September 2, 2026
By esentry Team

Your Expired Visa Card may not be dead yet: The “Zombie Card” Attack Explained

You cut up an expired bank card, throw it away and move on. But what if that card could still make a payment?

Researchers from the University of Massachusetts Amherst have demonstrated a new attack that can make certain expired Visa contactless cards appear valid at payment terminals. They call it “Zombie Card” because the card should be dead but under the right conditions, it can be brought back to life.

The technique does not crack the card's encryption or steal a customer's PIN. Instead, it takes advantage of the way expiration information is handled during a contactless transaction. In testing, researchers successfully used expired Visa cards to make real purchases, including transactions at retail locations.

There is currently no evidence that this technique is being used by criminals in real-world attacks, and it is not a conventional malware campaign. It is a proof-of-concept security finding that exposes a weakness in how different parts of the payment system handle card expiration.

What makes an Expired Card “come back to life”?

Normally, an expired card should be rejected when its expiration date has passed. The researchers found that, for affected Visa contactless transactions, the expiration date read by the payment terminal can be modified while the card is communicating with the terminal. The attack uses a Man-in-the-Middle (MitM) technique.

What does the attack actually require?

An attacker would generally need:

  • Physical possession of the expired card or sustained near-field communication (NFC) proximity to it.
  • Equipment capable of relaying the card's contactless communication.
  • A payment terminal that handles the transaction in a vulnerable way.
  • An account that remains active under the same Primary Account Number (PAN) after the card is replaced.
  • A bank that does not independently re-check the card's expiration during authorization.

Note: NFC (Near Field Communication) is a short-range wireless technology that allows devices to exchange data or make contactless payments by simply tapping or bringing them close together.

How serious is it?

The research is significant, but it should not be presented as a universal vulnerability affecting every Visa card. Multiple payment configurations and banks were tested, and the results were not identical across all of them. Some transactions were rejected, while one tested bank accepted the modified transactions.  

Is there a CVE?

As of the latest reporting, no CVE or public vendor mitigation has been issued specifically for the finding.

Who is actually at risk?

For ordinary cardholders, the risk currently appears limited but worth taking seriously. The attack requires physical access to the card and additional equipment, and there are several conditions that must line up for the transaction to succeed.

There is also currently no evidence that criminals are using the technique in active fraud campaigns. However, the research exposes an important security assumption that an expired card is not necessarily the same thing as a completely disabled account.

Recommendations

  1. Destroy expired cards properly: Do not simply throw an expired card intact into the bin. Cut through the chip and magnetic stripe and make sure the card number cannot easily be reconstructed.
  1. Don't give away old cards: If a bank replaces your card, keep the old card under your control until it has been properly destroyed.
  1. Monitor your account: Turn on transaction notifications and regularly check your bank statements. Report transactions you do not recognize immediately.
  1. Ask your bank about replaced cards: If you are concerned about an old card that has been lost or discarded, contact your bank and ask whether the old card has been fully deactivated.
  1. Don't panic: The Zombie Card attack is currently a research demonstration, not evidence of widespread criminal exploitation.
  1. Banks and payment networks should consider additional checks to ensure that an expired or replaced card cannot be used simply because the underlying account remains active.
  1. Payment providers should also review whether replaced cards are being treated as fully inactive across all transaction channels.

Conclusion

The Zombie Card research does not mean your old Visa cards are secretly waiting to drain your bank account, but it does challenge a common assumption: Expired does not always mean completely unusable. A card that has expired may no longer have a place in your wallet but that doesn't mean it should be left intact.

Follow esentry for emerging cyber threats, financial security research and practical security advisories that turn complex vulnerabilities into information people can actually use.