Researchers expose flaw that lets expired contactless cards be used for payments
Researchers at the University of Massachusetts Amherst demonstrated that expired contactless Visa cards can be tricked into completing purchases via a man-in-the-middle NFC attack.
In a paper presented at USENIX Security 2026, researchers from the University of Massachusetts Amherst described an attack that revives expired contactless credit cards for unauthorized transactions. By inserting an NFC proxy between the card and the terminal, they can modify the Application Expiration Date that the terminal reads, because Visa’s contactless kernel does not include this field in its digital signature. The altered date passes the terminal’s checks, and the transaction proceeds if the issuing bank does not reject it, allowing purchases with cards that should be invalid.
Tests showed Visa cards were vulnerable, whereas Mastercard, American Express and Discover cards blocked the attack. The authors notified Visa in May 2025 and followed up in December 2025, but Visa has not confirmed a fix. The findings highlight a trade-off between transaction speed and security in contactless payment designs.
Why it matters
A flaw that lets dead cards be used could enable fraud and undermine confidence in contactless payments.
In this story
