Researchers at UMass Amherst have found a way to bring expired credit cards back to life at checkout, effectively bypassing standard security expiration checks.
The findings, presented this month at the USENIX Security 2026 conference, rely on using two smartphones running relay software, an app that creates a long-distance digital bridge between two points. One smartphone is placed near the expired card, while the other faces the store’s payment terminal. By intercepting and manipulating the data exchange between them, the card’s expiration date gets swapped for the one that the payment terminal accepts as current.
The reason this exploit works comes down to something most people never think about: credit card accounts remain active long after their physical expiration dates. A fact proven by the way refunds continue to process on expired cards.
This banking feature discrepancy is what got project lead Taqi Raza, an assistant professor in the university’s Riccio College of Engineering, thinking, “If the card can get a refund,” Raza wondered, “can the card make a payment?”
The answer, the researchers found, depends on the bank. Some issuers strictly check expiration data for every transaction, while most others don’t go that extra mile.
The study highlights that the vulnerability specifically impacts Visa contactless (Kernel 3) implementations, where expiration data is not cryptographically bound to the transaction, while other major networks, such as Mastercard, American Express, and Discover, were found to be resistant.
This inconsistency creates a security gap that a relay attack can exploit, potentially allowing a card sitting forgotten in a drawer, or one already reported lost, to still authorize a charge if it happens to land on the wrong network.
This lingering vulnerability changes the rules for how consumers should dispose of old cards. Cutting up an old card and tossing it in the trash feels final, but the chip inside can keep live account data long after the plastic stops working the normal way. Destroying the card properly means destroying the chip too, not just the plastic around it.
However, relying on consumer diligence is hardly a fix. Banks hold the harder end of the problem, which means working to tighten expiration checks across aging systems that have run largely unchanged for years, on a payment network no single bank controls alone.
Sources: USENIX, Security Affairs, EurekaAlert, Cybernews
