‘Zombie Card’ Attack Revives Expired Visa Cards for Real Purchases
Published On 24 Aug, 2026
The researchers, presenting their findings at the 35th USENIX Security Symposium, call this the “Zombie Card” attack. The method is alarmingly simple: with just two regular smartphones, attackers can set up a relay system. All they need is to get hold of an expired card, or stay close to it with NFC equipment.
The flaw exploits a fundamental weakness in how Visa handles expiration dates in tap-to-pay transactions.
When a customer taps their card at checkout, the payment terminal reads one expiration date, but the card’s issuing bank sees another. The system does not securely link these two pieces of information.
With the two-phone relay, attackers can intercept the card data and change the expiration date that the terminal receives.
Since the digital security certificates on the card often stay valid long after the card itself expires, the payment terminal accepts the card as if it were still active and approves the purchase.
Lead researcher Raja Hasnain Anwar explained that attackers do not even need to know the victim’s actual replacement expiration date. Because the metadata lacks cryptographic protection, any arbitrary future date can easily fool the system.
The UMass team tested this flaw against five major US banks. While responses varied, no bank cleanly rejected the exploit. The researchers successfully completed live retail and grocery store purchases on campus, as well as laboratory transactions totaling up to $500.
The researchers first reported their findings to Visa and the banks involved earlier this year, but so far, Visa has not updated its terminal requirements.