TECH Signal 429
Visa contactless cards vulnerable to man-in-the-middle attack reviving expired cards for payments
Researchers from UMass Amherst demonstrated that Visa's contactless payment kernel does not cryptographically bind the expiration date, allowing an NFC proxy to alter the date a terminal sees while leaving the card's security checks intact.
The flaw means expired Visa contactless cards can be used for unauthorized purchases when the issuing bank does not fully validate the expiration date during online authorization. Mastercard, American Express, and Discover kernels resisted the same attack, making this a Visa-specific protocol gap rather than a general EMV weakness.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Visa's EMV kernel leaves the Application Expiration Date unsigned, so a man-in-the-middle can tamper with it without breaking the card's digital signature.
The attack uses mobile phones as NFC proxies between the expired card and the POS terminal, and its success depends on whether the issuing bank performs a full expiration check during online authorization.
Mastercard, American Express, and Discover contactless configurations all resisted the attack because their kernels bind the expiration date cryptographically.
THE CLUSTER