Visa Contactless Payments Flaw Allows Zombie Cards to Make Purchases
Researchers at the University of Massachusetts Amherst discovered a flaw in Visa's contactless payment system, allowing them to modify an expired card's expiration date and use it for purchases. The team tested cards from various issuers, including Visa, Mastercard, American Express, and Discover.
The study found that while some terminals rejected the altered expiry data, others accepted it, enabling the researchers to revive expired Visa contactless credit cards for real in-store purchases. This phenomenon has been dubbed 'Zombie Card.'
The flaw lies in the Visa Kernel 3 contactless flow, where the terminal-facing Application Expiration Date was not effectively bound to the card's data. In contrast, Mastercard, American Express, and Discover kernels had consistency checks or authenticated-data coverage that detected modified expiry data and declined transactions.
The most significant concern is the potential for thieves or attackers to recover expired or replaced cards and use them for unauthorized contactless purchases. Cardholders are advised to physically destroy their expired cards by cutting through the chip and damaging the magnetic stripe before disposing of the pieces.