Close-up of a Visa card showing the embedded NFC antenna, illustrating how the chip can be reprogrammed after expiration

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Expired Visa cards can be repurposed after their nominal validity ends, allowing fraudsters to execute contactless payments as if the card were still active. The practice, dubbed “zombification,” threatens the assumption that an expired card is automatically inert. Readers who rely on contactless transactions must understand the mechanics before they become victims.

How Card “Zombification” Operates

The NFC (near‑field communication) chip embedded in a Visa card retains power after the magnetic stripe expires, enabling it to broadcast payment data when tapped. Attackers harvest this residual functionality, rewrite the chip’s cryptographic token, and inject a fresh transaction credential that mimics a legitimate, unexpired card. Reprogramming the chip bypasses the issuer’s expiration check because the contactless interface validates only the token, not the printed date.

Tools that can rewrite NFC chips are widely available, ranging from inexpensive hobbyist programmers to commercial devices used in legitimate testing. When paired with publicly disclosed vulnerabilities in Visa’s token generation, these tools give a low‑skill adversary a reliable path to create a functional “zombie” card. The resulting device can be used in any terminal that accepts contactless payments, effectively erasing the expiration barrier.

Why Expired Cards Remain Vulnerable

Card issuers often deactivate the magnetic stripe and online account after the printed expiration date, yet the NFC chip’s firmware is rarely updated or disabled. This asymmetry stems from legacy design choices that prioritize backward compatibility over post‑expiry security. Consequently, the chip continues to respond to NFC queries even when the card should be considered dead.

Consumers typically discard expired cards without physically destroying the chip, leaving the hardware intact for potential reuse. Because the chip’s cryptographic keys are stored in a non‑volatile memory that survives the card’s lifespan, a recovered card provides a ready‑made platform for attackers. The combination of unchanged firmware and retained keys creates a predictable attack surface.

Contextual Threat Landscape

The emergence of card zombification coincides with a broader surge in cyber‑related warnings, such as Apple’s unprecedented number of spyware alerts reported in the same news cycle. This pattern indicates that threat actors are diversifying tactics across both software and hardware domains, exploiting any lingering trust assumptions.

Simultaneously, geopolitical cyber operations—exemplified by Ukraine’s cyber and drone strikes against a Russian e‑commerce giant—demonstrate that state‑aligned actors are willing to target commercial payment infrastructure. While the Visa card case is primarily criminal, the overlap of techniques underscores a shared toolbox that blurs the line between organized crime and nation‑state activity.

What This Actually Means For You

  1. Expiration dates no longer guarantee a card’s inertness; the NFC chip can remain active indefinitely.
  2. Physical disposal of expired cards must include chip destruction to eliminate the hardware foothold.
  3. Contactless payment terminals cannot differentiate between a freshly issued token and a zombified one without additional verification layers.
  4. Broader industry signals—Apple’s spyware warnings and cyber‑physical attacks—suggest that similar hardware‑based exploits may appear in other consumer devices.
  5. Relying solely on issuer notifications about card deactivation is insufficient; personal vigilance is required.

Immediate Action Steps

When a Visa card expires, cut it into multiple pieces, ensuring the NFC antenna is broken; this physically disables the chip. Follow the issuer’s guidance for secure disposal, often involving a designated drop box that shreds cards.

Monitor your account for unauthorized contactless transactions, especially within weeks of a card’s expiration. If you notice any activity, report it immediately and request a replacement that includes enhanced tokenization safeguards.

Frequently Asked Questions

Can an expired Visa card be used for contactless payments?

Yes. The source reports that an expired Visa card can be “zombified,” meaning its NFC chip can be reprogrammed to make contactless payments despite the printed expiration date.

What does “card zombification” mean?

It refers to the process of rewriting the NFC chip’s cryptographic token on an expired card so it behaves like a valid, active card, allowing fraudsters to complete transactions.

How can I protect my card from being zombified?

Destroy the NFC chip by cutting the card after it expires and stay vigilant for unexpected contactless charges, reporting any anomalies to your issuer promptly.

What Do You Think?

Given that an expired card’s chip can be weaponized, should payment networks redesign NFC chips to self‑disable after the expiration date?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.