetic stripe, a bad actor who gains physical possession can potentially exploit it. This threat is particularly acute at point-of-sale terminals that operate without human supervision, as the automated proxy system requires no interaction beyond the contactless tap. Since the fraudulent setup relies on relaying information through mobile devices, an attacker does not need to physically manipulate the terminal in a conspicuous way, making these unauthorized charges difficult to detect in real-time.
Recommendations for Cardholders
Given the findings presented at the Usenix conference, the researchers emphasize that standard habits regarding physical card security must be updated. While many users may view an expired card as little more than a piece of plastic or a relic for their wallet, the research proves these items can still serve as keys to sensitive bank accounts. To mitigate the risk of 'zombification,' the most effective defense remains physical destruction. Cutting the card across the chip and magnetic stripe ensures that no remaining circuitry can be interrogated or proxied by an attacker, effectively neutralizing the card's potential for reuse in illicit payment scenarios.
⚖ The Balanced View
Concerns & criticism
The primary concern is the potential for financial fraud resulting from improperly discarded credit cards, as the inconsistency in bank-level authentication allows some expired cards to be successfully proxied for unauthorized transactions.
→What's next
Users should proactively destroy any expired credit or debit cards to prevent their data from being exploited. Following the public disclosure of these findings, consumers should monitor their banking statements closely for any unrecognized activity, even involving accounts associated with inactive or expired plastic.
































































































































































































































































































