The transaction unfolded in silence, a chilling testament to a vulnerability that has persisted in the digital ether for half a decade.
On a dark screen, an iPhone, ostensibly secure and locked, became the unwitting conduit for a $10,000 transfer, executed without a single tap, a biometric scan, or an entered passcode.
The architects of this unsettling demonstration were not shadowy figures in a clandestine lab, but reputable cybersecurity researchers working alongside Veritasium’s Derek Muller and MKBHD, two of the internet’s most influential tech communicators.
Their video, a public exposé seen by millions, laid bare a man-in-the-middle NFC attack that targets Apple Pay’s Express Transit mode specifically with Visa cards – an exploit known to Apple and Visa since 2021, yet left unaddressed.
At the heart of the demonstration, and indeed the vulnerability, lies a deceptively simple relay attack.
Professors Ioana Boureanu and Tom Chothia, the researchers who originally identified the flaw, showcased how off-the-shelf NFC hardware, a laptop, and a Python script could effectively trick an iPhone.
The device, placed on a reader, would silently transmit payment credentials.
The iPhone’s Express Transit feature, designed for seamless taps at subway turnstiles, operates on a principle of speed over stringent security for low-value transactions.
The critical flaw emerges here: the iPhone trusts a flag from the NFC reader indicating a small, transit-type payment.
It does not independently verify the transaction amount.
By spoofing the transit terminal identifier and manipulating protocol bits, attackers can relay the Visa credentials to a legitimate payment terminal, processing any desired amount.
The researchers, after a successful $5 test, escalated to a $10,000 transaction, a sum that evaporated from MKBHD’s account with disturbing ease.
What makes this disclosure particularly galling is its lineage.
This isn’t a zero-day exploit fresh from discovery.
The exact mechanism was first brought to light by the same research team in 2021, presented at the IEEE Symposium on Security and Privacy in 2022, and publicly demonstrated with a £1,000 transaction.
The attack chain, the conditions required, and crucially, the fix status, remain unchanged.
The only new elements are the magnified scale of the demonstration – from £1,000 to $10,000 – and the unprecedented audience, courtesy of the combined 36 million subscribers of Veritasium and MKBHD.
This isn’t just a technical paper anymore; it’s a meticulously crafted pressure campaign, designed to force the hands of two corporate giants.
The core engineering failure, as detailed by the researchers, is a clear trust-boundary violation.
The iPhone’s Secure Element, rather than independently verifying the transaction amount against the payment network, blindly accepts the flag from the NFC reader.
This was a deliberate design choice, a trade-off for the sub-second response times demanded by transit systems.
The researchers, however, have unequivocally proven this assumption to be exploitable.
The protocol-level issue is specific and fixable.
Their 2021 paper outlined precise remedies: Apple could refuse Express Transit transactions above a certain threshold without user confirmation, or Visa could implement server-side checks to flag unusual transit-mode amounts.
Five years on, neither has happened.
Instead, the response from both Apple and Visa has been a study in corporate deflection.
Apple points fingers at Visa’s system, while Visa dismisses the attack as “very unlikely” in real-world scenarios and assures users of its zero-liability policy.
As Dr. Andreea Radu, one of the original researchers, presciently observed in 2021, “When two industry parties each have partial blame, neither is willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely.”
That statement, now half a decade old, remains starkly accurate.
The inertia isn’t born of technical complexity; the fixes are architecturally straightforward.
It stems, instead, from a corporate calculus that weighs the perceived rarity of the attack against the cost and effort of implementing a systemic solution, implicitly offloading the risk onto the consumer.
While the exploit is undeniably serious, it’s also important to contextualize its real-world applicability.
The attack requires physical proximity to the victim’s iPhone, typically for several seconds, meaning a casual brush-past in a crowd is insufficient.
The Veritasium demonstration showed the phone sitting directly on the hardware for the duration of the transfer.
A real-world pickpocket would need to maintain sustained contact while a collaborator operates a payment terminal elsewhere.
This coordination and physical constraint make large-scale exploitation challenging.
Indeed, despite five years of public knowledge, no confirmed cases of this specific attack vector being used in the wild have been reported by law enforcement, financial institutions, or fraud reporting services.
This rarity, however, does not absolve the companies of responsibility; it merely speaks to the economics of fraud, where simpler methods often yield greater returns.
Visa’s reliance on its zero-liability policy, while technically accurate, rings emotionally hollow.
Recovering $10,000 that has suddenly vanished from one’s account, even if guaranteed, involves days or weeks of dispute resolution, potential financial hardship, and the sheer mental burden of dealing with fraud.
“You can dispute the charge” is a corporate evasion of a fundamental user experience failure.
The default “fix” offered to users – disable Express Transit for Visa cards – is not a solution but a transfer of liability.
It demands that users unilaterally disable a convenience feature shipped by two trillion-dollar companies, acknowledging a known flaw that neither party seems willing to mend.
This saga extends beyond a mere technical glitch; it illuminates several broader trends critical to fintech and mobile payment security.
Firstly, convenience features inherently expand the attack surface.
Express Transit was designed for a clear user benefit, yet every skipped authentication step encodes a trust assumption.
When these assumptions are proven false, and the companies involved deem the risk acceptable due to “unlikelihood,” it mirrors the logic that precedes countless major data breaches.
The “theoretical” edge case becomes a demonstrated reality.
Secondly, the Visa-only specificity of the vulnerability is telling.
Mastercard, American Express, and Discover employ different security protocols for their contactless transactions that are not susceptible to this relay attack.
This suggests either a fundamental weakness in Visa’s protocol implementation or a deliberate cost-benefit decision regarding security posture.
For developers and businesses integrating payment processing, the choice of card network is not solely a matter of transaction fees; it carries significant security implications.
Finally, this incident serves as a stark case study in the failure of responsible disclosure and the subsequent escalation to public demonstration.
The researchers followed proper channels in 2021.
When their warnings were met with corporate inaction, they turned to the most powerful platform available: mass public media.
The Veritasium video is not merely infotainment; it is a strategic maneuver, a last resort for researchers seeking accountability when traditional avenues are exhausted.
We should anticipate more such public escalations as companies continue to drag their feet on known vulnerabilities.
For the individual user, the immediate fix is simple: navigate to your iPhone’s Wallet settings, find Transit Cards, and either set it to “None” or ensure you are not using a Visa card for Express Transit.
It takes mere seconds.
The larger, systemic fix, however – the one requiring Apple or Visa to write and ship code to address a five-year-old vulnerability – appears to be stalled indefinitely, a casualty of corporate finger-pointing and a misplaced sense of security.
Until that changes, the silence of a compromised, locked phone will remain a disquieting reminder of who ultimately bears the burden of unaddressed digital risk.
