How Extra Features In Contactless Payments Break Security, What We Can Do
Tom Chotia (University of Birmingham)
DEF CON 33 · Day 1 · Main Stage
Overview
In this DEF CON talk, Tom Chotia from the University of Birmingham dives deep into the often-overlooked security implications of "extra features" added to the otherwise robust EMV contactless payment protocols. While the core EMV specification is remarkably secure and well-designed, the relentless drive by payment providers and tech companies to introduce new functionalities – such as transit modes, loyalty schemes, and phone-based authentication bypasses – has inadvertently created a fertile ground for novel and severe security vulnerabilities. Chotia argues that these ad-hoc additions, often developed in isolation and without public scrutiny or rigorous interoperability testing, fundamentally undermine the security guarantees of contactless payments.

Key moments
- 0:00 Introduction: EU vs US payment rules
- 2:20 Understanding the basic EMV contactless payment protocol
- 4:50 How new features introduce security vulnerabilities
- 6:00 Visa's offline protocol and public key signing
- 7:00 Using formal models to uncover EMV protocol flaws
- 8:30 Face ID/fingerprint payments bypass transaction limits
How Extra Features In Contactless Payments Break Security, What We Can Do
Speakers: Tom Chotia (University of Birmingham)
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=_fGpR4Fqni0
Overview
In this DEF CON talk, Tom Chotia from the University of Birmingham dives deep into the often-overlooked security implications of "extra features" added to the otherwise robust EMV contactless payment protocols. While the core EMV specification is remarkably secure and well-designed, the relentless drive by payment providers and tech companies to introduce new functionalities – such as transit modes, loyalty schemes, and phone-based authentication bypasses – has inadvertently created a fertile ground for novel and severe security vulnerabilities. Chotia argues that these ad-hoc additions, often developed in isolation and without public scrutiny or rigorous interoperability testing, fundamentally undermine the security guarantees of contactless payments.
Chotia, along with his colleagues Andrea, George, Iona, and Anna, has spent years using formal verification models to systematically uncover these flaws. Their research highlights a critical disconnect between the theoretical security of the EMV standard and the practical insecurities introduced by proprietary extensions. The talk details specific, real-world attacks against Apple Pay (Visa) and Square's offline payment systems, demonstrating how attackers can bypass authentication and transaction limits, enabling fraudulent high-value purchases.
This presentation is crucial for anyone involved in payment systems, cybersecurity, or consumer protection. It exposes systemic weaknesses arising from fragmented development and lack of transparency in the payment industry. More importantly, Chotia presents a tangible, standards-based solution to mitigate a broad class of these attacks, underscoring the importance of collaborative, public standardization efforts over proprietary, opaque feature creep.
Background
▶ Watch: Introduction: EU vs US payment rules (0:00)
The foundation of modern contactless payments lies in the EMV (Europay, MasterCard, and Visa) specification, a global standard for credit and debit payment cards. Introduced in Europe significantly earlier than in the US, contactless payment offers convenience, but its security mechanisms differ across regions. In Europe, strict regulations often mandate a PIN for transactions over a certain threshold (e.g., $100), and banks typically place the responsibility for fraud on the cardholder, leading to highly locked-down card behavior. In contrast, US systems often have higher tap limits and more consumer-friendly fraud protection policies, where banks are more likely to refund fraudulent charges. Chotia's research primarily focuses on the European context, aiming to bypass these stringent limits.
The EMV specification itself is a colossal, multi-thousand-page document, notoriously complex and difficult to parse. Despite its density, Chotia notes that the core protocol, if left untouched, is remarkably secure. The basic online EMV transaction involves the reader asking the card type, the card providing a list of required transaction data (amount, currency, date), and the card then generating a cryptographic MAC (Message Authentication Code) using a shared secret key with the bank. This MAC, along with transaction details, is sent to the bank for cryptographic validation, fraud checks, and balance verification. For offline transactions, where no immediate bank connection is available, the card uses a public key to sign the transaction data, and the reader verifies this signature against a certificate chain to ensure the card's authenticity.
