Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography.

The attack, which the researchers named "Zombie Card," requires physical possession of the expired card or sustained NFC proximity to it, plus a man-in-the-middle (MitM) relay positioned between the card and the terminal.

It also requires that the account remain open under the same primary account number (PAN), which is standard practice when an issuer sends a replacement card, and that the issuing bank not independently re-check the expiry during authorization.

The paper's abstract describes an evaluation spanning five major US banks; the experiments with expired and replaced physical cards cover three of them, and of those three, one approved the revived transactions, one declined every attempt, and the third was running a different Europay, Mastercard, and Visa (EMV) kernel on which the modification failed outright.

The work was presented at the 35th USENIX Security Symposium in Baltimore from August 12 to 14, 2026. Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza disclosed the findings to Visa and the affected banks in May 2025 and made contact again in December 2025. No CVE has been assigned and no exploitation of the technique has been reported.