
Researchers at the University of Massachusetts Amherst have demonstrated what they call the “Zombie Card” attack: a technique that brings expired Visa contactless payment cards back to life by intercepting and altering the expiry date the card broadcasts over NFC, without touching any of the card’s cryptographic protections. The attack was tested successfully at a point-of-sale terminal at a U.S. bank.
The trick exploits how Visa’s NFC contactless protocol handles card authentication. When you tap an expired card, the POS terminal reads the expiry date from the NFC exchange and rejects the transaction. But the card’s cryptographic signature does not cover the expiry field in a way that prevents real-time modification. Researchers placed a relay device between the card and the reader that rewrites the expiry date in transit — the terminal then sees a valid, non-expired card and approves the charge. The card’s CVV and cryptogram remain intact, so issuer-side fraud checks that rely on those values still pass. The technique was confirmed to work against one tested U.S. bank; the researchers did not identify which issuer.
How to check if you’re affected
Affected products include any expired Visa contactless credit or debit card that you still physically possess and have not formally cancelled with your bank. Simply cutting a card in half does not cancel the account; the card number remains live until you call the issuer and request cancellation. To reduce your exposure: contact your bank to formally deactivate old card numbers when new cards arrive, enable real-time transaction alerts on all accounts, and check statements for small unfamiliar charges. Chip-and-PIN transactions require physical insertion and a PIN and are not vulnerable to this specific relay technique.
