• My Feed
  • Home
  • What's Important
  • Media & Entertainment
Search

Stay Curious. Stay Wanture.

© 2026 Wanture. All rights reserved.

  • Terms of Use
  • Privacy Policy
Tech/Security
iPhone Express Transit Flaw Lets Thieves Steal $10,000

20 April 2026

—

News

Carter Brooks

A security flaw discovered by UK researchers allows thieves to steal up to $10,000 from a locked iPhone using Apple Pay's Express Transit feature, and neither Apple nor Visa seems eager to own the problem.

The vulnerability bypasses Visa's built in transaction limits when Express Transit is enabled. That's the feature designed to let you tap your phone at subway turnstiles without unlocking it, convenient for commuters, but a gift to anyone with a homemade NFC reader and bad intentions.

Here's the kicker: your phone can be completely locked, Face ID dormant, Touch ID idle, and a thief can still authorize a payment well beyond what transit systems normally allow. Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using a custom NFC reader that mimics a transit terminal, tricking the phone into transmitting payment credentials without your biometric approval.

This isn't a universal Apple Pay meltdown. The exploit only works with Visa cards linked to Express Transit on iPhone. If you're using Mastercard, you're fine. Samsung Pay users? Also safe. It's a narrow technical crack, but it's a deep one.

The researchers went public with a full demonstration on the Veritasium YouTube channel, where they successfully extracted $10,000 from the locked iPhone of popular tech YouTuber Marques Brownlee (MKBHD). The video walks through the attack step by step, the kind of demonstration that makes you want to immediately open your Wallet app and start reviewing your settings.

Visa's official response boils down to: "This is a theoretical problem we don't expect to see in the wild, and even if it happens, you're covered." The company pointed to its zero liability policy, which reimburses cardholders for fraudulent charges. That's reassuring, until you think about the hassle of disputing a $10,000 phantom charge while you're just trying to get to work.

Apple, for its part, said the issue lies with the payment system, not the iPhone hardware. Translation: not our problem. Visa says it's a device issue. Apple says it's a payment network problem. Meanwhile, your phone is sitting there like a very expensive, very hackable transit pass.

Security experts recommend disabling Express Transit for Visa cards or removing the card from Apple Pay entirely until a fix arrives. It's not elegant, but it's effective. Go to Settings, tap Wallet & Apple Pay, select your Visa card, and turn off Express Transit Mode. You'll have to unlock your phone at the turnstile like it's 2015, but you won't wake up to a four figure charge from a transit system you've never visited.

As of now, neither Apple nor Visa has announced a timeline for patching the vulnerability. So for the moment, convenience loses to security, and honestly, that's the way it should be.

Mobile Bottom Test Banner

What is this about?

  • News/
  • Carter Brooks/
  • Tech/
  • Security/
  • Client Security/
  • Apple Pay Express Transit Vulnerability/
  • Visa Card Payment Exploit

Feed

    China's Dola‑Seed‑2.0 Cuts Gap to 2.7% vs. Claude Opus 4.6

    China's Dola‑Seed‑2.0 Cuts Gap to 2.7% vs. Claude Opus 4.6

    Rachel Steinabout 5 hours ago
    Apple delays refreshed Mac Studio launch to October

    Apple delays refreshed Mac Studio launch to October

    Supply shortages push MacBook Pro to late‑2026/early‑2027, Q4 earnings at risk

    Carter Brooksabout 5 hours ago
    Apple delays M6‑Pro/M6‑Max OLED MacBook Pro to 2027

    Apple delays M6‑Pro/M6‑Max OLED MacBook Pro to 2027

    Shortages delay M6‑Pro and M6‑Max to early 2027, pushing back the new Mac

    Carter Brooksabout 5 hours ago
    Apple unveils glassy Siri on Dynamic Island with iOS 27

    Apple unveils glassy Siri on Dynamic Island with iOS 27

    WWDC 2026: Siri expands Island on iPhone 14 Pro and up, arriving with iOS 27

    Carter Brooksabout 5 hours ago
    Honor Robot Shatters Half‑Marathon Record in 50:26

