
An expired credit card sitting in a junk drawer might not be as useless as you think. Researchers at the University of Massachusetts at Amherst say they uncovered a loophole that lets an expired Visa credit card complete real, live purchases at grocery stores, coffee shops, and other merchants using contactless tap-to-pay, even after the card's printed expiration date has passed.
The findings come from a paper titled “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments,” written by researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza and presented at the 35th USENIX Security Symposium in Baltimore this month, according to The Hacker News. Taqi Raza is an assistant professor at UMass Amherst, as reported by First Alert 4. The vulnerability specifically targets Visa's contactless payment specification known as Kernel 3, where the terminal-facing Application Expiration Date, a data field called EMV tag 5F24, is transmitted unencrypted over NFC and is excluded from the card's fast Dynamic Data Authentication signature, per The Hacker News.
How the Two-Phone Trick Works
According to First Alert 4, researchers used smartphones and man-in-the-middle relay software to pull off the attack. One phone reads the credit card information, and a second phone rewrites the credit card's expiration date before relaying it on to the payment terminal, First Alert 4 reports. The mismatch is possible because the digital certificate embedded in a card's chip can expire years after the date printed on the physical card, per the outlet's reporting.
The proof-of-concept setup used two off-the-shelf Android smartphones linked over Wi-Fi, introducing only about 70 milliseconds of latency as payment signals relayed between the expired card and the point-of-sale terminal, according to TechJuice. The underlying flaw stems from how Visa contactless transactions pass expiration data in two separate fields, tag 5F24 read locally by the terminal and tag 57 sent onward to the issuing bank, with no requirement that the two values match, as reported by Business Tech Weekly.
Real Transactions at Real Stores
This was not just a lab exercise. Researchers verified the real-world impact by executing live contactless transactions at retail and grocery merchants, demonstrating that replaced physical cards could still complete payments as long as the underlying bank account remained open, per the same account from RH-ISAC. First Alert 4 notes that a tap-to-pay card reader did decline a transaction from an expired card in one instance, while the man-in-the-middle relay system separately enabled approval of a transaction from an expired card, according to the outlet's report.
The attack exploits ordinary habits: expired credit cards still carry an existing line of credit, and cardholders routinely keep or discard old cards believing them harmless, while issuing banks intentionally leave the underlying accounts open so expired cards can still process refunds and returns, according to Help Net Security. That combination, the researchers argue, creates a blind spot that few consumers would think to guard against.
Other Card Networks Blocked the Attack
Not every network was vulnerable. Testing across other major card networks found that Mastercard's Kernel 2, American Express's Kernel 4, and Discover's Kernel 6 all successfully blocked the attack because their specifications enforce consistency checks or fold expiration data directly into authenticated signatures, according to Malwarebytes. Bank responses on the Visa side also varied widely. In tests across five major U.S. banks, researchers observed three distinct authorization policies, with one bank approving altered transactions from multiple expired cards on the same account simultaneously, and another detecting the alteration but still allowing the transactions to go through, per The Hacker News.
Per the outlet's reporting, the article notes that credit cards impacted by the loophole span the affected Visa ecosystem, though the researchers found digital wallets carry security measures that make them more resilient against the relay attack, according to First Alert 4. First Alert 4 reports that Visa and Mastercard had not responded to the outlet's requests for comment about the findings as of publication, even though both networks were asked about the report.
No Public Fix Yet
The UMass Amherst team disclosed the vulnerability to Visa and affected financial institutions in May 2025 and again in December 2025, but as of this month, no CVE identifier had been assigned and no public security advisories had been issued, according to Business Tech Weekly. The researchers outlined four architectural fixes in their paper: cryptographically signing expiration dates, requiring terminals to compare internal date representations, mandating issuers to check account number and date pairs together, and preserving terminal validation flags sent on to issuers, per Business Tech Weekly's report.
Until any of those changes are adopted industry-wide, the researchers' practical advice is blunt. They recommend cutting up or shredding expired credit cards entirely, destroying the account number, the magnetized strip, and the embedded digital chip rather than tossing an old card in a drawer, First Alert 4 reports. Cardholders should also check their bank statements regularly for unauthorized transactions, according to the outlet.









