Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

The Threat of "Zombie Credit Cards"

Scientists have proven that an expired physical card—even after a new one has been issued—can still be used to make in-store purchases via its contactless (NFC) chip. How can expired cards come to life? The phenomenon,

Scientists have proven that an expired physical card—even after a new one has been issued—can still be used to make in-store purchases via its contactless (NFC) chip.

How can expired cards come to life?

The phenomenon, discovered by researchers at UMass Amherst and presented at USENIX Security 2026, exploits a critical flaw in how point-of-sale (POS) terminals and issuing banks communicate during contactless (NFC) transactions. While a physical piece of plastic has a printed expiration date, the underlying credit card account remains active to facilitate incoming funds (like merchant refunds). Hackers can use a relay system—requiring just two standard smartphones and emulator software—to intercept the NFC signal from an expired card and digitally rewrite the expiration date to a future one before it hits the store reader. Because many issuing banks rely entirely on the terminal’s partial verification rather than re-checking the cryptographic expiration data on their end, the transaction gets approved, bringing the "inert" card back to life.

What are card issuers doing about this loophole?

Currently, the vulnerability does not impact all networks equally. It primarily exploits specific contactless protocols (like Visa Kernel 3), whereas Mastercard, American Express, and Discover have built-in cryptographic data binding that successfully resisted this type of manipulation. The long-term fix requires card companies and issuing banks to mandate a strict end-to-end cryptographic signature on the expiration date for every transaction. While major card companies have been formally notified of this architectural flaw, implementing a global, systemic fix across millions of legacy POS terminals and institutional banking systems takes considerable time, leaving the loophole partially open in the short term.

How can consumers protect themselves?

The danger of this attack stems from a massive behavioral misconception: consumers assume that once a card expires, the old plastic becomes a useless piece of trash. As a result, old cards are often carelessly discarded in the household garbage, where they can be easily harvested by bad actors. To mitigate this risk, consumers must treat expired cards with the same security rigor as active ones.

Jarrod Wright, SVP Marketing at Chargebacks911, gives the following piece of advice,

"You might often read standard consumer advice suggesting you slice a card lengthwise along the magnetic stripe and discard the pieces into separate trash bins. While this remains a decent rule of thumb for legacy security, it is completely irrelevant to this specific vulnerability. The 'Zombie Card' exploit operates strictly through the wireless antenna of the embedded EMV chip. If your scissors physically cut directly through the center of that metallic chip, shattering its internal silicon architecture, it is mathematically impossible to reassemble. Once the chip is severed, it is permanently dead, and the exploit is completely neutralized. Furthermore, if you hand over an old card to bank staff for disposal, ensure they physically destroy the chip right in front of you. Otherwise, a compromised card could easily be retrieved from a branch trash bin the moment an employee looks away."

Beyond physical destruction, there are other measures you can take:

  • Account Monitoring. Continuously monitor transactions via your banking app, even on accounts where a card was recently replaced or updated.
  • Leverage Tokenization. Transitioning to digital wallets (like Apple Pay or Google Pay) provides an extra layer of protection, as they utilize device-bound, randomized tokens rather than broadcasting the static card details exposed by physical plastic. Conclusion: The "Zombie Card" phenomenon serves as a stark reminder that in a highly digitized financial ecosystem, security protocols must evolve alongside technology. Relying on legacy habits like cutting a magnetic stripe provides a false sense of security while leaving the vulnerable EMV chip fully operational. Moving forward, both institutional issuers and consumers must treat physical card retirement with the same cryptographic and physical rigor as managing active credentials—because in modern fintech, a card is only truly dead when its silicon architecture is destroyed.
📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.