WTF?! Credit cards aren't meant to last forever, but a team of researchers just found a way to keep expired ones alive for a little longer than intended, and not for the cardholder's benefit. Not every card is affected, but the flaw sits deep enough in how contactless payments are verified that exploitation isn't just theoretical.
Being unable to use a credit card to pay for your groceries is annoying enough. It's worse when a "zombie" card claws its way back to life and bites you in the bank account. According to researchers at the University of Massachusetts Amherst, there's a way to abuse an already-expired card to make unauthorized purchases.
The UMass Amherst team first presented the work at the USENIX Security 2026 conference. In the paper, assistant professor Taqi Raza and his co-authors show that "dead" credit cards past their expiration date can still be pushed through vulnerable point-of-sale (POS) terminals to complete fraudulent purchases.
Raza's team found that when a credit card expires, the underlying account doesn't – even after the cardholder has already received a replacement card. That gap led the researchers to test whether an expired card could still be coaxed into approving a transaction. The answer: yes, using a "zombie card" setup built from two off-the-shelf smartphones and some basic emulation software to fool the card reader.
The trick uses the first phone to activate the expired card over NFC, the same short-range wireless tech behind tap-to-pay. The card is prompted to transmit its data, including its expiration date. A second phone then acts as a man-in-the-middle, relaying that data over Wi-Fi while rewriting the expiration date before it reaches the POS terminal – which, in the cards affected, accepts the doctored date and clears the transaction.
The root cause, per the researchers, is that a card's expiration date effectively exists in two places: the Application Expiration Date the POS terminal reads locally, and a separate expiration field the card issuer checks later during online authorization.
In Visa's contactless implementation, the two aren't cryptographically bound together, so intercepting and altering the first one doesn't get caught by the checks meant to protect the second. Mastercard, American Express, and Discover configurations resisted the attack in testing; Visa's didn't.
Raza noted that a digital payment system involves several independent actors – the card chip, the POS terminal, payment networks like Visa or Mastercard, and the issuing bank – and that gaps between how each of them enforces security checks are exactly where this kind of exploit lives.
"The attack exploits a documented misconception – expired cards are widely assumed inert, so cardholders discard them carelessly," Raza said.
Concerned users should always dispose of expired cards properly. The recommended method: demagnetize the magnetic strip, destroy the embedded chip with scissors, then shred the whole card. Even in pieces, the remains should go into separate trash cans.