Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New Vulnerability Discovered in Contactless Payments: "Zombie Card" Attack Can Revive Expired Visa Cards




A newly discovered vulnerability in contactless payments has the potential to allow hackers to revive expired Visa cards for real-world transactions. The "Zombie Card" attack exploits a series of weaknesses in Visa's Kernel 3 protocol, allowing attackers to rewrite the expiration date on a point-of-sale (POS) terminal. To prevent this type of attack, researchers have proposed several countermeasures, including binding expiry-critical data to an issuer-verifiable signature and preserving terminal validation signals. As the world of technology continues to evolve, it is essential that we remain proactive in identifying and mitigating vulnerabilities like this one.

  • The "Zombie Card" attack allows hackers to revive expired Visa cards for real-world transactions.
  • The attack exploits weaknesses in Visa's Kernel 3 protocol, which handles expiration dates.
  • The attack requires physical possession of the expired card or sustained NFC proximity to it, plus a man-in-the-middle relay.
  • The relay allows the attacker to intercept and modify transaction data, effectively extending the expiration date of the card.
  • Researchers have proposed several countermeasures to prevent this type of attack, including binding expiry-critical data to an issuer-verifiable signature.



  • The world of contactless payments has just taken a dramatic turn, with a newly discovered vulnerability that allows hackers to revive expired Visa cards for real-world transactions. Dubbed the "Zombie Card" attack, this exploitation of Visa's Kernel 3 protocol enables attackers to rewrite the expiration date on a point-of-sale (POS) terminal, effectively bringing the card back to life.

    According to researchers at the University of Massachusetts Amherst, who have been studying the vulnerability, the attack is made possible by a series of weaknesses in the way Visa's Kernel 3 protocol handles expiration dates. Specifically, the researchers found that the terminal's processing restrictions are not consistent, allowing an attacker to modify the terminal-facing date without breaking the card's cryptography.

    The attack requires physical possession of the expired card or sustained NFC proximity to it, plus a man-in-the-middle (MitM) relay positioned between the card and the terminal. This relay is essentially a two-way communication device that allows the attacker to intercept and modify the transaction data.

    Once the attacker has established the MitM relay, they can rewrite the terminal-facing date to any future value, effectively extending the expiration date of the card. However, this modification does not affect the card's signature or its issuer-verified cryptogram, which remain unchanged.

    The researchers tested the attack on four major US banks, with varying results. One bank approved the revived transactions, while another declined them outright. A third bank had a different Europay, Mastercard, and Visa (EMV) kernel on which the modification failed outright.

    To exploit this vulnerability, the attacker does not need to know the replacement card's real expiration date. Any date later than the transaction date is sufficient. The researchers also found that the attacker does not need to know the PAN (primary account number) of the card, as the PAN remains open under the same primary account number.

    The researchers have proposed several countermeasures to prevent this type of attack, including:

    * Binding the expiry-critical data to an issuer-verifiable signature
    * Checking the two expiry representations against each other
    * Authorizing against a PAN and expiry tuple
    * Preserving the terminal validation signals
    * Destroying the chip and magnetic stripe of expired cards, and keeping monitoring a closed account

    The discovery of this vulnerability has significant implications for the financial industry, as it highlights the importance of robust security measures to protect contactless payments. The researchers' findings have been presented at the 35th USENIX Security Symposium, and the paper's authors have made contact with Visa and the affected banks to inform them of the vulnerability.

    In related news, researchers from Singapore-headquartered Group-IB have documented a previously unseen Android NFC relay malware family, which they track as "WindRelay." This malware family is deployed alongside the "SpyNote" remote access trojan (RAT) in live-call social engineering attacks against victims in Czechia, Slovakia, and Slovenia.

    The development of this vulnerability and the accompanying countermeasures serves as a reminder of the importance of staying vigilant in the face of emerging threats to our personal and financial security. As the world of technology continues to evolve, it is essential that we remain proactive in identifying and mitigating vulnerabilities like this one.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-Vulnerability-Discovered-in-Contactless-Payments-Zombie-Card-Attack-Can-Revive-Expired-Visa-Cards-ehn.shtml

  • https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html


  • Published: Thu Aug 20 11:10:54 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us