An expired Visa card was used to complete a $100 contactless payment at a real point-of-sale terminal in a demonstration by University of Massachusetts Amherst researchers, exposing a weakness in how some payment systems enforce card expiration.
- An expired Visa card was used to complete a $100 contactless payment at a real point-of-sale terminal in a demonstration by University of Massachusetts Amherst researchers, exposing a weakness in how some payment systems enforce card expiration.
- Their demonstration includes a $100 contactless purchase made with an expired Visa card at a real point-of-sale terminal.
- The card could remain cryptographically valid while the terminal was presented with an expiration date that had not actually been issued for the card.
The researchers, Raja Hasnain Anwar, Gerard DeCunha and Muhammad Taqi Raza, called the technique “Zombie Card.” Their study found that an expired card can be made to appear valid to a compatible payment terminal without breaking the cryptographic protections used to authenticate the card.
The finding was presented at the USENIX Security ’26 conference and evaluated contactless transactions across Visa, Mastercard and Discover configurations, multiple point-of-sale terminals, merchants and cards issued by five major U.S. banks.
The most significant result was not that a payment terminal could be fooled in a laboratory. The researchers demonstrated that the modified transaction could complete under real payment conditions.
The Payment System Had A Different View Of Expiration
The weakness comes from how expiration is represented during a contactless transaction.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseAn expired card still contains functioning cryptographic credentials. Its printed expiration date does not deactivate the chip itself. Instead, expiration is treated as a transaction policy that payment systems use when deciding whether a card should be accepted.
In the Visa configuration examined by the researchers, the expiration value used by the terminal was not effectively bound to the authenticated transaction data. That meant the researchers could alter what the terminal interpreted as the card’s expiration date without causing the card’s cryptographic checks to fail.
The distinction matters because the attack did not defeat the encryption protecting the payment card. It exploited a gap between authentication and policy enforcement.
The card could remain cryptographically valid while the terminal was presented with an expiration date that had not actually been issued for the card.
Researchers Completed Real Transactions
The researchers tested the technique against payment terminals and carried out transactions under both controlled and merchant conditions.
Their demonstration includes a $100 contactless purchase made with an expired Visa card at a real point-of-sale terminal. The research team also conducted additional transactions in laboratory settings and validated the finding at campus retail and grocery merchants.
That does not mean every expired Visa card can be revived.
The researchers tested cards and payment configurations associated with five major U.S. banks, and the results differed between issuers and payment kernels. Their work found that Visa contactless transactions were susceptible in the configuration tested, while other payment networks included checks that prevented the same modification from succeeding.
The study therefore points to a configuration-specific weakness rather than a universal failure of contactless payments.
The Cryptography Was Not Broken
The most important technical detail is also the easiest to miss.
The researchers did not recover a card’s private key, forge its cryptographic signature or defeat the transaction cryptogram. Instead, the expiration information read by the terminal could be modified without invalidating the authentication mechanisms covering other transaction data.
That creates an unusual security boundary.
The terminal can make a decision based on one representation of the card’s state while the issuer receives other information when authorizing the payment. If those representations are not cryptographically linked, a security check performed by one component may not be visible to another.
The researchers found evidence that some issuers also relied heavily on the terminal’s decision during authorization, leaving fewer opportunities for the bank to independently reject the transaction based on the card’s actual lifecycle status.
The Finding Was Not Universal
The researchers tested several EMV payment kernels and found different behavior.
The Visa configuration was vulnerable to the expiration-date manipulation. Mastercard and Discover configurations tested by the researchers rejected the altered transactions through different validation mechanisms. The study also included American Express cards, with the researchers reporting that the modification failed under the tested configuration.
The outcome also depended on the issuing bank.
Some modified transactions were approved, while another bank’s issuer rejected transactions even after the terminal accepted the altered expiration information. The researchers said their merchant testing was intended to demonstrate that the technique could work outside a laboratory, not to measure the entire payment ecosystem.
That limitation is important. The research establishes a working attack path under particular conditions, not evidence that expired Visa cards generally remain usable.
Visa And Banks Were Notified
The researchers disclosed the findings to Visa and affected banks before publishing the work. Their research site says Visa’s report entered its internal reproduction process, while the researchers had not received public confirmation of completed mitigations from Visa or the notified banks at the time of publication.
The team also withheld its working relay implementation rather than releasing software that could directly facilitate fraudulent transactions. The researchers instead published technical findings and sanitized transaction data.
Their proposed defenses include cryptographically binding expiration information to authenticated card data, comparing different representations of expiration and making terminal validation results visible to issuers.
The research offers a simpler precaution: an expired or replaced card should not be treated as harmless plastic. It should be destroyed before disposal.
The larger lesson sits inside the payment architecture. An expiration date looks like a simple piece of information printed on a card. In a contactless transaction, however, it becomes a decision shared across several systems.
The researchers’ real-world payments showed what can happen when those systems do not all authenticate that decision in the same way.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





