Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
- ID
- 16030
- Status
- summarized
- Published
- 20 Aug 2026, 8:01 PM
- Fetched
- 20 Aug 2026, 9:35 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 20 Aug 2026, 9:38 PM
- Tags
- Audience
- developerssaas_founders
What happened
Researchers at UMass Amherst demonstrated a 'Zombie Card' attack that rewrites the expiration date a POS terminal reads from an expired Visa contactless card over NFC, reviving it for in-store purchases without breaking the card's cryptography. The attack requires physical possession or sustained NFC proximity plus a MitM relay, and only succeeded at one of three tested US banks; another declined all attempts and a third used a different EMV kernel where the modification failed. Disclosed to Visa in May 2025, no CVE, no exploitation, and no published mitigation exist as of August 2026.
Why it matters
If you build or integrate contactless payment flows in Southeast Asia, this highlights that Visa's Kernel 3 does not enforce consistency between the terminal-facing Application Expiration Date (tag 5F24) and the issuer-facing Track 2 expiry (tag 57), meaning your issuer-side authorization logic must independently re-check expiry rather than trusting terminal-validated data. Builders should not assume EMV contactless specs close this gap.
Discussion angle
For anyone shipping fintech or payment integrations in Malaysia/SEA: does your acquiring or issuing stack rely on terminal-validated expiry, or does the issuer re-check independently? This is a concrete spec-level gap, not a hypothetical.