Zombie Card Attack Lets Expired Visa Cards Still Pay via Contactless NFC

Researchers at UMass Amherst have revealed a novel vulnerability dubbed the “Zombie Card” attack, which enables expired Visa contactless cards to be fraudulently used for real in-store purchases. The exploit involves altering the expiration date that a point-of-sale (POS) terminal reads via NFC, while leaving the account’s primary account number (PAN) unchanged. Crucially, this attack doesn’t require breaking the card’s cryptography. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

How the Attack Works

The attack assumes the victim either possesses the expired card or holds it within NFC range. A man-in-the-middle (MitM) relay device is placed between the terminal and the card. When the terminal requests expiration data, the relay sends a future date in the Terminal’s Application Expiration Date field (Tag 5F24), while leaving the Track 2 data—which the issuer uses in authorization—intact. In Visa’s Kernel 3, the terminal does not cryptographically bind the Application Expiration Date, allowing this manipulation to pass unnoticed. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

Bank Responses & Kernel Differences

The study evaluated expired or replaced cards from five major US banks (anonymized as Banks A through E). Cards from three banks were tested in detail. In at least one bank’s system (Bank A), modified transactions of $1, $100, $500 in lab-environments and smaller amounts at retail and grocery were approved. Another bank (Bank B) accepted the spoofed expiry at the terminal but dropped the transaction during issuer authorization. A third bank’s terminal, using a different EMV kernel, rejected the manipulation outright. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

The attack’s success depends heavily on the specific EMV kernel in use. Visa’s Kernel 3 permits the exploit by not binding the expiry field in signatures checked offline, while other kernels do bind expiry data. Mastercard’s Kernel 2, and the kernels used by American Express and Discover, either check consistency between expiry fields or include the expiry in cryptographic verification steps—leading to failure of the attack. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

Threat Vector & Testing Details

The researchers built a relay from two NFC-capable Android phones running custom software to emulate both the card and the POS terminal. These were tested with SumUp Solo and Plus readers. In terms of speed, the relay adds roughly 20 ms, and about 50 ms when modifying the data—well under EMV’s limit of 500 ms per command. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

The testing took place in the United States, with expired cards from real banking customers and transactions run in lab and real-world merchants. The banks are anonymized. The findings were shared with Visa and the issuers in May 2025 and again late 2025, before being publicly presented in August 2026. No real fraud cases leveraging this specific technique have been reported. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

Mitigations & Recommendations

To shut down the zombie-card loophole, the paper proposes multiple layers of defense. Terminals should cryptographically bind the Application Expiration Date to issuer-verifiable signatures. Where multiple expiry fields exist, terminals need to compare all of them and signal discrepancies. Issuers should treat the presented expiry as part of PAN authentication and reject mismatches. Also, expiry validation outcomes at the terminal should be made visible to issuers. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

For cardholders, advice is to destroy the chip and magnetic stripe on expired cards instead of casually discarding them, and to ensure accounts are formally closed. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

Visa, while notified, has not publicly commented on these findings as of mid-August 2026. The report is in Visa’s triage and red-team review process. No advisory or specification updates have been issued yet by Visa, EMVCo, Mastercard, Discover, American Express, or terminal vendors. ([thehackernews.com](https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html))

The vulnerability highlights a less visible risk in contactless payments. Many systems assume card expiry is inherently dependable and bound, but this work shows that’s not always true. As contactless adoption grows, ensuring that every data element—including expiry—is cryptographically verified will be crucial. Expect regulatory or network-level guidance next, especially if attackers begin exploiting this in the wild.— TheDailyTechFeed