Researchers Expose "Zombie Card" Flaw Allowing Unauthorized Contactless Payments on Expired Credit Cards
PUBLISHED Aug 20, 2026, 12:56 AM ET
Read, Watch or Listen
Researchers at the University of Massachusetts Amherst have uncovered a cybersecurity vulnerability allowing expired contactless credit cards to execute unauthorized transactions. Revealed at the USENIX Security conference, the "Zombie Card" attack exploits a validation gap where point-of-sale terminals fail to invalidate payment permissions on expired cards. Investigators demonstrated that using a basic smartphone relay system, an attacker can modify unencrypted expiration metadata during a tap-to-pay transaction. Although credit card accounts remain active for functions like billing refunds, the vulnerability bypasses standard bank rejections because some issuing institutions do not verify terminal-read dates against authenticated records. The research team notified major financial institutions and payment networks prior to public disclosure, prompting card issuers to review validation protocols. Experts advise consumers to securely destroy expired physical plastic rather than assuming discarded cards are completely inert.
By Emily Rhodes | JQJO News
Timeline of Events
- On Jan 15, 2024, Researchers began investigating card lifecycle management and expiration discrepancies.
- On Jun 10, 2025, Laboratory tests successfully bypassed point-of-sale terminal validation checks.
- On Aug 10, 2025, Academic teams notified major payment processors of the vulnerability.
- On Aug 17, 2026, University of Massachusetts Amherst publicly announced the security flaw.
- On Aug 18, 2026, Findings were formally presented at the USENIX Security conference.
- On Aug 20, 2026, Card issuers review validation protocols to prevent ongoing exploits.
- In coming months, Financial institutions will update terminal software across merchant networks.
- In late 2026, Payment processors plan tighter cryptographic binding for expiration dates.
- In 2027, Retailers expect broader deployment of enhanced point-of-sale validation rules.
- By 2028, Industry standards aim to eliminate underlying card lifecycle vulnerabilities.
News Intelligence
- Immediate US impact: Financial institutions are urgently reviewing point-of-sale terminal validation rules.
- Possible long-term US impact: Payment networks will implement stricter cryptographic checks for expiration dates.
- Most affected groups: Credit card holders, banking institutions, and point-of-sale terminal manufacturers.
- Reader Priorities: Securely destroy expired cards and monitor monthly account transaction statements.
- Articles Published:
- 31
- Right Leaning:
- 0
- Left Leaning:
- 0
- Neutral:
- 31
- Distribution:
- Left 0%, Center 100%, Right 0%
Left: Focuses on corporate accountability and necessary regulatory payment network fixes. Center: Reports technical findings neutrally while emphasizing consumer security best practices. Right: Emphasizes individual consumer responsibility to properly destroy old credit cards.
University of Massachusetts Amherst published security research on August 17, 2026. https://www.umass.edu/news/article/when-zombie-credit-cards-attack-umass-researchers-discover-loophole-can-reanimate
Coverage of Story:
From Left
No left-leaning sources found for this story.
From Center
Researchers Expose "Zombie Card" Flaw Allowing Unauthorized Contactless Payments on Expired Credit Cards
Help Net Security / USENIX Security Help Net Security HotHardware Khwarizmi Lab The CU Daily University of Massachusetts Amherst Pasquale Pillitteri Tech Blog TechXplore The Register SecurityWeek Bleeping Computer Dark Reading The Hacker News ZDNet CNET Forbes PCMag Ars Technica Wired Threatpost InfoSecurity Magazine SC Media CSO Online SiliconANGLE The Verge Engadget Gizmodo Mashable Digital Trends Tom's Guide VentureBeatFrom Right
No right-leaning sources found for this story.
Comments