The problem, as Chotia emphasizes, arises when companies introduce "extra features" that are not part of the core, publicly available EMV specification. These additions, such as using phones with Face ID or fingerprint authentication, transit modes that bypass lock screens, or loyalty card integrations, are often retrofitted onto the existing protocol in an ad-hoc manner. Crucially, these proprietary extensions are rarely publicly documented, and different companies often implement similar features independently, without informing or coordinating with each other. This lack of transparency, standardization, and interoperability creates a breeding ground for security vulnerabilities, as the security properties of the overall system become a patchwork of unverified assumptions rather than a cohesive, formally proven design.
To tackle this complexity, Chotia's team at the University of Birmingham employs formal models – mathematical representations of these protocols. By writing simple rules in a language akin to a programming language, they can describe the exact behavior of cards and readers. Tools like Tamarin then allow them to test these models against an attacker who can "try anything," systematically searching for bad states or security breaches. This rigorous approach, which forces researchers to consider every minute detail of the protocol, has been instrumental in uncovering vulnerabilities that others have missed.
Key Findings
▶ Watch: How new features introduce security vulnerabilities (4:50)
The research presented by Tom Chotia revealed several critical vulnerabilities stemming from the non-standard, proprietary features added to contactless payment systems:
- Apple Pay (Visa) Transit Mode Bypass: This allowed attackers to bypass the lock screen and authentication requirements of iPhones in transit mode (e.g., for subway payments) and conduct high-value transactions with a Visa card. The attack exploited a combination of Apple's proprietary "Apple Enhanced Contactless Polling" (AECP) and specific handling of transaction flags by Visa, enabling a man-in-the-middle to trick both the phone and the payment terminal.
- Square Offline Mode Vulnerability: Square's proprietary method for identifying phones in offline transactions, which relied on checking for loyalty card information, was easily bypassed. This allowed attackers to use a standard plastic card to perform high-value offline transactions without any authentication. A subsequent fix by Square inadvertently created a temporary "money printing" vulnerability where any garbage signature was accepted offline.
- Systemic Weakness from Feature Creep: The overarching finding is that the addition of undocumented, non-standard, and independently developed features by payment providers (Apple, Visa, Mastercard, Square) introduces severe security flaws. These features often circumvent the original EMV security mechanisms, are not subject to the same rigorous scrutiny, and lead to a fragmented, insecure payment ecosystem.
- Lack of Interoperability and Communication: A major contributor to these vulnerabilities is the failure of different entities (e.g., Apple, Visa, Square, Mastercard) to communicate, standardize, or formally test their new features against each other's implementations. This results in conflicting assumptions and exploitable gaps.
- Relay Attack Vulnerability: Most of the identified attacks, including those against Apple Pay and Square, are variations of relay attacks (man-in-the-middle). Chotia's team found that these attacks can be effectively mitigated by introducing low-level timing checks into the EMV standard.
Technical Deep Dive
▶ Watch: Visa's offline protocol and public key signing (6:00)
The technical core of Chotia's research lies in understanding the EMV protocol's nuances and then meticulously analyzing how proprietary extensions break its security.
EMV Protocol Fundamentals
At its heart, an EMV contactless transaction proceeds through several stages:
- Card Identification: The reader sends a message asking "What kind of card are you?" (e.g., Visa, Mastercard). The card responds with its type.
- Transaction Preparation: The reader initiates a transaction, and the card requests specific data, such as the transaction amount, currency, and date. The reader sends this information to the card.
- Cryptographic Proof:
- Online Transactions (Visa/Amex default): The card creates a Message Authentication Code (MAC) using a cryptographic key shared only between the card and the bank. This MAC, along with the transaction data, is sent to the reader, which forwards it to the bank. The bank verifies the MAC, performs fraud checks, and balance checks, then sends an approval or denial back to the reader.
- Offline Transactions (Visa also has this): The card uses an on-card public key to sign all transaction data. The reader verifies this signature against a certificate chain to ensure the card's authenticity, without needing to contact the bank immediately.
- Confirmation: The reader receives the bank's decision (online) or verifies the card's signature (offline) and confirms the payment.
Chotia highlights that if EMV companies had strictly adhered to these well-defined, publicly specified protocols, security would be robust. The issues arise from deviations.
