In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping

Raja Hasnain Anwar (PhD student · University of Massachusetts Amherst), Syed Rafiul Hussain (Penn State University), Muhammad Taqi Raza (Dr · University of Massachusetts Amherst)

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

In an era where digital wallets have become an indispensable part of our daily financial transactions, offering convenience and a perceived layer of security over physical cards, a critical analysis by researchers from the University of Massachusetts Amherst and Penn State University reveals alarming vulnerabilities. Presented at USENIX Security '24 by Raja Hasnain Anwar, this talk, titled "In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping," dissects fundamental flaws in the digital payment ecosystem that could allow attackers to make unauthorized transactions, even after a physical card has been reported stolen, locked, or replaced.

Watch on YouTube

Visual summary for In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping by Raja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi Raza
Visual summary for In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping by Raja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi Raza

Key moments

  1. 0:00 Introduction: Digital wallet security bypass for free shopping
  2. 2:00 Understanding how digital wallets use tokens for payments
  3. 4:00 Weak user authentication when adding cards to wallets
  4. 6:00 Locked physical cards don't block digital wallet transactions
  5. 7:00 New card replacement without user authentication vulnerability
  6. 8:00 Security compromised for user experience leads to unlimited access

In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping

Speakers: Raja Hasnain Anwar; Syed Rafiul Hussain; Muhammad Taqi Raza

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=wZ8b6121l6w

Overview

In an era where digital wallets have become an indispensable part of our daily financial transactions, offering convenience and a perceived layer of security over physical cards, a critical analysis by researchers from the University of Massachusetts Amherst and Penn State University reveals alarming vulnerabilities. Presented at USENIX Security '24 by Raja Hasnain Anwar, this talk, titled "In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping," dissects fundamental flaws in the digital payment ecosystem that could allow attackers to make unauthorized transactions, even after a physical card has been reported stolen, locked, or replaced.

The research highlights how an "unconditional trust" placed by banks in digital wallet security leads to a cascade of weaknesses, including inadequate user authentication during card provisioning, a lack of re-authentication during card replacement, and an insufficient cardholder verification process during transactions. These vulnerabilities collectively challenge the widely held belief in the inherent security of digital wallets. This work is crucial for understanding the evolving threat landscape in digital payments, urging a re-evaluation of current security protocols by banks, payment networks, and wallet providers to protect consumers from sophisticated fraud.

Background

▶ Watch: Introduction: Digital wallet security bypass for free shopping (0:00)

The evolution of payment systems has seen a significant shift from traditional physical cards to digital wallets. Historically, physical card transactions involve tapping a card on a Point-of-Sale (POS) terminal, which reads the card data and forwards it to the bank. This process is largely governed by the EMV protocol, which primarily secures the communication between the card and the terminal. Previous research in this domain largely focused on the EMV layer, treating the subsequent processing beyond the POS as a "black box."

Digital wallets introduced a new paradigm, replacing physical card numbers with virtual card numbers, commonly referred to as tokens. When a card is added to a digital wallet, the wallet generates a unique token for that card, and merchants then process payments using this token rather than the actual Primary Account Number (PAN). This tokenization was designed to enhance security by obscuring sensitive card data from merchants and allowing a single card to be provisioned across multiple devices and shared among multiple users. The perceived security benefits of digital wallets also stem from features like biometric authentication (Face ID or fingerprint) required to unlock the wallet and the encryption mechanisms used to store card data on the device. However, as this research demonstrates, the underlying security architecture of the broader digital payment ecosystem, particularly the interaction between banks and digital wallets, introduces significant vulnerabilities that undermine these perceived benefits. The core issue revolves around the fragmented view of identity across the ecosystem, where the cardholder's personal identity, bank account, device identity, and wallet identity are not robustly bound together.

Key Findings

▶ Watch: Weak user authentication when adding cards to wallets (4:00)

The research uncovered three primary categories of vulnerabilities stemming from the "unconditional trust" banks place in digital wallets, leading to potential "free shopping" scenarios for attackers:

