Expired Credit Cards Pose Major Security Risk for Payments

Researchers from the University of Massachusetts have uncovered a significant security vulnerability in contactless payment systems related to expired credit cards, often referred to as “zombie cards.” This flaw allows technically invalid cards to process transactions under specific conditions, posing a substantial risk to consumers worldwide. The vulnerability stems from the fact that the expiration date read by payment terminals is not protected by digital signatures, enabling attackers to manipulate the data. This discovery highlights a critical oversight in how payment networks handle card validity, potentially exposing users to unauthorized charges even after their cards have officially reached their expiration dates.
- Researchers identified that the expiration date field on contactless cards lacks cryptographic protection against manipulation.
- A relay attack involving two smartphones can trick payment terminals into accepting expired cards as valid.
- Visa cards were specifically found to be susceptible to this vulnerability during laboratory testing protocols.
- Mandatory implementation of existing security protocols like the Relay Resistance Protocol could mitigate these risks effectively.
Contactless Payment Systems Face Technical Exploitation
The mechanism behind this security breach relies on a relay system that bridges the gap between an expired card and a payment terminal. By using two smartphones, an attacker can intercept and modify the signals sent during the payment handshake. Because the expiration date is treated as a policy check rather than a cryptographically verified field in certain configurations, the terminal fails to detect that the card is no longer valid.
This process exploits the complexity of the payment ecosystem, which involves multiple entities including merchants, card networks, and issuing banks, often leading to fragmented security responsibilities.
The lack of a secure link between the digital signature and the expiration date creates a window of opportunity for sophisticated relay attacks.
Network Variations Influence Vulnerability Levels
While the research team focused heavily on the structural flaws within the payment process, they noted significant differences between card networks. Testing revealed that while Visa cards were susceptible to date manipulation, other major networks such as Mastercard, Discover, and American Express successfully rejected the altered expiration data. The core issue remains that the terminal reads the date as plain text before cryptographic verification occurs, making the system vulnerable to attackers who can manipulate the data stream in real-time.
Security Protocols Remain Largely Unimplemented
Although the industry standard known as the Relay Resistance Protocol exists to prevent exactly these types of relay attacks, it remains an optional feature. Consequently, the researchers found that none of the terminals or cards tested had this protection enabled. Despite sharing these findings with Visa and relevant banking institutions throughout 2025, no official patches or systemic updates have been confirmed by the involved parties to address this critical gap in the contactless payment infrastructure.
Consumers are strongly advised to physically destroy expired payment cards by cutting through the chip to prevent any potential unauthorized usage.
As the financial sector continues to rely on legacy standards, the need for mandatory, non-optional security measures becomes increasingly urgent. Until banks move to enforce stricter validation protocols, the onus remains on the cardholder to ensure their decommissioned plastic is rendered completely unusable.
Given the ongoing risks associated with expired card data, do you believe financial institutions should be legally required to implement stricter security standards for all contactless transactions, or does the responsibility lie primarily with the user?
Your comment has been submitted,
it will be published after approval.