Researchers at the University of Massachusetts Amherst have demonstrated a novel attack, dubbed “Zombie Card,” that can revive expired Visa contactless credit cards for in-store purchases. The attack exploits a design gap in Visa’s EMV contactless kernel (Kernel 3) by rewriting the expiration date that the point-of-sale (POS) terminal reads over NFC, without breaking the card’s cryptographic protections.
The attack requires physical possession of the expired card or sustained NFC proximity, plus a man-in-the-middle (MitM) relay between the card and terminal. It also requires that the account remains open under the same primary account number (PAN), which is standard when a replacement card is issued, and that the issuing bank does not independently re-check the expiry during authorization.
In tests across five major US banks, the attack succeeded against one bank, while another declined all attempts and a third used a different EMV kernel that blocked the modification. The researchers tested the attack against four EMV contactless kernels: Visa (Kernel 3) was vulnerable, while Mastercard (Kernel 2), American Express (Kernel 4), and Discover (Kernel 6) were not.
The findings were presented at the 35th USENIX Security Symposium in Baltimore (August 12-14, 2026). The researchers disclosed the vulnerability to Visa and affected banks in May 2025, but no CVE has been assigned and no public advisory or mitigation has been issued as of August 20, 2026. The paper recommends countermeasures such as cryptographically binding the expiration date, checking consistency between the two expiry representations, and preserving terminal validation signals for issuers.
This research coincides with Group-IB’s disclosure of WindRelay, a new Android NFC relay malware family used in live-call social engineering attacks in Europe, which employs a similar two-device relay technique.
Companies: Visa, Mastercard, American Express, Discover, EMVCo, SumUp, Group-IB, University of Massachusetts Amherst
Products: SumUp Solo, SumUp Plus
Events: 35th USENIX Security Symposium
Original source: thehackernews.com