ATM and PIN-pad hacks demoed at Black Hat security conference show chip cards aren't impervious to fraud
The good news? Hacks are limited for now. The bad news? Hackers will get better. — Security researchers are eager to poke holes in the chip-embedded credit and debit cards …
Context & Ripple Effects
The chip card was sold to US banks as the fix for counterfeit fraud, so Black Hat demos that defeat ATM and PIN-pad terminals strike at the core of that pitch. The talk landed days after separate research on a Samsung Pay flaw that could skim payment tokens — a rough week for the assumption that newer payment tech equals safer payment tech.
The article's own framing — hacks are limited for now, but hackers will get better — reads differently in hindsight: four years later, researchers showed attackers could sidestep the security features of certain banks' chip cards to mint working counterfeit chip cards, exactly the escalation this demo foreshadowed.
First-order effects
- Banks and terminal operators deploying EMV have an immediate auditing problem: the demos target the PIN pads and ATMs in their own fleets, shifting scrutiny from cardholder behavior to device firmware and implementation choices.
- Card networks' fraud-liability shift toward chip means any demonstrated gap lands on issuers' and merchants' books, giving them a direct financial stake in the disclosed attack paths rather than treating them as academic curiosities.
Second-order effects
- Payment-terminal makers face the vendor dilemma already visible elsewhere at Black Hat — the same conference later exposed a 'full control' flaw in Deckmate's casino shufflers and a master-key flaw in Vingcard's hotel locks — forcing them toward coordinated-disclosure programs and faster patch pipelines for embedded hardware.
- Tokenized mobile wallets like Samsung Pay get marketed as the more secure alternative, but the same week's token-skimming research undercuts that pitch, leaving banks with no clean migration path away from vulnerable endpoints.
Third-order effects
- If the pattern holds — researcher demos in 2016 maturing into practical counterfeit techniques by 2020 — chip-and-PIN becomes one layer in a defense-in-depth stack rather than the terminal fix, pushing the industry toward continuous re-evaluation of payment cryptography instead of decade-long certification cycles.
- The recurring Black Hat hardware disclosures point regulators and standards bodies toward treating point-of-sale and access-control devices as a shared threat class, since ATM pads, hotel locks, and casino equipment all fail the same way: trusted embedded hardware with unvetted update paths.
The trend: Physical payment and access hardware — ATMs, PIN pads, locks, even casino shufflers — is being systematically dismantled by independent researchers, with Black Hat serving as the annual proving ground that turns lab attacks into criminal playbooks within years.