The Vulnerability of 'Zombie' Cards

Security experts from the University of Massachusetts Amherst have uncovered a concerning security flaw involving expired credit cards. Despite their expiration dates, these so-called "zombie cards" can potentially be manipulated to authorize contactless transactions at point-of-sale terminals. This discovery highlights a significant gap in how payment expiration is enforced in modern financial systems.


The Technical Flaw: Unencrypted Expiry Dates

The issue stems from the way contactless EMV transactions handle data validation. Rather than treating an expiration date as a fixed, immutable property of the card itself, the system relies on a policy check between various parties, including the card, the merchant terminal, and the issuing bank.

Researchers discovered that the "Application Expiration Date" read by a terminal is often stored in an unprotected, unencrypted field. Because this specific field is not cryptographically bound to the card's digital signature in some configurations, it creates an opportunity for malicious actors to modify the date to a valid one during the transaction relay process.


«The exposure here is that the expiry date, which should be a static security measure, can be changed with relative ease. Furthermore, the digital certificate used for card-to-terminal communication often remains valid longer than the date printed on the physical card,» the researchers noted.

Attack Constraints and Industry Response

While the threat sounds severe, the researchers emphasized that the attack requires a specific set of circumstances to succeed:

  • Physical access to the discarded, expired credit card.
  • The use of two smartphones acting as a relay device between the card and the terminal.
  • The vulnerability appears primarily limited to certain Visa configurations; other networks like Mastercard, Discover, and American Express were found to reject altered dates.

Lack of Implementation for Existing Protections

Interestingly, the financial industry already has a tool to prevent such "relay" attacks: the Relay Resistance Protocol. This feature is designed to measure transaction timing, which would detect and block any interference by a third-party device. However, this protocol remains optional and was notably absent or disabled on all terminals and cards tested by the team.


The research team informed Visa and the involved financial institutions of these findings in 2025. While Visa’s security team acknowledged the report, there has been no confirmation of a permanent fix or software patch to address the vulnerability as of this writing.


Expert Recommendations

Until the industry adopts more robust security standards, experts stress that users should not treat their old, expired credit cards as harmless pieces of plastic. The most effective way to prevent this type of abuse is to physically destroy the embedded chip and ensure the card numbers are completely defaced or destroyed before disposal.