Skip to content
theregister·

🚨Researchers Revive Expired Visa Cards for Unauthorized Payments

Visa cards can be tricked into working after expiration

TL;DR

Researchers found a way to revive expired contactless credit cards and make unauthorized payments. The vulnerability affects Visa's EMV protocol but not other major brands like Mastercard or American Express.

Researchers discovered that expired contactless credit cards can be revived to make unauthorized purchases, exploiting weaknesses in the Visa EMV payment process. This means that even after a card expires, it could still be used fraudulently if an attacker knows how to manipulate the transaction flow. The vulnerability arises because some data exchanged between the card and terminal is not fully encrypted until later verification steps, allowing for man-in-the-middle attacks using NFC proxy devices. Visa's EMV kernel implementation is more permissive compared to other major payment brands, making it particularly susceptible to such attacks.

Researchers Revive Expired Visa Cards for Unauthorized Payments — theregister

Key Points

1

Visa's EMV kernel implementation is more permissive, allowing POS terminals to evaluate processing restrictions based on Application Expiration Dates (AED).

2

Mastercard, American Express, and Discover configurations resisted the attack due to stricter integrity protection mechanisms in their protocols.

3

Researchers notified Visa of their findings in May 2025 and followed up in December 2025 but received no confirmation from Visa or banks about mitigations.

4

The EMV contactless protocol is fragile because transaction flow authentication is selective, allowing plaintext data exchange before cryptographic verification.

5

Some data sent between the card and terminal is only later linked to cryptographic verification using Offline Data Authentication (ODA) and issuer-verified cryptograms.

Why It Matters

If you're a Visa cardholder with an expired contactless credit card, your card could still be used fraudulently. Banks handling transactions play a crucial role in mitigating this risk; however, the lack of cryptographic binding between expiration dates and transaction data makes it easier for attackers to manipulate.

credit-cardsemv-protocolvisa-securitycontactless-payments

Frequently Asked Questions

Why does this matter?

If you're a Visa cardholder with an expired contactless credit card, your card could still be used fraudulently. Banks handling transactions play a crucial role in mitigating this risk; however, the lack of cryptographic binding between expiration dates and transaction data makes it easier for attackers to manipulate.

What happened?

Researchers found a way to revive expired contactless credit cards and make unauthorized payments. The vulnerability affects Visa's EMV protocol but not other major brands like Mastercard or American Express.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,179 builders reading daily.

Also get