Researchers at the University of Massachusetts Amherst have uncovered a concerning vulnerability in Visa’s contactless payment system that enables fraudsters to “zombify” expired Visa cards—making unauthorized contactless transactions even after the card has expired. The discovery was presented at the Usenix Cybersecurity Conference and highlights a gap in Visa’s authentication process that could expose cardholders to fraud long after their cards have become invalid.
What Happened
This week, cybersecurity researchers revealed that expired Visa credit cards can be exploited by criminals using a man-in-the-middle (MitM) proxy app deployed on two smartphones. The attack works by relaying payment data from the dormant, expired card through a pair of phones to facilitate contactless payments, circumventing the expected expiration checks. At the heart of the issue is a flaw in the authentication chain where Visa’s infrastructure defers transaction approval to the issuing banks, some of which do not block payments from expired cards. The researchers demonstrated how this vulnerability can lead to active payments from expired cards at unattended point-of-sale terminals, without any human oversight or suspicion. Visa has not publicly responded to the findings, according to the reporting source.
Key Facts
The main points confirmed by the researchers and reported sources include:
- The vulnerability was disclosed at the Usenix Cybersecurity Conference in August 2026.
- The technique uses a man-in-the-middle app leveraging two smartphones to proxy the card’s NFC data.
- Expired Visa cards pass Visa’s internal checks due to their authentication scheme, which offloads final verification to issuing banks.
- Some issuing banks permit transactions on expired cards, while others block them.
- The attack is especially effective at unattended terminals where no personnel can question unusual transactions.
- Visa has not issued a public statement or patch concerning the vulnerability as of the date of disclosure.
What This Means
This vulnerability underscores a significant and unexpected risk that expired Visa cards—generally regarded as deactivated and safe to discard—can still be weaponized for fraudulent contactless payments. For consumers, it means that simply waiting for a card to expire does not guarantee protection against its misuse if the physical card falls into the wrong hands. This challenges the conventional security assumption about expiration as a safeguard.
From a payments ecosystem perspective, the flaw reveals a critical weakness in how transaction authentication is partitioned between Visa and issuing banks. The inconsistent enforcement by banks creates an exploitable loophole, raising broader questions around standardizing security protocols in contactless payment systems to prevent similar risks.
Practically, users are advised to destroy expired cards—such as cutting them up thoroughly—to prevent “zombification” attacks. Merchants and banks may need to review and tighten policies on declined transactions and expiration checks, especially for contactless payments conducted without human supervision.
What Remains Unclear
At this time, it is not confirmed how widespread exploitation of this vulnerability might be in the wild, nor is it clear how many issuing banks currently allow contactless payments on expired cards. Also, Visa’s official plans to address this gap—whether through protocol changes, advisories, or other mitigation strategies—have not yet been disclosed.
Background
This research comes amid growing scrutiny of contactless payment technologies and the security challenges posed by their convenience features. While expired physical cards have long been viewed as inert tools, this discovery challenges that notion, indicating that cryptographic and procedural weaknesses can leave even expired credentials vulnerable to misuse.
Sources
This article is based on reporting and publicly available information from the following source:
Read more Cybersecurity stories on Goka World News.
