Vulnerability Allows Thieves to Bring ‘Zombie’ Cards Back to Life, Researchers Report

AMHERST, Mass. — Some expired credit cards may not be as dead as financial institutions and consumers think.

Researchers at the University of Massachusetts Amherst have identified a security vulnerability that can allow thieves to make purchases with certain expired credit cards by manipulating expiration-date information during a transaction, according to the university.

The researchers dubbed the affected cards “zombie credit cards” because they can effectively be brought back to life after expiration. The findings were presented at the USENIX Security 2026 conference.

“They can still use the victim’s expired credit card, despite the victim receiving another card,” Taqi Raza, an assistant professor in UMass Amherst’s Riccio College of Engineering, said in a statement.

The vulnerability stems partly from the distinction between a physical credit card and the underlying account. A card can expire while its account remains active, allowing transactions such as refunds to continue being processed.

How it Works

According to the university, that led Raza and his research team to investigate whether an expired card could also still make a payment.

For some cards, they found it could.

Using two commercially available smartphones and basic emulator software, researchers demonstrated that they could make a point-of-sale terminal believe an expired card was still active, UMass Amherst said.

The technique uses near-field communication, or NFC, the same technology behind contactless tap-to-pay transactions. One smartphone communicates with the expired card to obtain payment information, including its expired date.

A second smartphone receives the information through a Wi-Fi-based relay and changes the expiration date before communicating with the payment terminal.

‘We Can Easily Fool It’

Raja Hasnain Anwar, the study’s lead author and a doctoral candidate with UMass Amherst’s Khwarizmi Lab, said an attacker does not need to know the expiration date of the replacement card. Any future expiration date can potentially be substituted.

“The expiration date printed and stored on the card is the only way for the POS to know whether the card is active or expired,” Anwar said. “Yet it is not cryptographically protected. So, we can easily modify it to fool the POS.”

To someone watching the transaction, tapping the second smartphone on the payment terminal would appear similar to making a purchase with a conventional digital wallet, according to the university.

Researchers said consumers might expect the issuing bank to recognize that the card has expired and reject the transaction. However, not every bank verifies the expiration date read by the payment terminal against authenticated card data. If other safeguards do not independently verify the card’s lifecycle status, the transaction could be approved.

A Second Expiration Date

Payment cards also contain another expiration date associated with the digital certificate for the security key used to encrypt communications among the card, payment terminal and bank, the researcher noted. 

They found that the certificate can remain valid longer than the expiration date printed on the card.

“What we found is that the expiry date for the digital certificate for the security key is longer than the expiry date of return on the card,” Raza said.

That means the certificate does not necessarily provide an effective check on whether the physical card has expired, according to the university.

Researchers demonstrated the vulnerability both in laboratory testing and during transactions at local dining facilities and grocery stores, UMass Amherst said. Not all credit cards were equally susceptible.

Digital Wallets More Resilient, But…

Digital wallets also contained additional security protections that made them more resistant to this particular attack, although researchers said digital wallets can have other vulnerabilities.

The researchers attributed the broader problem to the increasingly distributed nature of payment systems, in which security decisions are divided among card chips, point-of-sale terminals, payment networks and financial institutions. Differences in the information available to those systems can create security gaps.

“With the rise of AI, it is becoming increasingly easy for attackers to spot these discrepancies and devise exploits, effectively putting millions of credit cards at risk,” Anwar said.

Major Card Companies Notified

UMass Amherst said major card companies have been notified about the researchers’ findings.

Raza urged consumers not to assume an expired or canceled card is harmless and recommended securely destroying old cards and continuing to monitor closed accounts for unauthorized transactions.

“The attack exploits a documented misconception — expired cards are widely assumed inert, so cardholders discard them carelessly,” Raza said. “Always discard your expired card, no matter what. Even if you permanently close your credit card, still monitor the transaction on the closed account.”

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.