Zombie Cards Back Online: Expired Card Attack
Toggle navigation
UMass - Khwarizmi Lab
Home
Research
Publications
Team
Media & Press
Gallery
Expired Card Attack
Zombie Cards Back Online
Reviving Expired Credit Cards for Contactless Payments
Raja Hasnain Anwar ·<br>Gerard DeCunha ·<br>Muhammad Taqi Raza
Abstract<br>Paper<br>Citation (Bib)
Abstract
Most people reasonably assume that an expired card has become useless. Our research asks a simple<br>question: is that always true? We found that, in some contactless Visa payment setups,<br>an expired card can still be accepted when someone changes the expiry date shown to the checkout<br>terminal. The card's built-in cryptography continues to look genuine, and some banks do not receive<br>enough reliable information to recognize that the physical card has expired.
We tested this finding with real cards, terminals, merchants, and five major US banks. Visa was the<br>susceptible configuration in our experiments; the Mastercard, American Express, and Discover<br>configurations we tested rejected the change. The result is not that card cryptography has been<br>broken. It is a gap between systems that each assume someone else has checked whether a card should<br>still be usable. We describe the gap and the changes that can close it.
Why Expired Cards?
When a replacement card arrives, the old one is often treated as harmless. People put it in a drawer,<br>throw it away, or assume that the date printed on it automatically prevents any future use. That is a<br>reasonable expectation. A card should not become usable again simply because different parts of the<br>payment system disagree about whether it has expired.
Contactless payments involve a card, the shop’s checkout terminal, the merchant’s bank, a payment<br>network such as Visa or Mastercard, and the cardholder’s bank. Each has a small part of the decision.<br>The important question is whether those parts agree on one basic fact: is this particular card<br>still valid?
The short version: the terminal and the bank can see expiry information in different<br>places. In the Visa configuration we studied, the terminal’s copy was not protected in the same way<br>as the card’s other security information. That left room for the two sides to reach different answers.
What We Found
The card gives the checkout terminal an expiry date to read. In the Visa contactless configuration<br>we tested, that particular date was not covered by the card’s digital signature. Someone positioned<br>between the card and terminal could therefore alter what the terminal sees while leaving the card’s<br>normal security checks looking valid.
Our controlled demonstration relays the conversation between a checkout terminal and an expired card. The relay changes the expiry information shown to the terminal while the card's normal security responses continue to travel between the two devices.
How the gap leads to a payment
1. An old card is treated as disposable. The starting point is an expired card that was not securely destroyed.
2. The terminal is shown a different date. In our controlled setup, a relay sits between the card and checkout terminal and changes the expiry value the terminal reads.
3. The card still looks genuine. The altered value is outside the signature checked by this Visa configuration, so the terminal's usual cryptographic check does not reveal the change.
4. The bank may lack the warning it needs. The payment reaches the issuer with a valid card cryptogram, while the terminal's view of expiry and the issuer's view are not reliably tied together.
5. The outcome depends on the issuer. A bank that verifies the status of this exact card can decline it. A bank that mainly sees an active account may approve it.
This is why we call it a Zombie Card : the card is supposed to be retired, yet it can appear<br>alive to part of the payment system. It does not mean every expired card works, and it does not mean<br>an ordinary cardholder is expected to defend against a complex technical attack. It means expiry has<br>to be enforced consistently by the payment system itself.
Demo Video
A live demonstration of the Zombie Card attack: an expired Visa card completing a $100 contactless transaction at a real POS terminal.
What We Tested
We tested the issue using our own expired cards, Android phones in a controlled relay setup, and<br>commercial payment terminals. We also validated the behavior with informed merchants and paid every<br>test charge in full. The study covered Visa, Mastercard, Discover, and American Express cards from<br>five major US banks, as well as Apple Pay and Google Pay.
The result was specific, not universal: the Visa configuration we tested could be affected; the<br>Mastercard, American Express, and Discover configurations we tested rejected the altered expiry<br>information. Banks also differed. Some declined the payment or asked for the replacement card, while<br>others approved it. That variation is the central lesson: the protection depends on the whole payment<br>chain, not on...