Formal Modeling and Discovery
The University of Birmingham team employs formal models to analyze these complex protocols. They translate the EMV specification and its various extensions into a set of mathematical rules, using tools like Tamarin Prover. This allows them to define the state of the card, reader, and network, and then systematically explore all possible message exchanges, including those initiated by a malicious attacker. This method forces them to explicitly define the behavior for every possible input and every bit value, often revealing undocumented or ambiguously specified behaviors that lead to vulnerabilities.
Apple Pay (Visa) Transit Mode Attack
This attack targets the specific implementation of Apple Pay with Visa cards, particularly when operating in "transit mode" (e.g., for subway turnstiles), which is designed for speed and convenience, bypassing the lock screen.
- Apple Enhanced Contactless Polling (AECP): The team discovered a proprietary "magic code" sent at the lowest layer of NFC communication (ISO 1443). This code, identified through a public Apple patent, instructs an iPhone to unlock a specific payment application in a sandboxed mode, even if the main user account is locked. This bypasses the typical Face ID or fingerprint authentication.
- Man-in-the-Middle Relay: The attacker sets up a relay device that acts as a fraudulent transit reader to the victim's iPhone and as a legitimate (but manipulated) payment terminal to a shop reader.
- Amount and Authentication Flag Manipulation:
- The attacker's relay broadcasts the AECP magic bytes, tricking the victim's iPhone into transit mode.
- The attacker initiates a high-value transaction (e.g., $10,000). The legitimate shop reader would normally send a flag indicating this is a "high amount" requiring strong authentication.
- The attacker's relay intercepts this message and flips a bit in the transaction data, reporting to the card that the $10,000 transaction is actually a "low amount." The card accepts this because it doesn't have hard coded limits for specific currencies (a $10,000 transaction might be "low" in some regions).
- The card processes the transaction and generates a payment token. Critically, it also includes a flag indicating no authentication was performed (e.g., no Face ID).
- The attacker's relay intercepts this response from the card and flips another bit, reporting to the shop reader that strong authentication (Face ID) was performed on the phone.
- The shop reader, believing the transaction is fully authenticated, forwards it to the bank. The bank, seeing the "Face ID done" flag, approves the transaction without further fraud checks.
This attack works because the critical flags (high/low amount, authentication performed) are not covered by the cryptographic MAC in online mode, nor are they part of the signed data checked by the reader in this specific online interaction. The card does sign a message saying "I haven't done any checks" for offline mode, but the attacker simply discards this information when relaying to an online reader. Apple initially dismissed the vulnerability, but after being presented with bank statements showing thousands of pounds of fraudulent transactions, they acknowledged it, blaming Visa. Visa, in turn, initially called it a "lab attack" but later confirmed its real-world applicability and committed to refunding victims.
Square Offline Mode Attack
Square's implementation of offline payment processing also introduced vulnerabilities due to proprietary feature additions.
- Loyalty Card as Phone Indicator: Square sought to limit offline transactions to phones that had performed strong authentication. However, there's no standard EMV flag for "I am a phone." Square's solution was to check for loyalty card information at the start of the transaction. If a card responded with loyalty data (or a non-error message), Square assumed it was a phone.
- Bypass: An attacker with a plastic card could use a relay to intercept Square's initial loyalty card query. The relay would respond to Square, pretending it was a phone with no loyalty card data (or simply not an error). This tricked the Square reader into thinking it was dealing with an authenticated phone.
- Offline Acceptance: The plastic card then processed the transaction, and while it would typically include a flag indicating "do not accept this without online authorization," the Square reader, operating in offline mode, could not check this flag immediately. It would accept the high-value transaction (e.g., $20,000) based on its flawed "phone detection."
- Temporary "Money Printing" Vulnerability: Square quickly fixed the initial loyalty card bypass. However, the fix introduced a new, temporary vulnerability. For a period, Square readers would accept any garbage signature from an offline card. The signature check was delayed until the reader went online and communicated with the bank. This meant an attacker could literally invent card data and signatures, perform offline transactions, and the Square reader would accept them, effectively "printing money" until the transactions were later rejected by the bank (by which time the attacker would be gone). Square, unlike Apple, was responsive and offered a bounty for this discovery.
