A Locked iPhone, a Visa Card, and a $10,000 Security Flaw

Researchers showed a Visa Express Transit card in Apple Wallet can be silently charged via NFC relay, with no patch confirmed since 2021

Rex Edison Avatar
Rex Edison Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Attackers can steal $10,000 from a locked iPhone using NFC relay hardware near Visa Express Transit cards.
  • Disable Express Transit in Wallet settings or replace Visa with another card to eliminate the vulnerability.
  • Apple and Visa blame each other, leaving no confirmed patch since the exploit’s 2021 public disclosure.

A locked iPhone processed roughly $10,000 through Apple Pay without Face ID, Touch ID, or a passcode. No unlock. No prompt. No authentication of any kind.

This is not a universal iPhone flaw, and that distinction matters. The vulnerability targets one specific setup: a Visa card configured as the Express Transit card inside Apple Wallet.

How a Transit Shortcut Becomes a $10,000 Problem

Express Transit was built for speed, and that convenience carries a real security cost.

Express Transit, sometimes called Express Travel, lets you tap through subway gates without unlocking your phone. As 9to5Mac noted, “Express Transit lets you use Apple Pay without requiring authentication like Touch ID or Face ID.” Apple’s own documentation confirms the phone does not even need to be awake.

By default, Express Transit is set to “None.” You have to go into Settings and manually assign a card to activate it.

Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using NFC relay hardware, specifically a Proxmark reader, paired with a custom Python script and an Android phone. That combination lets an attacker spoof a transit gate signal near your locked iPhone.

Your phone, convinced it is paying a subway fare, transmits payment data. The relay modifies the transaction amount and forwards it to a real point-of-sale terminal nearby.

BBC News reported the finding directly: “Large unauthorised contactless payments can be made on locked iPhones by exploiting how an Apple Pay feature designed to help commuters pay quickly at ticket barriers works with Visa.”

Your iPhone stays locked the entire time. Subsequent demonstrations pushed the transaction to around $10,000. No enforced cap was apparent within the exploit path, according to Forbes and India Times.

This is targeted fraud, not casual opportunistic theft. It requires specialized hardware, physical proximity to your device, and access to a point-of-sale terminal.

Apple and Visa Point at Each Other. You’re in the Middle.

Two companies, one open vulnerability, and no confirmed patch from either side.

Apple has argued the problem lies in Visa’s EMV contactless protocol implementation, not in Apple Pay’s core design. Visa points to its zero-liability policy, meaning unauthorized charges should be reimbursed if you report them promptly, according to 9to5Mac’s coverage of the original disclosure.

Researchers counter that liability policies are not a substitute for technical fixes. Neither Apple nor Visa has publicly confirmed a complete patch as of publication , a pattern reminiscent of how a surveillance app can persist undetected on a device long after its risks are known.

Mastercard and American Express are not affected in the same way. This exploit is specific to Visa cards sitting in the Express Transit slot.

The vulnerability was first publicly documented around September 30, 2021, and no confirmed fix has followed.

What You Can Do Right Now

The fix is available in Settings and takes less than a minute to apply.

Go to Settings, then Wallet & Apple Pay, then Express Transit Card, and set it to None. Alternatively, assign a non-Visa card to that slot. Either action removes the authentication bypass entirely.

If your iPhone is lost or stolen, activate Lost Mode immediately through Find My. Apple confirms this suspends Apple Pay cards on the device, including any Express Transit functionality, even if the phone is offline.

Check your Visa card statements for unfamiliar high-value contactless charges. If anything looks wrong, dispute it under Visa’s zero-liability protection. You should also review broader device habits , avoiding a public USB charger is one simple step that reduces your overall exposure to mobile payment exploits.

The fix has been available since 2021 and takes thirty seconds to apply. The vulnerability has stayed open just as long.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →