The Hidden Danger of Discarded Payment Cards

Many consumers mistakenly believe that once a credit card reaches its expiration date, it becomes essentially useless plastic. However, recent findings from researchers at the University of Massachusetts Amherst suggest otherwise. The study reveals that so-called "zombie cards"—cards that have officially expired—can still be manipulated to complete contactless purchases at legitimate point-of-sale terminals.


The Mechanics of the Vulnerability

The security flaw stems from the way EMV (Europay, Mastercard, and Visa) contactless protocols handle data validation. Unlike what many might assume, the expiration date is not always a strictly enforced property of the card itself. Instead, it often functions as a policy check between various parties—the terminal, the bank, and the card network—without a clear consensus on who is responsible for the final verification.

In many contactless transaction flows, data is transmitted in unencrypted text, and the verification process is only selectively authenticated. The researchers discovered that for certain Visa cards, the "Application Expiration Date" read by a terminal is not covered by the card’s digital signature. This oversight allows an attacker with physical access to an expired card to intercept the communication and modify the expiration date to a future, valid value using two standard smartphones.


Why Existing Protections Fail

The research notes that the vulnerability is exacerbated by two primary factors:

  • Certificate Mismatch: The digital certificates embedded within the card chip often remain valid long after the date printed on the plastic, effectively "tricking" the system into believing the card is still active.
  • Lack of Relay Resistance: There is an existing industry standard known as the "Relay Resistance Protocol" designed to detect and block "man-in-the-middle" relay attacks by measuring transaction timing. However, this feature is optional and was found to be disabled across all terminals and cards tested by the team.

Scope and Industry Response

While the attack requires physical possession of the card and a sophisticated setup, it represents a significant security oversight. The researchers noted that the issue primarily affects Visa cards, as other major networks like Mastercard, Discover, and American Express were shown to reject the altered data automatically.

"Payment decisions have spread across multiple players—chip, terminal, network, and bank architectures—where each assumes expiry is someone else's responsibility," the researchers observed.

The academic team alerted Visa and affected financial institutions to these findings in May 2025 and provided further documentation in December 2025. Despite this, there has been no official confirmation of a fix or a timeline for mitigation. Until a solution is implemented, experts advise users to avoid treating expired cards as harmless. The only safe way to prevent this type of abuse is to physically destroy the EMV chip and ensure the card numbers are completely defaced.