ATM and PIN-pad hacks demoed at Black Hat security conference show chip cards aren't impervious to fraud
Megan Geuss / Ars Technica :
Context & Ripple Effects
Chip-and-PIN was sold to banks and merchants as the fix for counterfeit card fraud, so the Black Hat demos land where it hurts: the attack surface isn't the card but the ATM and PIN-pad terminals that read it. The talk fits a pattern of hardware security research at Black Hat aimed at everyday payment and access devices rather than software.
The corpus shows this wasn't a one-off: years later, researchers were still finding ways to sidestep chip-based cards' security features to mint counterfeits, and the US Secret Service flagged the Fuze smart card as a tool thieves use to carry multiple counterfeit cards undetected.
First-order effects
- ATM operators and PIN-pad vendors are directly exposed: their terminals are now demonstrated attack vectors, forcing immediate scrutiny of device firmware and physical tamper protections.
- Issuing banks that leaned on EMV liability shifts to declare chip fraud largely solved have to revisit that assumption, since the compromise happens at the reader, not the card.
Second-order effects
- Terminal manufacturers face pressure to add attestation and anti-tampering features, shifting cost into every deployed PIN pad and ATM in exchange for closing a demonstrated hole.
- Fraud tooling follows the research path: the later work on bypassing chip security and the Fuze card shows counterfeiters industrializing exactly the class of attack these demos previewed.
Third-order effects
- If terminal-level attacks keep outpacing card-level defenses, payment security investment migrates from the card to the point-of-interaction device — attested readers, encrypted PIN entry, and remote terminal monitoring become the baseline.
- Conference disclosures like this one function as an informal audit layer for embedded hardware: vendors of locks (Vingcard's master-key flaw) and even casino shufflers (Deckmate) have since been put on notice the same way, making Black Hat a recurring stress test for physical-device trust.
The trend: Payment and access-control fraud is migrating from cloned credentials toward attacks on the trusted hardware that reads them, with researcher disclosures setting the remediation agenda.