遇见数据集

Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments

收藏
Zenodo2026-05-29 更新2026-06-05 收录
官方服务:

资源简介:

Contactless payment cards are widely assumed to stop working past their printed expiration dates, and many stakeholders rely on this assumption for authorization and access control. This paper shows that banks enforce the expiration as a transaction policy check, rather than an intrinsic property of the card, which allows an expired card to still initiate contactless payments. We demonstrate a practical \enquote{Zombie Card} attack that makes an expired card appear unexpired, allowing successful transactions despite the card being past its printed date. We evaluate the attack across real-world transaction configurations spanning multiple EMV kernels (Visa, Mastercard, and Discover), POS terminals, merchants, and five (5) major US banks. Our results show that Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection. We further find that banks often rely on the POS terminal’s decisions and skip critical security checks during transaction authorization for faster payments. Across our trials, the attack remains operational under typical in-store conditions using commodity NFC transceivers and does not require specialized hardware. Together, these findings indicate that the outcome of a “zombie card” transaction is determined by how security responsibility is divided between terminals, card manufacturers, and issuers, and by how consistently issuers enforce card lifecycle state. Based on these findings, we propose countermeasures that span kernels, issuers, and payments to ensure end-to-end transaction integrity and security.

提供机构:
Zenodo
创建时间:
2026-05-29
二维码
社区交流群
二维码
科研交流群
商业服务