Proposed Solution: Timing Checks
To counter the prevalence of relay attacks, Chotia's team proposes a novel solution: timing the communication between the reader and the card at the lowest possible layer (ISO 1443). Relay attacks inherently introduce latency (e.g., 20 milliseconds) as data is transmitted between the victim, the attacker's relay, and the legitimate reader. By measuring the round-trip time of initial handshake messages, if the time exceeds a very short threshold (e.g., 15 milliseconds), the transaction can be aborted, effectively shutting down relay attacks. While Mastercard explored a similar idea at the application layer, Chotia's team found that variations in card-reader distance affected timing at higher layers. Implementing this at the fundamental ISO 1443 layer, where power and data exchange begins, provides a more reliable and robust defense. The team has been actively working with the ISO standardization committee for two years to integrate this amendment into the global standard, hoping to make EMV significantly safer.
Demo / Proof of Concept
▶ Watch: Using formal models to uncover EMV protocol flaws (7:00)
The talk, despite lacking visual aids due to technical difficulties, repeatedly emphasized the practical, real-world nature of these attacks. Chotia described several instances of successful demonstrations:
- Proxmark in London: During the height of COVID-19, his colleague Andrea traveled to London, equipped with a Proxmark device (a radio device for scanning NFC/RFID communications), to capture live EMV transaction data on the subway system. This hands-on data collection was crucial for understanding the undocumented "Apple Enhanced Contactless Polling" (AECP) magic codes.
- High-Value Purchases: Chotia detailed how his team successfully performed fraudulent high-value transactions using the Apple Pay/Visa transit mode bypass. He explicitly mentioned sending Apple "scannings of our bank statements showing thousands of pounds coming out of the bank accounts" as definitive proof. They even considered buying an Apple laptop using the attack, demonstrating its real-world impact.
- Square Offline Transactions: Similar practical demonstrations were conducted against Square readers in offline mode, proving the loyalty card bypass and the subsequent "money printing" vulnerability. Chotia mentioned having videos of Andrea performing these attacks, which would eventually be posted online.
- Not Just Lab Attacks: A key point of contention with Visa was their initial dismissal of the Apple Pay attack as a "lab attack." The team countered this by performing the attack "in practice" in a real shop, forcing Visa to acknowledge its real-world feasibility. Chotia also noted that "people are actually using this in real malware attacks to steal money," underscoring that these are not merely theoretical curiosities.
These demonstrations highlight that the vulnerabilities are not abstract or theoretical but represent concrete threats to consumers and payment systems, capable of being exploited for substantial financial fraud.
Defensive Implications
▶ Watch: Face ID/fingerprint payments bypass transaction limits (8:30)
The findings from Chotia's research carry significant implications for various stakeholders in the payment ecosystem:
- For Consumers:
- Be cautious with Apple Pay + Visa in Transit Mode: Chotia explicitly advises against having "Apple Pay and Visa and Transit mode" enabled together, as it makes users vulnerable to unlimited fraudulent transactions without authentication. Users should be aware of the settings that allow payments without Face ID or PIN, especially in public transport scenarios.
- Monitor Bank Statements: Always scrutinize bank and credit card statements for suspicious transactions, particularly for contactless payments.
- For Payment Processors and Banks (e.g., Visa, Mastercard, Square):
- Prioritize Standardization and Transparency: The most critical implication is the urgent need for payment companies to cease developing and deploying proprietary, undocumented "extra features" in isolation. All new features that touch the core payment protocol must be publicly specified, standardized, and subjected to rigorous, collaborative security analysis.
- Formal Verification of New Features: Adopt formal modeling and verification techniques for all proposed protocol extensions. This proactive approach can catch subtle flaws before deployment, preventing costly breaches and reputational damage.
- Interoperability Testing: Conduct comprehensive interoperability testing of new features across different card schemes, device manufacturers (phones, readers), and payment processors. Assumptions made by one party about another's implementation are a major source of vulnerabilities.
- Enhanced Fraud Detection: While not a primary solution, banks should refine their fraud detection systems to flag unusual transaction patterns, especially those involving high values through contactless channels that might bypass standard authentication.
