Listen to this Post
Introduction: The Card You Thought Was Useless Could Still Matter
Most people treat an expired credit card as harmless plastic. Once a replacement arrives, the old card is often tossed into a drawer, dropped into household waste, or cut once before being thrown away. The assumption is simple: the expiration date has passed, so the card is dead.
Security researchers have shown that this assumption may not always be safe.
A team from the University of Massachusetts Amherst discovered that, under specific conditions, the expiration information presented by certain contactless payment cards could be manipulated before reaching a payment terminal. In successful tests, expired Visa contactless cards were effectively brought back to life for real-world purchases.
The researchers called the concept the “Zombie Card.”
The discovery does not mean that every expired card can suddenly be used again. The results depended on the payment network, the issuing bank, the card configuration, and the transaction environment. Mastercard, American Express, and Discover configurations tested by the researchers rejected the manipulated expiration data.
However, the research raises an uncomfortable question.
If an expired card is no longer supposed to be usable, why should anyone assume that simply throwing it away is enough?
The Original Research: How Expired Cards Were Brought Back
Researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza examined contactless payment cards issued across major US financial institutions and payment networks.
Their testing included cards associated with Visa, Mastercard, Discover, and American Express. The researchers also used multiple payment terminals, merchants, and cards issued by five major US banks.
The central discovery involved the expiration date transmitted during certain contactless transactions.
Under the vulnerable scenario, researchers were able to alter the expiration date information seen by the payment terminal. Instead of the terminal receiving the card’s real, expired date, it could be presented with a future expiration date.
That modification allowed some expired Visa contactless cards to complete real in-store purchases.
In other words, the physical card had reached the end of its intended lifecycle, but under specific conditions, its contactless functionality could still participate in a successful transaction.
That is where the name Zombie Card comes from.
The card was supposed to be dead.
Instead, it came back.
The Vulnerability Was Not Universal
One of the most important details in the research is that this was not a universal weakness affecting every card or payment network.
The researchers found that tested Mastercard, American Express, and Discover configurations rejected the altered expiration information.
Different Visa cards also behaved differently.
Some transactions were declined.
Some systems appeared to recognize that the card had been replaced or retired.
Other transactions, however, were approved.
This difference is important because payment security is not controlled by a single system. A transaction can involve the physical card, the contactless protocol, the payment terminal, the merchant, the acquiring institution, the payment network, and the issuing bank.
Security can therefore depend on multiple layers working correctly.
If one layer assumes another layer has already validated critical information, a gap can emerge.
The Technical Problem: When Expiration Data Is Not Properly Bound
According to the research, the weakness was connected to the Visa Kernel 3 contactless transaction flow.
The key issue involved the Application Expiration Date presented to the payment terminal.
Security systems are strongest when important information cannot be modified without detection. If data is cryptographically authenticated or protected by integrity checks, changing it should cause the transaction to fail.
In the vulnerable flow identified by the researchers, the terminal-facing expiration information was not effectively bound to the card data in a way that prevented manipulation during the tested transaction scenario.
This created an opportunity to alter the expiration date seen by the terminal.
The card itself had expired.
The payment terminal, however, could potentially be shown information suggesting otherwise.
By comparison, the tested Mastercard, American Express, and Discover implementations included consistency checks or authenticated-data protections that caused the altered information to be detected.
The result was a declined transaction rather than an approved purchase.
That distinction demonstrates why integrity protection matters.
Encryption protects secrets.
Authentication proves origin.
Integrity protection helps ensure that important information has not been silently changed.
A payment system can use strong cryptography and still face problems if critical transaction fields are not consistently authenticated across every stage of the payment process.
Why an Expired Card Could Become a Security Risk
The most realistic abuse scenario does not involve a Hollywood-style hacker secretly stealing payment information from people walking through a shopping mall.
The more credible concern begins after a card has already been discarded, lost, replaced, or forgotten.
Imagine an expired card thrown into ordinary household waste.
Imagine a replacement card stored in an office disposal bin.
Imagine an old card sitting inside a drawer because its owner believes it can no longer be used.
Imagine a wallet being lost, with an expired card inside that the owner decides is not worth reporting.
Under the right conditions, an attacker who obtains that physical card could potentially attempt to manipulate the contactless transaction data and use the card through an appropriate relay setup.
The attack is not effortless.
It requires technical capability, access to the physical card, and a transaction environment where the other security layers fail to reject the credential.
But security incidents do not require a vulnerability to affect everyone.
Sometimes the most dangerous weaknesses are the ones that affect only a narrow set of victims while remaining difficult to notice.
The Difference Between Discarded Cards and Proximity Attacks
There is another theoretical attack scenario involving a card that is still in the owner’s possession.
An attacker could potentially attempt a proximity relay attack involving the card’s NFC communication.
However, this is a much more difficult scenario.
NFC operates over very short distances, and a relay attack generally requires the attacker to maintain the necessary communication path during the transaction.
That is very different from simply walking past someone and instantly stealing their credit card through their pocket.
The discarded-card scenario is therefore more practical.
A physical card that has been thrown away can be accessed repeatedly.
It can be examined.
It can be connected to specialized equipment.
It can potentially be tested multiple times.
The owner may not even realize that the supposedly expired card still deserves attention.
Why “Expired” Does Not Always Mean “Inert”
Consumers often think about expiration as a physical shutdown switch.
The date passes, and the card becomes useless.
Real payment systems are more complicated.
An expiration date is only one element within a much larger authorization ecosystem.
A transaction may involve card credentials, cryptographic values, account status, replacement status, issuer rules, transaction risk scoring, merchant configuration, terminal software, and network validation.
The strongest defense is therefore not simply asking whether the expiration date is valid.
The entire lifecycle of the card credential must be enforced consistently.
A card that has been replaced should be recognized as replaced.
A card that has been retired should be rejected as retired.
A card that has expired should not become valid merely because one transaction field can be manipulated before it reaches a particular system.
That responsibility belongs primarily to the payment ecosystem, not to consumers.
What Cardholders Should Do With Expired Cards
The practical advice is simple.
Do not treat an expired or replaced payment card as worthless.
Physically destroy it before disposal.
Cut through the EMV chip several times.
Make additional cuts through the body of the card to damage the contactless antenna.
Damage the magnetic stripe as well.
The goal is not to create one decorative cut through the middle.
The goal is to make the different technologies embedded in the card difficult or impossible to reuse.
A card can contain several components.
Destroying only one visible part may not necessarily disable every communication mechanism.
It is also sensible to dispose of the pieces separately when practical.
Why Lost Expired Cards Should Still Be Reported
An expired card that disappears should not automatically be ignored.
If the underlying account remains active or if the issuing bank still has some connection between the physical credential and the account, reporting the loss creates an additional opportunity for the issuer to investigate and deactivate the credential.
Consumers should not have to understand the internal details of payment protocols.
That is exactly why reporting a missing card remains a sensible security practice.
A card may be expired from the
The payment infrastructure may still need to formally recognize that the physical credential should never be accepted again.
The Bigger Responsibility Belongs to Payment Networks
Consumers can cut cards.
They can report losses.
They can avoid throwing sensitive financial materials directly into the trash.
But none of these actions should be considered the primary solution to a protocol weakness.
The larger responsibility belongs to payment networks, card issuers, terminal providers, and financial institutions.
Critical transaction data should be integrity-protected.
Terminal implementations should detect inconsistent information.
Issuers should validate the lifecycle state of a credential instead of relying on assumptions created by earlier stages of the transaction.
Payment security works best when multiple layers independently verify important information.
A discarded card should not become dangerous simply because one system believes another system has already performed the necessary validation.
The Security Lesson Goes Beyond Credit Cards
The Zombie Card research is also relevant outside the world of payments.
Modern security failures frequently appear when different components disagree about what information should be trusted.
One system signs data.
Another system modifies it.
A third system validates only part of it.
A fourth system assumes the previous component already performed a security check.
That pattern appears in APIs, authentication systems, cloud environments, identity infrastructure, supply chains, and payment technologies.
The lesson is simple.
Security boundaries must be explicit.
Important information must remain protected throughout its journey.
And systems should never blindly trust values simply because another component presented them.
What Undercode Say:
A Small Payment Field Can Create a Large Security Question
The Zombie Card research is interesting because it challenges a basic assumption about payment security.
Most people believe an expired card automatically becomes technologically useless.
The research shows that expiration is not simply a physical property of the plastic card.
It is a state enforced by software, protocols, networks, and financial institutions.
If those layers disagree, unexpected behavior can emerge.
The Real Problem Is Trust Between Systems
The most important security question is not whether an attacker can change a date.
Attackers change data constantly.
The critical question is whether the receiving system can determine that the data was changed.
When transaction information travels across multiple systems, every important security property must have a clear chain of trust.
If the expiration date influences authorization, its authenticity and consistency should be verifiable.
Otherwise, a manipulated value can become a trusted value.
Defense in Depth Should Stop the Attack
Even if a terminal receives manipulated information, other layers should still have the ability to reject a retired credential.
The issuing bank should understand the
The payment network should enforce protocol consistency.
The terminal should reject contradictory data.
The authorization system should not approve a card simply because one field appears valid.
Security should fail closed, not fail open.
Discarded Technology Is Still Technology
Organizations often focus on protecting active systems.
Old credentials are forgotten.
Retired devices are placed into storage.
Expired cards are thrown away.
Former employee accounts remain in databases.
Deprecated API keys continue to exist.
The same principle applies everywhere.
Retirement must be an active security process.
A credential is not necessarily safe just because its owner stopped using it.
Physical Disposal Remains Part of Cybersecurity
Cybersecurity is often imagined as a purely digital problem.
This research proves that the physical world still matters.
A discarded card can become the starting point of a technical attack.
A stolen device can expose credentials.
An improperly destroyed storage drive can reveal sensitive information.
The boundary between physical security and cybersecurity continues to disappear.
Organizations should treat disposal procedures as part of their security architecture.
The Attack Surface Includes Forgotten Assets
Security teams should ask a difficult question.
What happens to an asset after everyone believes it no longer matters?
That question can reveal overlooked attack surfaces.
Old cards.
Inactive tokens.
Deprecated certificates.
Replaced hardware.
Archived databases.
Former authentication methods.
Forgotten technology is often attractive to attackers because it receives less attention.
Payment Security Must Assume Adversarial Conditions
A payment protocol should not assume that every field reaching a terminal is honest.
It should assume that attackers may attempt to alter, replay, relay, intercept, or substitute data.
The design must survive hostile conditions.
That is the difference between functionality and security.
A system can work perfectly during normal transactions while still failing under deliberate manipulation.
Security testing must therefore examine abnormal behavior.
Consumers Should Not Carry the Entire Burden
Cutting up an expired card is good advice.
But consumers should not become the final security control protecting a global payment network.
If a discarded card remains usable under certain conditions, the ecosystem must examine why.
Secure design should reduce the consequences of ordinary human behavior.
People will forget cards.
People will throw things away.
People will assume expired credentials are inactive.
Technology should be designed with those realities in mind.
The Zombie Card Is a Reminder About Security Assumptions
Every security architecture contains assumptions.
This card is expired.
This field is authentic.
This system already checked the data.
This credential is retired.
This device cannot be reused.
Attackers often succeed when one of those assumptions is wrong.
The best security programs continuously challenge those assumptions before criminals do.
Deep Analysis: Testing Card Lifecycle Controls
Command: Identify Connected Smart Card Readers
On Linux systems, administrators and researchers can inspect available smart-card hardware using:
pcsc_scan
This can help identify whether a compatible reader is available and whether a card can communicate with the local smart-card subsystem.
Command: Inspect USB Devices
Researchers can list connected USB hardware with:
lsusb
This is useful for identifying connected smart-card readers, NFC devices, or other testing hardware.
Command: Monitor System Messages
When connecting hardware for legitimate security testing, Linux system events can be monitored with:
dmesg -w
This can help determine whether the operating system correctly recognizes a connected device.
Command: Review NFC Hardware Availability
Systems with supported NFC hardware can inspect devices and interfaces with:
ip link
Administrators should ensure that NFC and contactless hardware is only used in authorized testing environments.
Command: Check Smart Card Services
The PC/SC service can be inspected with:
systemctl status pcscd
If a legitimate laboratory environment requires smart-card testing, administrators can verify that the service is running correctly.
Command: Review Security Logs
Relevant authentication and system activity can be reviewed using:
journalctl -xe
Monitoring logs is an important part of identifying unexpected hardware behavior or unauthorized testing activity.
Defensive Analysis
Security researchers and payment organizations should test whether card lifecycle information remains consistent across every stage of a transaction.
They should validate that expiration information cannot be silently substituted.
They should test whether replaced or retired cards are rejected even when individual transaction fields appear valid.
They should also examine whether terminals, networks, and issuers disagree about the status of a credential.
The objective should be simple.
A retired credential must remain retired across the entire ecosystem.
✅ The research described a scenario in which manipulated expiration information allowed certain tested expired Visa contactless cards to complete real purchases under specific conditions.
✅ The tested Mastercard, American Express, and Discover configurations rejected the altered expiration information, showing that the behavior was not universal across payment networks.
❌ It would be inaccurate to claim that every expired credit card can be revived or that an attacker can simply scan a person’s card from a distance and immediately spend money without additional technical requirements.
Prediction
(+1)
Payment networks and card issuers will continue strengthening integrity checks around contactless transaction data and retired card credentials.
Financial institutions may increasingly validate the complete lifecycle state of a card instead of relying heavily on individual transaction fields.
Security researchers will likely investigate whether similar trust-boundary weaknesses exist in other contactless payment implementations.
Attackers will continue targeting discarded, forgotten, and supposedly inactive credentials because abandoned assets often receive less security attention than active systems.
Final Thought: Destroy the Card, but Fix the System
The Zombie Card research delivers a simple but important message.
An expired card should not automatically be considered harmless.
Destroying old payment cards remains a sensible precaution, especially when they are being replaced or discarded. Cut through the chip, disrupt the contactless components, damage the magnetic stripe, and treat the card as sensitive financial hardware until it is properly destroyed.
But the deeper lesson belongs to the payment industry.
Consumers can destroy plastic.
Payment networks must destroy trust in retired credentials.
Because in cybersecurity, something that is supposed to be dead should stay dead.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.malwarebytes.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




