Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
Raja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi Raza
摘要
Contactless payment cards are widely assumed to stop working past their printed expiration dates, and many stakeholders rely on this assumption for authorization and access control. This paper shows that banks enforce the expiration as a transaction policy check, rather than an intrinsic property of the card, which allows an expired card to still initiate contactless payments. We demonstrate a practical "Zombie Card" attack that makes an expired card appear unexpired, allowing successful transactions despite the card being past its printed date. We evaluate the attack across real-world transaction configurations spanning multiple EMV kernels (Visa, Mastercard, and Discover), POS terminals, merchants, and five (5) major US banks. Our results show that Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection. We further find that banks often rely on the POS terminal's decisions and skip critical security checks during transaction authorization for faster payments. Across our trials, the attack remains operational under typical in-store conditions using commodity NFC transceivers and does not require specialized hardware. Together, these findings indicate that the outcome of a "zombie card" transaction is determined by how security responsibility is divided between terminals, card manufacturers, and issuers, and by how consistently issuers enforce card lifecycle state. Based on these findings, we propose countermeasures that span kernels, issuers, and payments to ensure end-to-end transaction integrity and security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 被引用 69 次
- Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile PaymentXiaolong Bai, Zhe Zhou, XiaoFeng Wang, Zhou Li 等USENIX Security 2017 · 被引用 34 次
- Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa TransactionsDavid A. Basin, Ralf Sasse, Jorge Toro-PozoUSENIX Security 2021 · 被引用 32 次
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu 等S&P 2022 · 被引用 26 次
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 被引用 4 次
相关 Paper
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free ShoppingRaja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi RazaUSENIX Security 2024
- More is Less: Extra Features in Contactless Payments Break SecurityGeorge Pavlides, Anna Clee, Ioana Boureanu, Tom ChothiaUSENIX Security 2025
- Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment AppsJesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain 等S&P 2026
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 被引用 39 次
