Zombie Card: An expired Visa credit card can be used for purchases
Did you know there is still a good reason to physically destroy your expired credit card?
Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering.
University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.
They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.”
The result was not universal. The tested Mastercard, American Express, and Discover configurations rejected the altered expiry data, while issuer behavior differed even among the tested Visa cards: Some transactions were declined or prompted for a replacement card, while others were approved.
The flaw lies in the Visa Kernel 3 contactless flow, where the terminal-facing Application Expiration Date was not effectively bound to the card’s data. In the tested Mastercard, American Express, and Discover kernels, consistency checks or authenticated-data coverage caused modified expiry data to be detected and the transaction to be declined.
How this could be abused
The most credible abuse case is theft or recovery of an expired or replaced card which the owner regards as harmless. Consider cards left in household waste, a drawer, a lost wallet, or an unsecured corporate disposal stream. If the underlying account remains open and issuer-side controls do not validate the exact card lifecycle state, an attacker could attempt contactless purchases using a relay setup.
Less likely is a scenario that uses a proximity relay attack against a card still held by its owner. That requires sustained NFC (Near Field Communication) proximity and a live relay during the transaction, making it materially harder than merely scanning a card from a passing distance.
How to stay safe
For cardholders, the practical advice is simple:
- Destroy expired and replacement cards. Cut through the chip several times. Make further cuts through the card body to disrupt the contactless antenna, and damage the magnetic stripe before disposing of the pieces.
- Report a lost expired card rather than treating it as inert.
These are sensible precautions, but the primary responsibility lies with payment networks, terminal implementations, and issuers to ensure expiry data is integrity-protected and that authorization systems reject retired card credentials.
Something feel off? Check it before you click.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.