  1. Weak User Authentication During Card Addition: The process of adding a card to a digital wallet often relies on inadequate user authentication. Banks delegate the verification decision to the wallet provider, which, being closest to the user, typically employs either Knowledge-Based Authentication (KBA) or Multi-Factor Authentication (MFA). The critical flaw lies in the prevalence and weakness of KBA methods, which might involve simple details like a billing address, zip code, date of birth, or the last four digits of a Social Security Number. Such personal identifiable information (PII) is frequently compromised and readily available on the dark web or obtainable through social engineering, making KBA a highly insecure method. Even when MFA options are presented, the availability of a KBA alternative allows a malicious actor to choose the path of least resistance. For instance, PayPal was observed to allow card addition solely with a billing address, while Apple Pay, though offering MFA via email or SMS, still provided a KBA option involving a phone call to provide PII.
  1. Persistence of Malicious Wallet Access Post-Card Lock/Replacement: A major finding is that the security measures taken by a legitimate cardholder after a card is compromised often fail to revoke access for a malicious digital wallet. If a card is reported stolen or locked, banks typically block transactions from the physical card but, in many cases, continue to allow transactions initiated through a digital wallet that was previously provisioned with that card. Furthermore, when a cardholder requests a replacement card, the new PAN and associated token are often automatically pushed to existing digital wallets without any further user intervention or re-authentication. This behavior, intended to enhance user experience as per some interpretations of the EMV specification for seamless updates, inadvertently grants a malicious wallet "unlimited access" to the new card, perpetuating the fraud even after the original card has been replaced.
  1. Flawed In-Device Cardholder Verification Method (CVM): The mechanism used to verify the cardholder during a digital wallet transaction, known as Consumer Device CVM, is fundamentally flawed. Unlike physical card transactions that might require a PIN or signature, digital wallet payments often rely on the user unlocking their device using biometrics (fingerprint or Face ID) or a device passcode. The research highlights that this only verifies the owner of the device, not necessarily the legitimate cardholder. Since one person's card can be added to another person's device, unlocking the device merely confirms device ownership, leading the bank to "automatically approve" the transaction without true authentication of the cardholder. This critical disconnect between device identity and cardholder identity creates a significant bypass in transaction security.

Collectively, these findings expose a systemic vulnerability rooted in the misaligned trust models and identity binding mechanisms within the digital payment ecosystem, where convenience has, in several instances, been prioritized over robust security.

Technical Deep Dive

▶ Watch: Locked physical cards don't block digital wallet transactions (6:00)

The technical underpinnings of digital payment security, particularly the interplay between banks, payment networks, and digital wallets, reveal where these vulnerabilities manifest. The system is built upon the concept of tokenization, where a sensitive Primary Account Number (PAN) is replaced by a unique, non-sensitive token for transactions. This token is what merchants see, theoretically protecting the actual card details. However, the integrity of this system relies heavily on robust processes for token provisioning, lifecycle management, and user authentication, areas where the research identified significant gaps.

Identity Binding and Authentication Delegation

A core issue is the missing binding of cardholder identities. In the digital payment ecosystem, there are distinct identities: the cardholder's personal identity, their bank account, the identity of the device (e.g., a smartphone), and the identity of the digital wallet application itself. The study found that these identities are not strongly linked. Banks, often distant from the user's immediate interaction, delegate user authentication during card registration to the digital wallet provider. This delegation is performed through a handshake procedure, where the bank queries the wallet's authentication capabilities and prepares for the method preferred by the wallet.

This delegation leads to the critical choice between Knowledge-Based Authentication (KBA) and Multi-Factor Authentication (MFA). KBA, relying on easily compromised personal information such as billing address, zip code, date of birth, or the last four digits of a Social Security Number, presents a severe weakness. The speaker provided concrete examples:

  • PayPal: Allowed card addition solely based on providing the billing address. This represents a purely KBA-based authentication with minimal security.
  • Apple Pay: Offered more choices, including MFA via email or SMS. However, it also presented a KBA option requiring a phone call to the bank to provide personal details like date of birth or SSN digits. Even if Apple Pay considers this an MFA due to the call, the underlying authentication is still KBA, relying on PII. This illustrates how the presence of a weak option, even alongside stronger ones, compromises the overall security posture.

An attacker, having obtained basic PII (which is readily available through data breaches or social engineering), can exploit these weak KBA mechanisms to successfully provision a stolen card into their malicious digital wallet.

Card Replacement and Token Persistence

The EMV specification, particularly its aspects related to token lifecycle management and user experience, is cited as a factor contributing to the vulnerability during card replacement. When a legitimate cardholder's physical card is stolen or corrupted, they request a new card from their bank. The bank then generates a new PAN and a corresponding new token. Crucially, this update is often "pushed" to existing digital wallets that previously held the original card, without any user intervention or re-authentication.

The research highlights that:

  1. Previously active tokens often remain active: Even if the physical card is locked or reported stolen, some banks do not automatically revoke the associated tokens in digital wallets, allowing the malicious wallet to continue making transactions.
  2. New card details are automatically provisioned: If a malicious wallet was already associated with the original card, it automatically receives the updated token for the new card. This effectively grants the attacker "unlimited access" to the replacement card, bypassing any security measures the user might have taken. This "enhancement of user experience" comes at a severe security cost.

