A locked iPhone processed roughly $10,000 through Apple Pay without Face ID, Touch ID, or a passcode. No unlock. No prompt. No authentication of any kind.
This is not a universal iPhone flaw, and that distinction matters. The vulnerability targets one specific setup: a Visa card configured as the Express Transit card inside Apple Wallet.
How a Transit Shortcut Becomes a $10,000 Problem
Express Transit was built for speed, and that convenience carries a real security cost.
Express Transit, sometimes called Express Travel, lets you tap through subway gates without unlocking your phone. As 9to5Mac noted, “Express Transit lets you use Apple Pay without requiring authentication like Touch ID or Face ID.” Apple’s own documentation confirms the phone does not even need to be awake.
By default, Express Transit is set to “None.” You have to go into Settings and manually assign a card to activate it.
Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using NFC relay hardware, specifically a Proxmark reader, paired with a custom Python script and an Android phone. That combination lets an attacker spoof a transit gate signal near your locked iPhone.
Your phone, convinced it is paying a subway fare, transmits payment data. The relay modifies the transaction amount and forwards it to a real point-of-sale terminal nearby.
BBC News reported the finding directly: “Large unauthorised contactless payments can be made on locked iPhones by exploiting how an Apple Pay feature designed to help commuters pay quickly at ticket barriers works with Visa.”
Your iPhone stays locked the entire time. Subsequent demonstrations pushed the transaction to around $10,000. No enforced cap was apparent within the exploit path, according to Forbes and India Times.
This is targeted fraud, not casual opportunistic theft. It requires specialized hardware, physical proximity to your device, and access to a point-of-sale terminal.
Apple and Visa Point at Each Other. You’re in the Middle.
Two companies, one open vulnerability, and no confirmed patch from either side.
Apple has argued the problem lies in Visa’s EMV contactless protocol implementation, not in Apple Pay’s core design. Visa points to its zero-liability policy, meaning unauthorized charges should be reimbursed if you report them promptly, according to 9to5Mac’s coverage of the original disclosure.
Researchers counter that liability policies are not a substitute for technical fixes. Neither Apple nor Visa has publicly confirmed a complete patch as of publication , a pattern reminiscent of how a surveillance app can persist undetected on a device long after its risks are known.
Mastercard and American Express are not affected in the same way. This exploit is specific to Visa cards sitting in the Express Transit slot.
The vulnerability was first publicly documented around September 30, 2021, and no confirmed fix has followed.
What You Can Do Right Now
The fix is available in Settings and takes less than a minute to apply.
Go to Settings, then Wallet & Apple Pay, then Express Transit Card, and set it to None. Alternatively, assign a non-Visa card to that slot. Either action removes the authentication bypass entirely.
If your iPhone is lost or stolen, activate Lost Mode immediately through Find My. Apple confirms this suspends Apple Pay cards on the device, including any Express Transit functionality, even if the phone is offline.
Check your Visa card statements for unfamiliar high-value contactless charges. If anything looks wrong, dispute it under Visa’s zero-liability protection. You should also review broader device habits , avoiding a public USB charger is one simple step that reduces your overall exposure to mobile payment exploits.
The fix has been available since 2021 and takes thirty seconds to apply. The vulnerability has stayed open just as long.



























