/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

ATM and PIN-pad hacks demoed at Black Hat security conference show chip cards aren't impervious to fraud

Megan Geuss / Ars Technica :

Ars Technica Megan Geuss

Context & Ripple Effects

Chip-and-PIN was sold to banks and merchants as the fix for counterfeit card fraud, so the Black Hat demos land where it hurts: the attack surface isn't the card but the ATM and PIN-pad terminals that read it. The talk fits a pattern of hardware security research at Black Hat aimed at everyday payment and access devices rather than software.

The corpus shows this wasn't a one-off: years later, researchers were still finding ways to sidestep chip-based cards' security features to mint counterfeits, and the US Secret Service flagged the Fuze smart card as a tool thieves use to carry multiple counterfeit cards undetected.

First-order effects

  • ATM operators and PIN-pad vendors are directly exposed: their terminals are now demonstrated attack vectors, forcing immediate scrutiny of device firmware and physical tamper protections.
  • Issuing banks that leaned on EMV liability shifts to declare chip fraud largely solved have to revisit that assumption, since the compromise happens at the reader, not the card.

Second-order effects

  • Terminal manufacturers face pressure to add attestation and anti-tampering features, shifting cost into every deployed PIN pad and ATM in exchange for closing a demonstrated hole.
  • Fraud tooling follows the research path: the later work on bypassing chip security and the Fuze card shows counterfeiters industrializing exactly the class of attack these demos previewed.

Third-order effects

  • If terminal-level attacks keep outpacing card-level defenses, payment security investment migrates from the card to the point-of-interaction device — attested readers, encrypted PIN entry, and remote terminal monitoring become the baseline.
  • Conference disclosures like this one function as an informal audit layer for embedded hardware: vendors of locks (Vingcard's master-key flaw) and even casino shufflers (Deckmate) have since been put on notice the same way, making Black Hat a recurring stress test for physical-device trust.

The trend: Payment and access-control fraud is migrating from cloned credentials toward attacks on the trusted hardware that reads them, with researcher disclosures setting the remediation agenda.