The Zombie Card Loophole: How Visa’s Authentication Gaps Fuel Seamless Spend

AI-generated image · US National Wire
Researchers reveal that expired Visa cards can be 'zombified' for contactless payments, exposing a systemic failure in how issuers handle tokenized authentication.
In the payments industry, the expiration date on a piece of plastic is traditionally viewed as a hard stop—a security boundary that renders a card useless once its tenure ends. However, as Wired first reported, new research presented at the Usenix Cybersecurity Conference suggests that for many Visa users, that boundary is an illusion.
Reporting from Wired reveals a vulnerability where expired Visa cards can be 'zombified' to facilitate unauthorized contactless payments. The mechanism involves fraudsters using a man-in-the-middle application to relay data from a discarded or stolen expired card through a pair of smartphones. This setup allows a bad actor to proxy the card's data to a point-of-sale terminal, effectively reanimating a dead account to siphon funds.
From a market perspective, this isn't merely a technical glitch; it is a failure of the authentication chain. According to the researchers from the University of Massachusetts Amherst, the responsibility for verifying whether a transaction from an expired card should be disallowed is fragmented. While different card issuers implement cryptography in various ways, Wired reports that Visa possesses a specific flaw that allows out-of-date cards to pass its initial checks.
Crucially, Visa has essentially offloaded the final authentication task to the cardholder's issuing bank. This creates a fragmented security landscape where some banks successfully block these 'zombified' transactions while others do not. The result is a system that prioritizes the seamless flow of transaction data over rigid security protocols. By failing to enforce a universal kill-switch at the network level, the infrastructure allows expired credentials to remain viable keys to a consumer's bank account.
This vulnerability is particularly potent at automated point-of-sale terminals. Because these kiosks lack human oversight to question a phone-based proxy setup, the friction for the fraudster is nearly zero.
When asked for comment by the tech news outlet the Register, which also reported on the research, Visa did not respond. For the consumer, the takeaway is clear: the digital tokenization that makes modern payments seamless also means that physical destruction—via a pair of scissors—is the only guaranteed way to ensure an expired card stays dead.

