
UMass Zombie Card attack rewrites Visa 5F24 expiry via NFC relay, bypassing fDDA without touching Track 2 cryptogram
Zombie Card exploits missing cryptographic binding of 5F24 in Visa Kernel 3, allowing expiry tampering on replaced cards across multiple banks. Evidence from UMass tests shows inconsistent issuer detection and no published mitigations. This reveals a systemic EMV design gap between terminal and issuer verification paths.
The attack requires physical card access or sustained proximity plus a relay positioned between card and terminal. Visa Kernel 3 omits 5F24 from fast Dynamic Data Authentication coverage and sets Terminal Verification Results to zeros, so banks receive no indication the terminal skipped its local expiry check. Track 2 Equivalent Data remains unmodified, preserving the issuer-side authorization path. Five banks showed divergent policies: Bank A accepted modified expiries and concurrent cards, Bank B rejected modified dates outright, and Bank D running Discover kernel still permitted multi-card use after detection.
Disclosure occurred in May and December 2025 with no CVE issued and no EMVCo or Visa specification bulletin published by August 2026. The pattern matches prior EMV contactless weaknesses where terminal-enforced checks lack cryptographic binding to issuer-verified data. Replacement cards retain the same PAN, extending the attack window until issuers implement independent expiry re-validation or bind 5F24 into signed data.
Operational significance lies in the low barrier for physical possession attacks at scale against high-value accounts. Terminal vendors and networks have not updated kernels, leaving contactless acceptance unchanged. Next steps include monitoring for issuer-side policy shifts in authorization logs and potential extension to other kernels lacking expiry binding.
Visa: No Kernel 3 update mandating 5F24 binding issued by Q3 2027
Sources (3)
- [1]Zombie Card: Reviving Expired Cards for Contactless Payments(https://www.usenix.org/conference/usenixsecurity26/presentation/anwar)
- [2]Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments(https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html)
- [3]EMV Contactless Specifications v2.10(https://www.emvco.com/specifications/)