Researchers have identified a vulnerability, dubbed "Zombie Card," that could allow expired Visa contactless credit cards to be used for in-store purchases by manipulating the expiration date presented to payment terminals. The flaw was discovered by University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza.
The researchers found that in certain configurations, specifically within the Visa Kernel 3 contactless transaction flow, the application expiration date displayed to the terminal was not sufficiently protected or linked to the card's internal data. This allowed them to modify the expiration date seen by the terminal to a future date, effectively "reviving" expired Visa cards for real transactions.
Their testing involved contactless cards from Visa, Mastercard, Discover, and American Express, issued by five major U.S. banks, and used across various terminals and merchants. While the vulnerability was specific to Visa, the results were not uniform even among Visa cards; some transactions were declined or prompted for a replacement card, while others were approved. In contrast, tested Mastercard, American Express, and Discover configurations consistently rejected altered expiration data due to robust consistency checks or authenticated data coverage.
The most plausible scenario for exploitation involves an attacker obtaining an expired or replaced card that the owner might consider harmless, such as one found in household waste, a lost wallet, or an unsecured disposal stream. If the underlying account remains active and the card issuer's systems do not thoroughly validate the card's lifecycle status, an attacker could potentially make contactless purchases using a relay setup. A less likely scenario involves a proximity relay attack against a card still in the owner's possession, which would require sustained NFC proximity and a live relay during the transaction.
For cardholders, the recommended precaution is to physically destroy expired and replacement cards. This includes cutting through the chip multiple times, making additional cuts to disrupt the contactless antenna, and damaging the magnetic stripe before disposal. Additionally, reporting a lost expired card is advised rather than assuming it is inert. However, the primary responsibility for addressing this vulnerability lies with payment networks, terminal implementers, and card issuers to ensure that expiration data is integrity-protected and that authorization systems correctly reject retired card credentials.