Cardholder Verification Method (CVM) Flaws

The final layer of defense, Cardholder Verification Method (CVM), is also compromised in digital wallet transactions. For physical cards, CVMs include PINs, signatures, or ZIP code verification. For digital wallets, the primary CVM is Consumer Device CVM. This involves the user unlocking their wallet app using biometrics (fingerprint, Face ID) or a device passcode.

The fundamental flaw here is that **Consumer Device CVM verifies the owner of the device, not the *cardholder***. The speaker explicitly states, "the bank thinks okay this is the the legitimate user user and this user is authorized to make payments but we know that the card holder identity and the device identity and the wallet identity are not the same because one person's card could be added to another person's device." Therefore, any transaction performed using the wallet, once the device is unlocked, is "automatically approved without any authentication" of the actual cardholder. This disconnect allows an attacker who has successfully provisioned a stolen card into their device to conduct transactions seamlessly, as their device ownership is sufficient for the CVM.

The research also alludes to "additional attacks that involve the online payments," suggesting the vulnerabilities extend beyond physical POS transactions, though the talk's primary focus was on the foundational issues described. The study was conducted with stringent ethical considerations, using the researchers' own devices and credit cards to avoid any financial liability on banks, wallets, merchants, or users, with all findings responsibly disclosed to affected parties.

Demo / Proof of Concept

▶ Watch: New card replacement without user authentication vulnerability (7:00)

While no live, public demonstration of an attack on third-party systems was performed during the conference talk, the researchers thoroughly validated their findings through controlled experiments. The speaker explicitly stated: "all the testing that we do is on on our own devices using our own credit card so we don't do not put any Financial liability on the banks or the wallets or any other Merchant or a user." This rigorous approach ensured that the identified vulnerabilities were reproducible and not theoretical.

The researchers effectively demonstrated the practical implications of their findings by:

  • Simulating card addition with weak KBA: They showed how easy it was to add a card to certain digital wallets (e.g., PayPal) using only readily available personal information like a billing address, bypassing stronger authentication methods.
  • Observing token persistence post-card lock/replacement: They validated that even after reporting their physical card as locked or stolen, and subsequently receiving a replacement, the associated tokens in their test digital wallets often remained active, or the new card's token was automatically provisioned, allowing continued transactions from the "malicious" (test) wallet.
  • Confirming the CVM bypass: By provisioning their own card onto a test device and then unlocking that device, they could verify that the digital wallet transactions were approved based on device ownership rather than specific cardholder identity, illustrating the critical flaw in the Consumer Device CVM.

These internal proofs of concept provided the empirical evidence necessary to substantiate the claims of systemic vulnerabilities, underscoring the gap between perceived and actual security in the digital payment ecosystem. The speaker confirmed that "all the findings have been responsibly disclosed to all the banks and wallets and to our best information they have disclo they have patched these problems," indicating the practical impact of their validation efforts.

Defensive Implications

▶ Watch: Security compromised for user experience leads to unlimited access (8:00)

The findings of "In Wallet We Trust" carry significant implications for all stakeholders in the digital payment ecosystem, necessitating a multi-pronged defensive strategy.

For Banks and Payment Networks:

  • Re-evaluate Trust Models: Banks must critically re-assess their "unconditional trust" in digital wallet security. This requires a shift from passive delegation to active oversight and enforcement of security standards.
  • Strengthen User Authentication for Card Provisioning: Mandate robust Multi-Factor Authentication (MFA) for adding cards to digital wallets, eliminating or severely restricting the use of weak Knowledge-Based Authentication (KBA). This might involve requiring strong device-bound biometrics, hardware tokens, or one-time passwords delivered via secure channels that are not easily compromised.
  • Implement Strong Authentication for Card Replacement: When a card is replaced, any associated digital wallet tokens should be automatically revoked or, at minimum, require explicit, strong re-authentication from the cardholder to re-provision the new card details. The current system of silent, automatic updates compromises security for convenience.
  • Ensure Comprehensive Token Revocation: Card locking or reporting a card stolen must trigger the immediate and complete revocation of all associated digital wallet tokens across all devices. Banks need to ensure their policies and technical capabilities support this comprehensive revocation.
  • Improve Identity Binding: Develop and implement mechanisms that strongly bind the cardholder's identity to their bank account, digital wallet, and device. This could involve cryptographically linking identities or using stronger attestations during provisioning and transaction authorization.
  • Standardize Security Policies: Work with payment networks and wallet providers to establish uniform, high-security standards for digital wallet integration, ensuring consistent protection across different platforms and financial institutions.