    Honor Robot Shatters Half‑Marathon Record in 50:26

    Robot Beats Human Benchmark by 7 Minutes, With 40% Fully Autonomous

    Marcus Dillardabout 21 hours ago
    AI Demand Drives DRAM Shortage, 16 GB DDR4 Prices Triple

    AI Demand Drives DRAM Shortage, 16 GB DDR4 Prices Triple

    AI outpaces DRAM, 16 GB DDR4 kit costs rise to three‑times mid‑2025 levels

    Priya Desaiabout 22 hours ago
    Casely issues second E33A recall in April 2026

    Casely issues second E33A recall in April 2026

    Up to 429,000 units made between March 2022 and Sept 2024 may overheat, prompting an urgent CPSC warning

    Carter Brooks2 days ago
    Meta hikes Quest 3S 128 GB, 256 GB, and Quest 3 512 GB prices

    Meta hikes Quest 3S 128 GB, 256 GB, and Quest 3 512 GB prices

    Price rise effective April 19, 2026, cites memory‑chip cost pressures

    Carter Brooks2 days ago
    Surface Laptop 8 OLED to debut this summer

    Surface Laptop 8 OLED to debut this summer

    Top‑tier models will feature OLED; Intel units arrive in May, and Snapdragon later

    Carter Brooks2 days ago
    Pixel 11 Leaks Pixel Glow Notification LEDs

    Pixel 11 Leaks Pixel Glow Notification LEDs

    Android 17 beta code shows Pixel 11 will add back‑panel lighting for alerts

    Carter Brooks3 days ago
    Apple adds camera shortcuts to iOS 27

    Apple adds camera shortcuts to iOS 27

    iOS 27 shortcuts turn photos into nutrition logs, contacts, and ticket scans

    Carter Brooks3 days ago
    Intel AI Quiet Plus Debuts on April 15, 2026

    Intel AI Quiet Plus Debuts on April 15, 2026

    Core Ultra 200HX Plus NPU caps noise at 43 dBA, retains 92% performance

    Priya Desai3 days ago
    Redmi Buds 8 Launches with 50 dB ANC and 11 mm Driver

    Redmi Buds 8 Launches with 50 dB ANC and 11 mm Driver

    Xiaomi Rolls Out Budget Earbuds in China on April 22, with 4 kHz ANC

    Carter Brooks3 days ago
    AMD re‑releases Ryzen 7 5800X3D for Q2 2026

    AMD re‑releases Ryzen 7 5800X3D for Q2 2026

    AMD offers performance to AM4 builders, extending platform life

    Priya Desai3 days ago
    OpenAI’s Codex gets gpt‑image‑1.5 and 90+ plugins

    OpenAI’s Codex gets gpt‑image‑1.5 and 90+ plugins

    The April 15, 2026 update adds autonomous screen control and a built‑in browser

    Ben Ramos3 days ago
    Apple to debut OLED iPad Air in 2027

    Apple to debut OLED iPad Air in 2027

    Affordable OLED display aims to revamp mid-range tablets

    Carter Brooks4 days ago
    Capcom orders GrizzoUK to delete 1,004 videos

    Capcom orders GrizzoUK to delete 1,004 videos

    Cease‑and‑desist nukes his Resident Evil: Requiem and Street Fighter mods, warning creators

    Ben Ramos4 days ago
    Allbirds' Pivot Fuels 600% Stock Surge

    Allbirds' Pivot Fuels 600% Stock Surge

    Marcus Dillard4 days ago
    DaVinci Resolve Beta Adds Photo Editor

    DaVinci Resolve Beta Adds Photo Editor

    Photo Manager lets creators edit RAW images inside the video timeline

    Ben Ramos5 days ago
    Loading...
Recommended for you
Subscription

Get daily briefings and deep dives without missing important updates.

Popular reads

See the most discussed stories and editor picks from this week.

Internal promo

Explore our featured projects, interviews, and special collections.

Tech/Security

iPhone Express Transit Flaw Lets Thieves Steal $10,000

20 April 2026

—

News

Carter Brooks

A security flaw discovered by UK researchers allows thieves to steal up to $10,000 from a locked iPhone using Apple Pay's Express Transit feature, and neither Apple nor Visa seems eager to own the problem.

