Zombie Card Attack Allows Expired Card Transactions
Researchers have uncovered a "zombie card attack" that can revive expired credit cards for unauthorized contactless payments. Learn how this surprising vulnerability works and what steps you can take to protect your accounts.

You might assume that once your credit card expires, it becomes a useless piece of plastic. However, recent findings from security researchers at the University of Massachusetts at Amherst suggest that some expired cards can be "revived" to make fraudulent purchases. This vulnerability, dubbed the zombie card attack, highlights a critical security loophole in certain contactless payment systems.
How the Vulnerability Works
The exploit allows an attacker who finds a physically expired card to make live transactions. According to Taqi Raza, Assistant Professor at UMass Amherst, the attack works by using a "man-in-the-middle" (MitM) relay system, which can be set up using two smartphones and custom software. This system intercepts the payment data from the expired card's chip during a contactless transaction.
The core of the problem lies in a discrepancy between two different expiration dates associated with the card. "We discovered that these two dates do not match each other," Raza stated. While your card has a date printed on the front, the embedded chip contains a separate digital certificate with its own expiration date, which researchers found can be valid for years longer. The MitM system digitally alters the transaction data to reflect the later date, effectively bypassing the printed expiration and getting the purchase approved. The researchers demonstrated this contactless payment vulnerability in a research video and detailed the full credit card expiration bypass method in their published study.
Scope and Impact
To test the real-world implications, the research team successfully made fraudulent purchases in various stores, including coffee shops and grocery stores. It's important to note that their findings showed that not all credit cards were susceptible to the zombie card attack, suggesting the vulnerability depends on the specific card issuer and payment network.
Interestingly, the study found that digital wallets, such as Apple Pay or Google Pay, often have additional security measures that make them more resilient to this particular exploit. The researchers have reported their findings to major payment networks, including Visa and MasterCard, to address this potential Visa payment vulnerability.
How to Protect Yourself
While the financial industry works to address this issue, there are simple, effective steps you can take to protect your accounts from this and other types of fraud.
- Securely Destroy Expired Cards: Don't just toss an old card in the trash. To prevent it from being used, cut it up or shred it, making sure to destroy the EMV chip, the magnetic stripe, and the full account number.
- Monitor Your Statements: Regularly review your credit card and bank statements for any unauthorized transactions, no matter how small. Many fraudulent charges start with a small test amount.
- Report Suspicious Activity Immediately: If you spot a charge you don't recognize, contact your financial institution right away. Federal law limits your liability for fraudulent charges, but prompt reporting is key.
Conclusion and Next Steps
The discovery of the "zombie card attack" serves as a crucial reminder that physical card security is important even after a card's printed expiration date has passed. The findings reveal a significant gap in how some payment systems verify transaction data, putting the responsibility on the financial industry to close this loophole. For now, the best defense is vigilance and the simple habit of thoroughly destroying your old plastic.