Affected Systems

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies. Mastercard Kernel 2, American Express Kernel 4, and Discover Kernel 6 are not vulnerable due to cryptographic binding or consistency checks.

Exploitation Status

Proof-of-concept demonstrated by University of Massachusetts Amherst researchers with real transactions ($1-$500) at retail and campus merchants. No active exploitation reported in the wild. Disclosed to Visa and affected banks May 2025 and December 2025. No CVE assigned. No vendor advisories or mitigations published as of August 20, 2026.

Business Impact

Attackers with physical access to expired Visa contactless cards can conduct fraudulent in-store purchases if the account remains open under the same PAN (standard for replacement cards) and the issuing bank does not independently verify expiration during authorization. Attack requires custom relay hardware (two NFC-enabled Android phones) positioned between card and terminal, adding 50-415ms latency per transaction—within EMV's 500ms limit. Relay Resistance Protocol (RRP), which would detect the added latency, is optional and was not implemented on any tested cards or terminals. Visa has not published mitigation guidance 15 months after initial disclosure.

Urgency

🟡 Within a week

Recommended Actions

  • Audit contactless payment terminals to confirm Relay Resistance Protocol (RRP) is enabled if supported by hardware; prioritize deployment of RRP-capable terminals.
  • If issuing Visa contactless cards, implement server-side expiration date validation during authorization rather than relying solely on terminal checks; verify Tag 5F24 matches Track 2 Equivalent Data (tag 57) expiration.
  • Monitor transaction logs for expired card attempts, multiple active cards under one PAN, or anomalous Consumer Device Cardholder Verification Method (CDCVM) flag modifications.
  • Educate cardholders to destroy expired contactless cards immediately upon receiving replacements, emphasizing physical destruction of the chip.
  • Contact Visa and your payment processor for updated Kernel 3 guidance; escalate if no response within 7 days given 15-month disclosure window.

---

# Geopolitical Context

Geopolitical Context

The discovery of the "Zombie Card" vulnerability by University of Massachusetts Amherst researchers highlights systemic weaknesses in the global contactless payment infrastructure that underpins modern commerce. Visa's Kernel 3 implementation—deployed across millions of point-of-sale terminals in the United States and internationally—permits manipulation of expiration date fields without invalidating cryptographic signatures, a design flaw that reflects the tension between transaction speed requirements and security validation. The vulnerability affects the financial services backbone that facilitates cross-border commerce and consumer confidence in digital payments, sectors increasingly central to economic statecraft and sanctions enforcement. The absence of a CVE assignment or public mitigation guidance from Visa, EMVCo, or affected terminal vendors more than fifteen months after initial disclosure in May 2025 suggests either protracted remediation complexity or institutional reluctance to acknowledge specification-level weaknesses in widely deployed EMV standards. This gap may create asymmetric risk for jurisdictions and institutions that have invested heavily in contactless infrastructure as part of financial modernization initiatives.

State Actor Alignment

No state actor involvement is indicated in this research disclosure. The vulnerability was identified through academic research at a U.S. public university and disclosed through responsible channels to Visa and affected financial institutions. However, the technique's reliance on physical card access and NFC relay infrastructure positions it within the capability envelope of organized criminal networks rather than state-sponsored advanced persistent threat groups. The lack of coordinated vendor response may complicate regulatory oversight by financial authorities in the United States (Federal Reserve, OCC, CFPB) and internationally (ECB, PCI SSC), particularly if the flaw is exploited before patches are deployed. The vulnerability does not appear to intersect with sanctions evasion or state-directed financial crime at this time, though any widespread exploitation could erode trust in payment rails that underpin both licit commerce and sanctions enforcement mechanisms.

Business Impacty pro region

The vulnerability's impact extends beyond the United States to any jurisdiction where Visa Kernel 3 contactless payments are deployed, including the European Union, United Kingdom, Canada, Australia, and emerging markets that have adopted EMV contactless standards. European regulators under PSD2 and the Digital Operational Resilience Act (DORA) may face pressure to mandate disclosure and remediation timelines, particularly given the EU's stricter consumer protection and critical infrastructure frameworks. Retail and financial services sectors globally face reputational and fraud liability risks if the flaw is exploited at scale before terminal software updates are deployed. The research also underscores divergent security postures among payment networks: Mastercard, American Express, and Discover kernels demonstrated greater resilience to the same manipulation, potentially influencing merchant and issuer preferences in competitive markets. Developing economies that have leapfrogged to contactless payments without legacy magnetic stripe infrastructure may face disproportionate risk if terminal fleets lack firmware update mechanisms or if issuers do not perform server-side expiry validation.

Forecast

If Visa and terminal vendors do not issue coordinated patches and deployment guidance within the next quarter, organized fraud networks may reverse-engineer the published USENIX research and operationalize relay attacks against high-value merchants, particularly in jurisdictions with limited real-time fraud monitoring. If EMVCo declines to mandate cryptographic binding of expiration date fields in future kernel specifications, the vulnerability is likely to persist in legacy terminal deployments for years, creating a long-tail risk analogous to earlier EMV implementation gaps. Should exploitation incidents surface and attract media attention, regulatory bodies in the EU and U.S. may impose mandatory disclosure requirements or accelerate migration to relay-resistant protocols, increasing compliance costs for issuers and acquirers. If competing payment networks leverage this incident to promote their more robust kernel implementations, market share dynamics in the contactless payments sector may shift, particularly in enterprise and government procurement. Conversely, if no public exploitation occurs and the issue is quietly remediated through backend issuer controls, the incident may fade without structural reform to EMV standards governance.