USENIX Security2024Top-tier venue
In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping
Raja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi Raza
Abstract
Digital wallets are a new form of payment technology that provides a secure and convenient way of making contactless payments through smart devices. In this paper, we study the security of financial transactions made through digital wallets, focusing on the authentication, authorization, and access control security functions. We find that the digital payment ecosystem supports the decentralized authority delegation which is susceptible to a number of attacks. First, an attacker adds the victim's bank card into their (attacker's) wallet by exploiting the authentication method agreement procedure between the wallet and the bank. Second, they exploit the unconditional trust between the wallet and the bank, and bypass the payment authorization. Third, they create a trap door through different payment types and violate the access control policy for the payments. The implications of these attacks are of a serious nature where the attacker can make purchases of arbitrary amounts by using the victim's bank card, despite these cards being locked and reported to the bank as stolen by the victim. We validate these findings in practice over major US banks (notably Chase, AMEX, Bank of America, and others) and three digital wallet apps (ApplePay, GPay, and PayPal). We have disclosed our findings to all the concerned parties. Finally, we propose remedies for fixing the design flaws to avoid these and other similar attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 809477e0-0907-4cac-b114-9e532546b0e8Cited by top-tier papers2
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
- "Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFCYilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao et al.USENIX Security 2026
Builds on16
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- The Many Kinds of Creepware Used for Interpersonal AttacksKevin A. Roundy, Paula Barmaimon Mendelberg, Nicola Dell, Damon McCoy et al.S&P 2020 · 46 citations
- Defensive Technology Use by Political Activists During the Sudanese RevolutionAlaa Daffalla, Lucy Simko, Tadayoshi Kohno, Alexandru G. BardasS&P 2021 · 44 citations
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li et al.USENIX Security 2017 · 34 citations
Related papers
- Security Analysis of Unified Payments Interface and Payment Apps in IndiaRenuka Kumar, Sreesh Kishore, Hao Lu, Atul PrakashUSENIX Security 2020
- Identity Confusion in WebView-based Mobile App-in-app EcosystemsLei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao et al.USENIX Security 2022
- WalleTruth: Visual-Oriented Software Testing for Web3 Wallet Browser ExtensionsXiaohui Hu, Ningyu He, Haoyu WangFSE 2026
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 4 citations
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
