Paying with an implant

When it comes to alternative point of sale payment technologies, PayPal is making an effort to plant itself into the payment terminals of various stores, and solutions like Venmo are proposing an “out of band” payment solution which allows customers to pay vendors through a mobile app. In this case, there was a lot of “buzz” (pun!) generated when a Buzzfeed reporter implanted an xNT chip to make payments using Venmo. While it is very interesting, it was a complete hack job that required participation from a former Venmo engineer and the vendor, wherein the end result was a completely insecure method to prove it could be done. The reporter’s Venmo wallet key had to be given to the vendor to make the transfer. Therefor the wallet key had to be stored insecurely on the xNT, and the solution would never work in the real world because everyone you did business with would have a copy of your wallet key. Still, it’s very interesting. Until Venmo or PayPal or other payment stakeholders become interested in implant technology, these solutions will be edge cases and proofs of concept only.


I read it until the VivoKey questionnaire as I have already filled that out. the rest seems either irrelevant or information I already knew. However thank you for posting it here so I could at least learn about the supposed “insecurities” with this payment method. as we all know it can’t be any more unsafe than someone walking past your card and being able to steal all of your card info. I feel like when we talk about contactless nothing is too insecure.

Okay, I’ll bite… most credit card fraud these days is done via online transactions using just the card number, expiration date and CVV (old, insecure, static card data).

When cards are copied to be used in person (which is much rarer as it is easier to get caught on cameras and arrested than on the internet through a VPN) it is to my knowledge ALWAYS by cloning the magstripe data to another card (for those playing at home - old, insecure, static card data). @DeviantOllam demonstrated this attack on The Modern Rogue youtube channel by copying a credit card to an old hotel key card. As of now, implanting magspoof devices has never been done.

I have NEVER seen evidence of a chip or contactless EMV card copied from a credible source online. This attack doesn’t exist. It relies on a private key being written to the card at factory and linked with a public key in their database. You can’t get the private key off the device, and without that you cannot pass the cryptographic challenges the terminal issues you on behalf of the bank. Transaction Declined. Thanks for playing.


Now to add shit to the water… I have. You create a payment request and swipe the details with a active antenna this can be done from some range. The gotcha if that rellaying those details is done with ACTIVE hardware and cannot be replicated with a chip.

You are duping a replaying the info, an implant would be the size of pegleg.


It starts in January, I found out that it is possible to get also in Austria a vimpay account. I got a microcard and shipped it to Amal. He converted it .
I will get it implanted next week :slight_smile:


You just described how you haven’t :wink: To clarify, I meant that the end result is a cloned card that can be freely used multiple times and is indistinguishable to a payment terminal. I’m aware that replay attacks exist, but its not the same thing as creating a copied card.

1 Like

@Pilgrimsmaster to answer your question, yes, any of those.

@Recorpse is correct in this, insecure is perfectly acceptable.

From Google’s dictionary - ‘not sufficiently protected; easily broken into.’

Insecure can be used to describe insufficient security, where unsecure is usually used to describe things that are not secured at all. Nonsecure seems to be a catch-all.


