• Tech Tech

Massachusetts researchers revive 'dead' Visa credit cards for contactless payments

"Visa contactless transactions are susceptible to man-in-the-middle tampering."

Credit cards.

Photo Credit: iStock

Even after a card expires, it may not be unusable.

A University of Massachusetts Amherst team found that certain expired Visa tap-to-pay cards could still be used if a transaction were relayed through mobile phones, revealing a weakness in the contactless payment system.

Here's what to know

At USENIX Security 2026, UMass Amherst doctoral candidate Raja Hasnain Anwar and fellow researchers Gerard DeCunha and Muhammad Taqi Raza presented the work in a paper titled Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments, The Register reported.

The issue the researchers described stems from a mismatch in how expiration data is handled during a tap-to-pay purchase. In one configuration, a technically skilled person could place mobile phones between the card and the payment terminal and exploit that gap so an expired card appeared valid long enough to try a transaction.

The researchers summarized it this way, according to The Register: "The card gives the checkout terminal an expiry date to read. In the Visa contactless configuration we tested, that particular date was not covered by the card's digital signature. Someone positioned between the card and terminal could therefore alter what the terminal sees while leaving the card's normal security checks looking valid."

The outcome was not the same across networks. The same attack failed in the team's tests against Mastercard, American Express, and Discover. Even among Visa contactless cards, results varied, and a bank's authorization process could determine whether the purchase was approved.

More background

By contrast, inserted chip transactions usually handle expiration checks more directly. Contactless payments are built for speed, so some details are passed early in the exchange and only tied into security protections further along in the transaction.

That split can matter if someone has physical access to a card and the equipment needed to relay and alter what a terminal receives. In that situation, the terminal and the issuing bank may end up acting on different versions of the expiration information.

The researchers said as much in their paper, writing, "Our results show that Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection," per The Register.

The researchers alerted Visa in May 2025 and again in December and also said that neither Visa nor the notified banks had confirmed a fix for the expiration-date flaw.

What can be done?

For the payments industry, the findings show that the expiration date shown to a checkout terminal should be cryptographically linked to the data the issuing bank reviews during authorization.

The paper also indicated that banks with strong back-end verification may have a good chance of stopping questionable transactions before approval, The Register reported.

Old tap-to-pay cards should not be treated as waste. If one is no longer needed, it is best to cut it up or otherwise destroy it securely instead of discarding it intact.

Account alerts and regular statement checks can catch unfamiliar charges. This attack appears to require specialized tools and is unlikely to affect many people, but expired payment cards should still be handled like active financial data.

"It comes down to the trade-off between performance and security and often leaves room for this kind of vulnerability. No design is inherently bad," Anwar told The Register.

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider