International Edition
Latest News
Technology

Researchers Unveil New Cybersecurity Flaws at Def Con 2024

At the DEF CON cybersecurity conference in Las Vegas, security researchers Robert Kruczek and Kamil Szczurowski demonstrated vulnerabilities in contactless payment systems that allow unauthorized charges by cloning transaction signals. According to the researchers, threat actors can capture…

Researchers Unveil New Cybersecurity Flaws at Def Con 2024

At the DEF CON cybersecurity conference in Las Vegas, security researchers Robert Kruczek and Kamil Szczurowski demonstrated vulnerabilities in contactless payment systems that allow unauthorized charges by cloning transaction signals. According to the researchers, threat actors can capture legitimate point-of-sale terminal data and replay it using specialized hardware to initiate fraudulent transactions on nearby contactless cards and mobile wallets.

How Contactless Payment Relay Attacks Work

The attack vector relies on manipulating near-field communication (NFC) protocols between a payment card and a card reader. Kruczek and Szczurowski explained that attackers can use modified hardware setups—often costing less than $100—to bridge the physical distance between a victim’s card and a rogue terminal. By extending the communication range of the NFC signal, the proxy device tricks the card into believing it is interacting directly with an authorized point-of-sale machine, authorizing a transaction without the cardholder’s knowledge or physical consent.

Mitigation Strategies and Industry Standards

Payment card issuers and terminal manufacturers implement multiple security layers to counter relay and replay threats, including dynamic cryptograms and strict transaction time-out windows. According to industry specifications managed by EMVCo, contactless transactions require a unique cryptographic token for every payment, preventing a captured signal from being reused indefinitely. However, security researchers continue to test the boundaries of these safeguards, pointing to the need for continuous protocol updates and hardware-level enhancements to protect consumer financial data against evolving wireless interception techniques.

Frequently Asked Questions

Can contactless cards be scanned from a distance in a crowd?

Standard NFC chips operate within a very short range of a few centimeters. However, specialized relay equipment demonstrated by researchers can extend this operational distance, though practical execution in a crowded environment remains constrained by timing tolerances required by payment networks.

How can consumers protect themselves against NFC relay fraud?

Cardholders can use RFID-blocking wallets or sleeves that physically disrupt radio frequency signals when cards are not in active use. Additionally, monitoring account statements regularly and enabling real-time transaction alerts via banking mobile applications ensures immediate detection of unauthorized charges.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”