Expired Visa Contactless Cards Can Be Revived Using an NFC Relay
Researchers showed that a gap in Visa's Kernel 3 lets a two-phone relay change the expiry a terminal sees which enabled real in-store purchases and no public fix has been confirmed.
Overview
- University of Massachusetts Amherst researchers built a two‑phone NFC relay that alters the terminal-facing expiration field and completed live retail and grocery purchases during a USENIX Security 2026 presentation.
- The flaw stems from Visa Kernel 3 not cryptographically binding the terminal-facing Application Expiration Date (tag 5F24) to the signed card data so the terminal can be fed a future expiry without breaking the card signature.
- Mastercard, American Express, and Discover kernels blocked the tampering in tests because they either check expiry consistency or include expiry in authenticated hashes while Visa’s tested flow did not.
- Success also depends on issuing banks because some issuers accepted the altered transactions and in tests one bank even allowed charges from an expired card and its replacement at the same time.
- Researchers and reporters recommend layered fixes at the kernel, terminal, and issuer levels and advise consumers to physically destroy expired or replacement contactless cards and report them lost to reduce theft risk.