Visa made a design error in Kernel 3, the proprietary software specification that dictates how payment terminals talk to contactless Visa cards. While the baseline EMV standard defines general chip transactions, each card network writes its own kernel to handle contactless taps (Mastercard uses Kernel 2, Visa uses Kernel 3). The Zombie Card attack proved how sloppy protocol architecture creates real fraud. Researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza showed that expired Visa cards can still buy goods in retail stores because Kernel 3 splits the expiration date across two fields, sending Tag 5F24 to the local terminal and Tag 57 to the issuing bank. Visa omitted Tag 5F24 from the fast Dynamic Data Authentication signature, leaving it unverified.
The researchers used two Android phones over Wi-Fi to sit between an expired card and a SumUp reader. When the terminal asked for card details, the phone proxy modified Tag 5F24, pushing the expiration date into the future. The terminal accepted the date because the signature verification skipped that field, and the issuing bank approved the charge because the untouched Track 2 data inside Tag 57 preserved the real cryptographic payload.
This flaw turns into theft because banks cut corners on account lifecycles. When a bank mails you a replacement card, it keeps your primary account number identical. The researchers tested Bank A, which approved modified transactions up to $500 on an expired card simply because the account was open, without checking if the presented expiration date matched the active card on file. If the bank ignores the presented expiry date during authorization, the dead card functions just like the new one.
Competitors solved this issue years ago. Mastercard rejects transactions where the two date fields disagree, American Express binds the expiration date into static offline authentication data, and Discover hashes the data fields together during dynamic verification. Visa leaves the door open, so shred the physical chip before throwing an old card in the trash.
Projects
- SANS SEC504 (aka GCIH)
- TryHackMe
Videos
Articles
- French tax authority data breach affects 678,000 individuals – The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.
- Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware – Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks.
- Beacon CRM Confirms Full Database Theft After AWS Access Key Breach – Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfiltrated its customer database.
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P – Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
- US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them – The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware – Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments – Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card’s cryptography.
- Hundreds of leaked AWS keys give full control over corporate accounts – More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

