A vulnerability has been confirmed that allows some credit cards past their expiration date to be used again for contactless payments.
On Sept. 29, Japan's ITmedia reported that a University of Massachusetts Amherst research team disclosed a Zombie Card attack at the USENIX Security Symposium 2026 that makes an expired card appear to be valid.
The core issue is that even after a card expires, the payment function and cryptographic keys on the IC chip do not automatically deactivate. In an actual payment, the card, POS terminal, payment network and card issuer each verify validity. In that process, expiration-date information may not be protected and verified consistently.
The researchers reproduced communication between an expired card and a POS terminal in an NFC relay setup using 2 commercially available smartphones. When they tampered with the expiration-date information checked by the terminal, the card was recognized as still valid in some environments and the payment proceeded. No special payment equipment was needed.
The attack did not succeed with all cards. The team tested Visa, Mastercard, American Express and Discover and confirmed a successful case in Visa's contactless payment specification Kernel 3. In test configurations for the other 3 payment networks, tampering was detected and the transaction was declined.
Card issuers also responded differently. Some banks relied on the POS terminal's judgment and did not sufficiently recheck the expired status, approving the transaction, while other banks declined the payment or required a replacement card. The researchers verified this using 5 major U.S. banks and real payment environments.
The researchers said, "This issue is not so much an attack that broke the card cryptosystem as a structural weakness that arose because responsibility for verifying the expiration date is divided among the terminal, payment network and issuer." They added that expired cards should be handled safely before disposal, such as by physically damaging the IC chip.