New “Zombie Card” Flaw Lets Expired Visa Cards Make Contactless Payments

New “Zombie Card” Flaw Lets Expired Visa Cards Make Contactless Payments

Researchers found a flaw that can let expired Visa cards make contactless payments. Here’s how the “Zombie Card” attack works and what to do with old cards you still have.

What Happened?

According to Cybersecurity News, researchers found a flaw in Visa contactless payments that can make some expired cards work again.

The study came from the University of Massachusetts Amherst and was presented at the 35th USENIX Security Symposium. Researchers named the attack “Zombie Card.”

They tested their own expired and replaced cards at retail and grocery stores using accounts from five major U.S. banks. One bank approved test purchases up to $500, while another bank consistently declined them.

The researchers notified Visa and affected banks in May 2025. The report says no confirmed fix had been deployed when the findings were published.

This is not a remote attack against every expired Visa card. The test required a device to be placed near the physical card.

This flaw does not involve a data breach, so leak monitoring cannot stop the card attack itself. However, payment fraud can also involve personal information stolen elsewhere.

If you want to check for those separate risks, automatic monitoring can help. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Which Cards and Banks Were Affected?

The researchers tested contactless systems used by Visa, Mastercard, American Express, and Discover.

The tested Mastercard, American Express, and Discover systems detected the changed expiration information and stopped the transactions.

Visa’s contactless system, called Kernel 3, handled the expiration date differently. That difference made the “Zombie Card” attack possible during testing.

The researchers also tested cards linked to five major U.S. banks, but the banks were not named publicly.

One bank approved expired-card purchases up to $500. Another bank rejected them and asked for the replacement card instead.

The team also found that one replaced card could still make payments after a newer card had already been issued.

The source did not report any leaked customer data. It also did not show that criminals are already using this attack widely.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How the “Zombie Card” Attack Works

The researchers used two NFC-enabled Android phones. NFC is the short-range technology used when you tap a card or phone to pay.

One phone communicated with the payment terminal, while the other communicated with the expired physical card. The phones passed payment information between them.

During that exchange, the researchers changed the expiration date sent to the terminal.

Visa’s tested system did not fully protect that expiration information from changes. As a result, the terminal could treat an expired card as valid.

The payment request then reached the bank that issued the card. Some banks performed extra checks, while others approved the test transaction.