Cybersecurity

Researchers Reveal ‘Zombie’ Exploit for Expired Visa Contactless Cards

Researchers at the University of Massachusetts Amherst have uncovered a concerning vulnerability in Visa’s contactless payment system that enables fraudsters to “zombify” expired Visa cards—making unauthorized contactless transactions even after the card has expired. The discovery was presented at the Usenix Cybersecurity Conference and highlights a gap in Visa’s authentication process that could expose cardholders to fraud long after their cards have become invalid.

What Happened

This week, cybersecurity researchers revealed that expired Visa credit cards can be exploited by criminals using a man-in-the-middle (MitM) proxy app deployed on two smartphones. The attack works by relaying payment data from the dormant, expired card through a pair of phones to facilitate contactless payments, circumventing the expected expiration checks. At the heart of the issue is a flaw in the authentication chain where Visa’s infrastructure defers transaction approval to the issuing banks, some of which do not block payments from expired cards. The researchers demonstrated how this vulnerability can lead to active payments from expired cards at unattended point-of-sale terminals, without any human oversight or suspicion. Visa has not publicly responded to the findings, according to the reporting source.

Key Facts

The main points confirmed by the researchers and reported sources include:

  • The vulnerability was disclosed at the Usenix Cybersecurity Conference in August 2026.
  • The technique uses a man-in-the-middle app leveraging two smartphones to proxy the card’s NFC data.
  • Expired Visa cards pass Visa’s internal checks due to their authentication scheme, which offloads final verification to issuing banks.
  • Some issuing banks permit transactions on expired cards, while others block them.
  • The attack is especially effective at unattended terminals where no personnel can question unusual transactions.
  • Visa has not issued a public statement or patch concerning the vulnerability as of the date of disclosure.

What This Means

This vulnerability underscores a significant and unexpected risk that expired Visa cards—generally regarded as deactivated and safe to discard—can still be weaponized for fraudulent contactless payments. For consumers, it means that simply waiting for a card to expire does not guarantee protection against its misuse if the physical card falls into the wrong hands. This challenges the conventional security assumption about expiration as a safeguard.

From a payments ecosystem perspective, the flaw reveals a critical weakness in how transaction authentication is partitioned between Visa and issuing banks. The inconsistent enforcement by banks creates an exploitable loophole, raising broader questions around standardizing security protocols in contactless payment systems to prevent similar risks.

Practically, users are advised to destroy expired cards—such as cutting them up thoroughly—to prevent “zombification” attacks. Merchants and banks may need to review and tighten policies on declined transactions and expiration checks, especially for contactless payments conducted without human supervision.

What Remains Unclear

At this time, it is not confirmed how widespread exploitation of this vulnerability might be in the wild, nor is it clear how many issuing banks currently allow contactless payments on expired cards. Also, Visa’s official plans to address this gap—whether through protocol changes, advisories, or other mitigation strategies—have not yet been disclosed.

Background

This research comes amid growing scrutiny of contactless payment technologies and the security challenges posed by their convenience features. While expired physical cards have long been viewed as inert tools, this discovery challenges that notion, indicating that cryptographic and procedural weaknesses can leave even expired credentials vulnerable to misuse.

Sources

This article is based on reporting and publicly available information from the following source:

Read more Cybersecurity stories on Goka World News.

Ethan Clarke
About the editor

Ethan Clarke

Ethan Clarke Role: Cybersecurity Editor Ethan Clarke covers cybersecurity incidents, data breaches, online threats, ransomware, software vulnerabilities, and digital safety. His reporting focuses on confirmed details, affected systems, official advisories, and practical context without making unsupported accusations.

View all posts by Ethan Clarke