- For EMVCo and Standardization Bodies (e.g., ISO):
- Integrate Timing-Based Relay Attack Detection: The proposed timing-based check at the ISO 1443 layer is a robust, low-level defense against a wide class of relay attacks. Standardization bodies should expedite its adoption and integration into global standards. This would provide a foundational security layer that is less susceptible to application-layer feature creep.
- Discourage Proprietary Extensions: Actively work to discourage or penalize the deployment of non-standard, undocumented protocol extensions that undermine the security architecture of EMV.
- For Device Manufacturers (e.g., Apple):
- Security by Design for "Convenience" Features: Features like transit mode, designed for user convenience, must be implemented with robust security mechanisms that are publicly vetted and standardized. Bypassing lock screens for payment should be treated with extreme caution and subjected to the highest level of security review.
- Responsible Vulnerability Disclosure: Engage constructively with security researchers. Dismissing well-documented, practically demonstrated vulnerabilities as "doesn't work" or "lab attacks" only delays fixes and endangers users. Bounties should reflect the severity and impact of the discovered flaws.
By addressing these defensive implications, the payment industry can move towards a more secure, transparent, and resilient contactless payment ecosystem, where innovation does not come at the cost of fundamental security.
Key Takeaways
- Proprietary features undermine security: Ad-hoc, undocumented "extra features" added to EMV protocols by individual companies (e.g., Apple, Square) are the primary source of new and severe contactless payment vulnerabilities, not flaws in the core EMV spec.
- Formal modeling is essential: Rigorous formal verification using tools like Tamarin is a highly effective method for discovering subtle, non-obvious vulnerabilities in complex payment protocols that traditional testing might miss.
- Apple Pay (Visa) transit mode is vulnerable: The Apple Pay/Visa combination, when used in transit mode, can be exploited via a relay attack to bypass lock screen authentication and perform high-value fraudulent transactions by manipulating transaction flags.
- Square's offline mode had critical flaws: Square's proprietary method for identifying phones in offline transactions was bypassable, leading to unauthorized high-value payments. A subsequent fix temporarily introduced a "money printing" vulnerability.
- Lack of communication creates systemic risk: Independent development and deployment of features without public specification, standardization, or inter-company communication lead to conflicting assumptions and easily exploitable security gaps.
- Timing checks offer a robust defense: Implementing low-level timing checks (e.g., at the ISO 1443 layer) can effectively mitigate a broad class of relay attacks by detecting the latency introduced by an attacker's relay device.
About the Speaker(s)
Tom Chotia is a distinguished researcher from the University of Birmingham, specializing in the security of payment systems, particularly EMV contactless protocols. He is part of a dedicated research group, acknowledging the significant contributions of his colleagues Andrea, George, Iona, and Anna. Chotia's work is characterized by a deep dive into the mathematical and technical intricacies of these protocols, employing advanced techniques such as formal modeling and verification to identify subtle, yet critical, security vulnerabilities. His expertise extends beyond theoretical analysis to practical, real-world demonstrations of attacks, often involving close collaboration (and sometimes contention) with major industry players like Apple, Visa, and Square. Furthermore, Chotia is actively engaged in the global standardization process, working with bodies like ISO to propose and integrate fundamental security improvements into the core payment standards, such as timing-based relay attack detection. His commitment to both academic rigor and practical impact makes him a key voice in the field of payment security.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid academic security research with real teeth: formal verification catching production vulnerabilities in Apple Pay and Square that actually got exploited in the wild. The bit-flipping relay attack against Apple Pay/Visa transit mode is genuinely elegant, and the ISO 1443 timing-check proposal shows a researcher who didn't stop at 'here's the problem.' Minor drag on novelty — relay attacks aren't new, and EMV research has a deep bibliography — but the application to proprietary extension creep and the formal modeling methodology elevate this above typical payment security rehash.
Heather Calloway (CISO) — SOLID
Chotia presents credible, formally-verified research exposing real fraud vectors in contactless payment systems — and backs it with bank statements, not just lab captures. The work is technically sound and the proposed timing-based fix is a genuine contribution. But this is a researcher talking at DEF CON, not an accountability brief for the people who can actually fix the ecosystem.