The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Latest News

Expired Visa Cards Can Still Make Contactless Payments, Researchers Complete Real-World Transactions

The researchers, Raja Hasnain Anwar, Gerard DeCunha and Muhammad Taqi Raza, called the technique "Zombie Card." Their study found that an expired card can be made to appear valid to a compatible payment terminal without…

Expired Visa Cards Can Still Make Contactless Payments, Researchers Complete Real-World Transactions

An expired Visa card was used to complete a $100 contactless payment at a real point-of-sale terminal in a demonstration by University of Massachusetts Amherst researchers, exposing a weakness in how some payment systems enforce card expiration.

Key Takeaways
  • An expired Visa card was used to complete a $100 contactless payment at a real point-of-sale terminal in a demonstration by University of Massachusetts Amherst researchers, exposing a weakness in how some payment systems enforce card expiration.
  • Their demonstration includes a $100 contactless purchase made with an expired Visa card at a real point-of-sale terminal.
  • The card could remain cryptographically valid while the terminal was presented with an expiration date that had not actually been issued for the card.
Listen to this article
READY

The researchers, Raja Hasnain Anwar, Gerard DeCunha and Muhammad Taqi Raza, called the technique “Zombie Card.” Their study found that an expired card can be made to appear valid to a compatible payment terminal without breaking the cryptographic protections used to authenticate the card.

The finding was presented at the USENIX Security ’26 conference and evaluated contactless transactions across Visa, Mastercard and Discover configurations, multiple point-of-sale terminals, merchants and cards issued by five major U.S. banks.

The most significant result was not that a payment terminal could be fooled in a laboratory. The researchers demonstrated that the modified transaction could complete under real payment conditions.

The Payment System Had A Different View Of Expiration

The weakness comes from how expiration is represented during a contactless transaction.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

An expired card still contains functioning cryptographic credentials. Its printed expiration date does not deactivate the chip itself. Instead, expiration is treated as a transaction policy that payment systems use when deciding whether a card should be accepted.

In the Visa configuration examined by the researchers, the expiration value used by the terminal was not effectively bound to the authenticated transaction data. That meant the researchers could alter what the terminal interpreted as the card’s expiration date without causing the card’s cryptographic checks to fail.

The distinction matters because the attack did not defeat the encryption protecting the payment card. It exploited a gap between authentication and policy enforcement.

The card could remain cryptographically valid while the terminal was presented with an expiration date that had not actually been issued for the card.

Researchers Completed Real Transactions

The researchers tested the technique against payment terminals and carried out transactions under both controlled and merchant conditions.

Their demonstration includes a $100 contactless purchase made with an expired Visa card at a real point-of-sale terminal. The research team also conducted additional transactions in laboratory settings and validated the finding at campus retail and grocery merchants.

That does not mean every expired Visa card can be revived.

The researchers tested cards and payment configurations associated with five major U.S. banks, and the results differed between issuers and payment kernels. Their work found that Visa contactless transactions were susceptible in the configuration tested, while other payment networks included checks that prevented the same modification from succeeding.

The study therefore points to a configuration-specific weakness rather than a universal failure of contactless payments.

The Cryptography Was Not Broken

The most important technical detail is also the easiest to miss.

The researchers did not recover a card’s private key, forge its cryptographic signature or defeat the transaction cryptogram. Instead, the expiration information read by the terminal could be modified without invalidating the authentication mechanisms covering other transaction data.

That creates an unusual security boundary.

The terminal can make a decision based on one representation of the card’s state while the issuer receives other information when authorizing the payment. If those representations are not cryptographically linked, a security check performed by one component may not be visible to another.

The researchers found evidence that some issuers also relied heavily on the terminal’s decision during authorization, leaving fewer opportunities for the bank to independently reject the transaction based on the card’s actual lifecycle status.

The Finding Was Not Universal

The researchers tested several EMV payment kernels and found different behavior.

The Visa configuration was vulnerable to the expiration-date manipulation. Mastercard and Discover configurations tested by the researchers rejected the altered transactions through different validation mechanisms. The study also included American Express cards, with the researchers reporting that the modification failed under the tested configuration.

The outcome also depended on the issuing bank.

Some modified transactions were approved, while another bank’s issuer rejected transactions even after the terminal accepted the altered expiration information. The researchers said their merchant testing was intended to demonstrate that the technique could work outside a laboratory, not to measure the entire payment ecosystem.

That limitation is important. The research establishes a working attack path under particular conditions, not evidence that expired Visa cards generally remain usable.

Visa And Banks Were Notified

The researchers disclosed the findings to Visa and affected banks before publishing the work. Their research site says Visa’s report entered its internal reproduction process, while the researchers had not received public confirmation of completed mitigations from Visa or the notified banks at the time of publication.

The team also withheld its working relay implementation rather than releasing software that could directly facilitate fraudulent transactions. The researchers instead published technical findings and sanitized transaction data.

Their proposed defenses include cryptographically binding expiration information to authenticated card data, comparing different representations of expiration and making terminal validation results visible to issuers.

The research offers a simpler precaution: an expired or replaced card should not be treated as harmless plastic. It should be destroyed before disposal.

The larger lesson sits inside the payment architecture. An expiration date looks like a simple piece of information printed on a card. In a contactless transaction, however, it becomes a decision shared across several systems.

The researchers’ real-world payments showed what can happen when those systems do not all authenticate that decision in the same way.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the timeline behind Expired Visa Cards?

Researchers Completed Real Transactions The researchers tested the technique against payment terminals and carried out transactions under both controlled and merchant conditions.
02

What is the main point of contention here?

The card could remain cryptographically valid while the terminal was presented with an expiration date that had not actually been issued for the card.
03

What happens next?

The most significant result was not that a payment terminal could be fooled in a laboratory.
04

What is Expired Visa Cards?

An expired Visa card was used to complete a $100 contactless payment at a real point-of-sale terminal in a demonstration by University of Massachusetts Amherst researchers, exposing a weakness in how some payment systems enforce card expiration.
05

Why does this matter?

Their demonstration includes a $100 contactless purchase made with an expired Visa card at a real point-of-sale terminal.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.