USENIX Security2026Top-tier venue
Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
Raja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi Raza
Abstract
Contactless payment cards are widely assumed to stop working past their printed expiration dates, and many stakeholders rely on this assumption for authorization and access control. This paper shows that banks enforce the expiration as a transaction policy check, rather than an intrinsic property of the card, which allows an expired card to still initiate contactless payments. We demonstrate a practical "Zombie Card" attack that makes an expired card appear unexpired, allowing successful transactions despite the card being past its printed date. We evaluate the attack across real-world transaction configurations spanning multiple EMV kernels (Visa, Mastercard, and Discover), POS terminals, merchants, and five (5) major US banks. Our results show that Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection. We further find that banks often rely on the POS terminal's decisions and skip critical security checks during transaction authorization for faster payments. Across our trials, the attack remains operational under typical in-store conditions using commodity NFC transceivers and does not require specialized hardware. Together, these findings indicate that the outcome of a "zombie card" transaction is determined by how security responsibility is divided between terminals, card manufacturers, and issuers, and by how consistently issuers enforce card lifecycle state. Based on these findings, we propose countermeasures that span kernels, issuers, and payments to ensure end-to-end transaction integrity and security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 30ab768e-0795-4f62-803c-e39793043314Builds on8
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li et al.USENIX Security 2017 · 34 citations
- Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa TransactionsDavid A. Basin, Ralf Sasse, Jorge Toro-PozoUSENIX Security 2021 · 32 citations
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 4 citations
Related papers
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free ShoppingRaja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi RazaUSENIX Security 2024
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
- Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment AppsJesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain et al.S&P 2026
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 39 citations
