Tech and AI
Researchers revive expired contactless cards and get payments out of them, because the printed expiry date is not cryptographically protected
By Staff Writer | 20 August 2026

A team at the University of Massachusetts Amherst has shown that an expired contactless card can be made to look active to a shop terminal, using two ordinary smartphones as a relay. The account behind an expired card does not close when the plastic does, and in the configuration the team tested the date the terminal reads is not covered by the card's own signature.
The question that started it is the sort a practitioner asks about any expiry provision. If an expired card can still receive a refund, and it can, then what exactly is the expiry date doing? Taqi Raza, assistant professor in the Riccio College of Engineering at the university, put it as a straight test: if the card can get a refund, can the card make a payment. For one of the four card configurations tested, the answer was yes.
How the relay works
Two off-the-shelf smartphones and ordinary emulator software are enough. The first phone is held against the expired card and asks it for a transaction, which makes the card hand over the cardholder data, the payment application and the expiry date printed on it. A second phone, linked to the first over a wireless connection, takes that data, rewrites the expiry date to any date in the future, and is then tapped against the shop terminal. To anyone watching, it looks like somebody paying with a phone wallet.
The attacker never needs to know the expiry date of the replacement card. Any future date is enough, because the terminal is being told the date rather than checking it against anything the card has signed.
The expiration date printed and stored on the card is the only way for the POS to know whether the card is active or expired. Yet it is not cryptographically protected. So we can easily modify it to fool the POS.
Raja Hasnain Anwar, doctoral candidate and lead author, University of Massachusetts Amherst
Where the second check should have caught it
There is a second expiry date in the system, embedded in the digital certificate that carries the security key the card uses to talk to the terminal. That certificate is checked first, so in principle it ought to catch a dead card. The team found that it does not, because it outlives the card. In Raza's words, what they found is that the expiration date for the digital certificate for the security key is longer than the expiration date of return on the card, which makes it an ineffective check of whether the card is actually alive.
That leaves the issuing bank as the last line, and the bank does not always look. Where the bank verifies the date the terminal read against authenticated data, the transaction is refused. Where it relies on the terminal's own view, the charge goes through. Some of the banks in the test set refused and some did not. Only the Visa configuration tested gave way; the other three schemes in the test set resisted the same attack. Digital wallets carried extra protections that made them harder to fool by this route, although the same group has found other weaknesses in wallets.
The work was not confined to a bench. The researchers say they reproduced it in ordinary use at dining facilities and grocery stores as well as in the laboratory, across a range of terminals. They say they told the affected scheme in May 2025 and followed up in December 2025, and that neither the scheme nor the banks they contacted have confirmed a fix.
Why it is getting easier to find things like this
The root of it is that a modern payment is decided by four parties who each hold part of the picture: the chip in the card, the terminal, the payment network and the bank. Nobody holds all of it, and the seams between them are where a discrepancy sits. Anwar's point about how quickly those seams are now being found is the one worth carrying away, and it applies well beyond payments: with the rise of AI, he says, it is becoming increasingly easy for attackers to spot these discrepancies and devise exploits, putting millions of cards at risk.
The advice from the team is unglamorous and it is the sort that gets ignored. An expired card is not inert. Demagnetise the strip, destroy the chip, cut through the raised numbers, and split the pieces between different bins.
Always discard your expired card, no matter what. Even if you permanently close your credit card, still monitor transactions on the closed account.
Taqi Raza, assistant professor, Riccio College of Engineering, University of Massachusetts Amherst