Expired credit cards revived by researchers to make unauthorized payments
- ID
- 15382
- Status
- summarized
- Published
- 19 Aug 2026, 4:20 AM
- Fetched
- 19 Aug 2026, 6:08 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 19 Aug 2026, 6:11 AM
- Tags
- Audience
- developerssaas_founders
What happened
Researchers from UMass Amherst demonstrated at USENIX Security 2026 that expired Visa contactless credit cards can be revived to make unauthorized payments via a man-in-the-middle attack using mobile phones as NFC proxies. The vulnerability stems from Visa's EMV kernel not cryptographically binding the expiration date, unlike American Express, Discover, and Mastercard kernels, and from wallet Card Transaction Qualifiers steering transactions toward online authorization rather than immediate rejection.
Why it matters
If you build or integrate payment systems in Southeast Asia—where contactless card and wallet adoption is near-universal—this is a concrete protocol-level flaw in Visa's contactless kernel, not a configuration mistake. Fintech builders should verify whether their issuer-side authorization logic independently checks card expiration rather than trusting the POS terminal's evaluation, since the attack exploits exactly that delegation gap.
Discussion angle
Visa's kernel is specifically called out as more permissive than Mastercard/Amex/Discover—does this mean merchants and issuers on Visa are carrying asymmetric risk, and should Malaysian payment processors push for issuer-side expiration enforcement rather than relying on terminal checks?