Why can expired contactless cards still make payments?
Credit card expiry dates are commonly seen as a firm cutoff on card usability. However, with contactless payments, this expiration check is not always enforced by the card itself but rather as a policy decision between the payment terminal and the card issuer. This difference in enforcement creates a potential loophole where an expired contactless card, sometimes called a 'zombie card,' can be used for a purchase if certain conditions are met.
Specifically, the Application Expiration Date that a payment terminal reads during a contactless transaction is transmitted in an unprotected way; it’s not covered by the card’s digital signature. This means the expiry date can be modified by an attacker intercepting the transaction between the card and terminal, potentially changing it to a date that is still valid, allowing the transaction to proceed.
What makes this vulnerability possible and who is affected?
The root of this issue lies in how parts of the payment data travel unencrypted between the card and terminal, combined with incomplete cryptographic protection of the expiry date field. Additionally, the digital certificate used in card-to-terminal communication can have an expiry date that extends beyond the card’s printed expiration, which fails to catch these discrepancies.
This flaw has been demonstrated mainly with Visa contactless cards. Other major networks like Mastercard, American Express, and Discover appear to reject altered expiry dates outright, reducing their risk.
However, exploiting this flaw requires physical possession of the expired card and two ordinary smartphones for the attack, making it complex and limiting the scope of misuse.
Why aren't current security protocols preventing this?
EMV payment standards include protection methods like the Relay Resistance Protocol, which can detect and block attempts to relay or alter data between a card and terminal by measuring timing delays. Unfortunately, this protection is optional, and testing has shown it is not enabled on many cards or terminals. Consequently, the vulnerability remains exploitable.
Despite being reported to Visa and affected banks with detailed reproduction instructions, no confirmed fix or mitigation strategy has been publicly communicated. This highlights a challenge: responsibility for verifying expiration dates is fragmented across banks, card networks, terminals, and chip manufacturers, allowing such security gaps to persist.
What should cardholders do to protect themselves?
Until official mitigations are widely adopted, users should not assume expired cards are harmless. Discarded cards with chips should have their chips physically destroyed, and card numbers should be obscured or cut to prevent reuse.
Maintaining physical control over old cards and timely destruction is crucial, as the attack requires the attacker to have the expired card itself.
Final takeaway: Understanding and addressing hidden risks in contactless payment security
While contactless payments offer convenience, they also introduce complex security dynamics involving multiple parties. The ability to use expired cards by exploiting unprotected transaction fields underscores the importance of coordinated security enforcement across all payment system components.
Cardholders should remain vigilant with expired cards and demand clearer security responses from card issuers and payment networks. Until changes are implemented, safeguarding physical card disposal remains the best practical defense against this unusual but real risk.