For Digital Wallet Providers:

  • Prioritize Strong Authentication: Actively promote and enforce strong MFA during card addition. If KBA is offered, it should be as a last resort, supplemented by additional fraud detection mechanisms, or phased out entirely.
  • Enhance Consumer Device CVM: Re-architect the Consumer Device CVM to genuinely verify the cardholder, not just device ownership. This could involve requiring a separate, cardholder-specific biometric or PIN within the wallet app after the device is unlocked, or integrating with stronger identity verification services.
  • Implement Robust Token Management: Ensure that tokens are securely managed throughout their lifecycle, with clear protocols for revocation and re-provisioning that prioritize security over seamless user experience when a card is compromised.
  • Transparency with Banks: Maintain open communication and technical integration with banks to ensure that security policies (e.g., token revocation upon card lock) are effectively implemented and synchronized.

For Consumers:

  • Be Vigilant with PII: Exercise extreme caution when sharing personal information, especially details that could be used for KBA. Assume that information like billing addresses or partial SSNs could be compromised.
  • Report Compromise Immediately: If a physical card is lost or stolen, report it to the bank immediately. Crucially, explicitly ask the bank to confirm that all associated digital wallet tokens have been revoked and that no new card details will be automatically pushed to existing wallets without your explicit re-authentication.
  • Utilize Strong MFA: Always opt for the strongest available authentication methods (e.g., SMS/email OTP, hardware tokens, biometrics) when adding cards to digital wallets or performing sensitive transactions.
  • Regularly Review Statements: Monitor bank and card statements diligently for any unauthorized transactions, even after a physical card has been replaced.

By addressing these architectural and procedural weaknesses, the digital payment ecosystem can move towards a more secure future where convenience does not come at the cost of fundamental security principles.

Key Takeaways

  • Unconditional Trust is a Critical Flaw: Banks' implicit and often "unconditional trust" in the security of digital wallets creates systemic vulnerabilities, leading to a lack of robust security measures.
  • Weak Authentication During Card Addition: The reliance on easily compromised Knowledge-Based Authentication (KBA) for adding cards to digital wallets allows attackers to provision stolen card details with minimal effort.
  • Card Replacement Does Not Guarantee Security: Even after a physical card is locked or replaced, a malicious digital wallet can retain access to the original token or automatically receive updates for the new card, perpetuating unauthorized transactions without further user authentication.
  • Flawed In-Device Cardholder Verification: The Consumer Device CVM used by digital wallets primarily verifies device ownership (e.g., via fingerprint or Face ID) rather than the legitimate cardholder, enabling unauthorized transactions if a stolen card has been provisioned to an attacker's device.
  • Missing Identity Binding: A core issue is the insufficient binding between a cardholder's personal identity, their bank account, their device, and their digital wallet, which fragments security responsibilities and creates exploitable gaps.
  • Security vs. User Experience Trade-off: Current digital payment practices often prioritize a seamless user experience (e.g., automatic card updates) over implementing stringent security protocols, leading to significant compromises.

About the Speaker(s)

Raja Hasnain Anwar is a PhD student at the University of Massachusetts Amherst. He was the primary presenter of this research at USENIX Security '24 and is actively seeking internship opportunities. His work focuses on critical aspects of digital payment security, aiming to identify and mitigate vulnerabilities in widely adopted systems.

Syed Rafiul Hussain is affiliated with Penn State University. He collaborated on this research, contributing his expertise to the study of digital wallet payment security.

Muhammad Taqi Raza is associated with the University of Massachusetts Amherst. He served as the supervisor for Raja Hasnain Anwar's PhD work, guiding the research that led to these significant findings on digital payment vulnerabilities.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This research provides a deep, actionable dive into systemic vulnerabilities within the digital payment ecosystem, exposing how banks' "unconditional trust" in digital wallets enables persistent fraud. The detailed analysis of weak authentication, token persistence post-card replacement, and flawed Consumer Device CVM offers critical insights for banks and wallet providers to re-evaluate their security postures. It's solid work that actually matters.

Heather Calloway (CISO) — MUST SEE

This research exposes fundamental systemic flaws in the digital payment ecosystem, stemming from misaligned trust models between banks and digital wallet providers. It clearly articulates critical gaps in user authentication, token lifecycle management, and cardholder verification, creating significant fraud exposure. The findings are essential for driving a necessary re-evaluation of governance and operational practices across the industry.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium