🚨Researchers Revive Expired Visa Cards for Unauthorized Payments
Visa cards can be tricked into working after expiration
TL;DR
Researchers found a way to revive expired contactless credit cards and make unauthorized payments. The vulnerability affects Visa's EMV protocol but not other major brands like Mastercard or American Express.
Researchers discovered that expired contactless credit cards can be revived to make unauthorized purchases, exploiting weaknesses in the Visa EMV payment process. This means that even after a card expires, it could still be used fraudulently if an attacker knows how to manipulate the transaction flow. The vulnerability arises because some data exchanged between the card and terminal is not fully encrypted until later verification steps, allowing for man-in-the-middle attacks using NFC proxy devices. Visa's EMV kernel implementation is more permissive compared to other major payment brands, making it particularly susceptible to such attacks.

Key Points
Visa's EMV kernel implementation is more permissive, allowing POS terminals to evaluate processing restrictions based on Application Expiration Dates (AED).
Mastercard, American Express, and Discover configurations resisted the attack due to stricter integrity protection mechanisms in their protocols.
Researchers notified Visa of their findings in May 2025 and followed up in December 2025 but received no confirmation from Visa or banks about mitigations.
The EMV contactless protocol is fragile because transaction flow authentication is selective, allowing plaintext data exchange before cryptographic verification.
Some data sent between the card and terminal is only later linked to cryptographic verification using Offline Data Authentication (ODA) and issuer-verified cryptograms.
Why It Matters
If you're a Visa cardholder with an expired contactless credit card, your card could still be used fraudulently. Banks handling transactions play a crucial role in mitigating this risk; however, the lack of cryptographic binding between expiration dates and transaction data makes it easier for attackers to manipulate.
Frequently Asked Questions
Why does this matter?
If you're a Visa cardholder with an expired contactless credit card, your card could still be used fraudulently. Banks handling transactions play a crucial role in mitigating this risk; however, the lack of cryptographic binding between expiration dates and transaction data makes it easier for attackers to manipulate.
What happened?
Researchers found a way to revive expired contactless credit cards and make unauthorized payments. The vulnerability affects Visa's EMV protocol but not other major brands like Mastercard or American Express.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,179 builders reading daily.