During that exchange, the relay altered the expiration date supplied to the terminal. A past date could be replaced with a future date, so the terminal’s local checks treated the card as current. The reported demonstration required possession of the physical card, or continued NFC proximity to it, as well as the relay positioned between the card and the terminal.
The important distinction is that the relay did not need to counterfeit the card’s secret keys. The genuine card continued to produce the signed and dynamic transaction material expected by the EMV process. The weakness was the ability to change one decision-relevant field—the expiration date—without invalidating the other authenticated data.
The reported problem involved inconsistent treatment of the expiration date in Visa’s EMV contactless Kernel 3 implementation. In the tested setup, the date presented to the payment terminal was not sufficiently cryptographically bound to the card data and transaction information later used for authorization.
That created a mismatch:
In other words, the attack targeted the relationship between fields, not the cryptography itself. A signature or transaction cryptogram can remain genuine while a separate value used by the terminal is manipulated if the protocol does not bind those values together tightly enough. The researchers’ findings describe this as a man-in-the-middle tampering weakness in the Visa contactless transaction flow.
Card expiration is often treated as though it were an intrinsic cryptographic shutdown. The available research summary indicates that this is not always how contactless payment systems enforce it. Some checks may depend on what the terminal receives and what the issuer can independently verify during authorization.
If the terminal sees a future expiration date and the issuer receives otherwise authentic transaction evidence, the system may lack a dependable, consistently authenticated signal that the physical card has expired. The account must also remain usable for an authorization to succeed; the attack does not turn a closed account or invalid account into an active one.
The supplied reports say that the same expiration-date substitution did not succeed in the tested Mastercard Kernel 2, American Express Kernel 4, and Discover Kernel 6 configurations.
However, the available evidence does not provide a full kernel-by-kernel protocol analysis explaining exactly which field bindings or validation steps caused those transactions to fail. The cautious conclusion is that the tested implementations rejected this particular manipulation more effectively than the tested Visa configuration—not that every card issued under those brands is immune to relay attacks or other payment fraud.
The research was reported as involving cards from multiple major U.S. banks, and coverage describes successful or attempted transactions across multiple issuers.
The available source material does not identify all five banks or provide a verified approval-and-decline result for each one. It would therefore be misleading to publish a bank-by-bank table or claim that one issuer universally accepted or rejected the attack. Results can depend on the card product, account status, authorization controls, terminal, acquirer, and transaction conditions.
One supplied report says the researchers disclosed the findings to Visa and affected banks in May and December 2025, including reproduction material, transaction records, and a demonstration video.
The available sources do not include a verifiable Visa statement, a confirmed security advisory, or evidence of a completed remediation rollout. That means there is not enough evidence to say that Visa has fully fixed the issue, which cards or terminals are covered, or whether any mitigation is mandatory across the payment ecosystem.
The central fix is to prevent the terminal-facing expiration date from diverging from the authenticated card data.
Consumers should follow the issuer’s instructions first, especially if the issuer requests that the old card be returned. Otherwise, remove the card from saved merchant accounts and digital-wallet applications, confirm that the replacement is active, and destroy the old card so its payment details cannot be reconstructed easily.
Cut through the chip, magnetic stripe, printed card number, signature panel, and security code. A cross-cut shredder designed for payment cards is preferable to leaving the card intact. If practical, discard the pieces separately. These steps reduce exposure from discarded card data, but they do not replace account monitoring or reporting an unfamiliar transaction to the issuer.