The vulnerability bypasses Visa's built in transaction limits when Express Transit is enabled. That's the feature designed to let you tap your phone at subway turnstiles without unlocking it, convenient for commuters, but a gift to anyone with a homemade NFC reader and bad intentions.

Here's the kicker: your phone can be completely locked, Face ID dormant, Touch ID idle, and a thief can still authorize a payment well beyond what transit systems normally allow. Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using a custom NFC reader that mimics a transit terminal, tricking the phone into transmitting payment credentials without your biometric approval.

This isn't a universal Apple Pay meltdown. The exploit only works with Visa cards linked to Express Transit on iPhone. If you're using Mastercard, you're fine. Samsung Pay users? Also safe. It's a narrow technical crack, but it's a deep one.

The researchers went public with a full demonstration on the Veritasium YouTube channel, where they successfully extracted $10,000 from the locked iPhone of popular tech YouTuber Marques Brownlee (MKBHD). The video walks through the attack step by step, the kind of demonstration that makes you want to immediately open your Wallet app and start reviewing your settings.

Visa's official response boils down to: "This is a theoretical problem we don't expect to see in the wild, and even if it happens, you're covered." The company pointed to its zero liability policy, which reimburses cardholders for fraudulent charges. That's reassuring, until you think about the hassle of disputing a $10,000 phantom charge while you're just trying to get to work.

Apple, for its part, said the issue lies with the payment system, not the iPhone hardware. Translation: not our problem. Visa says it's a device issue. Apple says it's a payment network problem. Meanwhile, your phone is sitting there like a very expensive, very hackable transit pass.

Security experts recommend disabling Express Transit for Visa cards or removing the card from Apple Pay entirely until a fix arrives. It's not elegant, but it's effective. Go to Settings, tap Wallet & Apple Pay, select your Visa card, and turn off Express Transit Mode. You'll have to unlock your phone at the turnstile like it's 2015, but you won't wake up to a four figure charge from a transit system you've never visited.

As of now, neither Apple nor Visa has announced a timeline for patching the vulnerability. So for the moment, convenience loses to security, and honestly, that's the way it should be.

What is this about?

  • News/
  • Carter Brooks/
  • Tech/
  • Security/
  • Client Security/
  • Apple Pay Express Transit Vulnerability/
  • Visa Card Payment Exploit

Feed

    China's Dola‑Seed‑2.0 Cuts Gap to 2.7% vs. Claude Opus 4.6

    China's Dola‑Seed‑2.0 Cuts Gap to 2.7% vs. Claude Opus 4.6

    Rachel Steinabout 5 hours ago
    Apple delays refreshed Mac Studio launch to October

    Apple delays refreshed Mac Studio launch to October

    Supply shortages push MacBook Pro to late‑2026/early‑2027, Q4 earnings at risk

    Carter Brooksabout 5 hours ago
    Apple delays M6‑Pro/M6‑Max OLED MacBook Pro to 2027

    Apple delays M6‑Pro/M6‑Max OLED MacBook Pro to 2027

    Shortages delay M6‑Pro and M6‑Max to early 2027, pushing back the new Mac

    Carter Brooksabout 5 hours ago
    Apple unveils glassy Siri on Dynamic Island with iOS 27

    Apple unveils glassy Siri on Dynamic Island with iOS 27

    WWDC 2026: Siri expands Island on iPhone 14 Pro and up, arriving with iOS 27

    Carter Brooksabout 5 hours ago
    Honor Robot Shatters Half‑Marathon Record in 50:26

    Honor Robot Shatters Half‑Marathon Record in 50:26

    Robot Beats Human Benchmark by 7 Minutes, With 40% Fully Autonomous

    Marcus Dillardabout 21 hours ago
    AI Demand Drives DRAM Shortage, 16 GB DDR4 Prices Triple

    AI Demand Drives DRAM Shortage, 16 GB DDR4 Prices Triple

    AI outpaces DRAM, 16 GB DDR4 kit costs rise to three‑times mid‑2025 levels

    Priya Desaiabout 22 hours ago
    Casely issues second E33A recall in April 2026

    Casely issues second E33A recall in April 2026

    Up to 429,000 units made between March 2022 and Sept 2024 may overheat, prompting an urgent CPSC warning

    Carter Brooks2 days ago
    Meta hikes Quest 3S 128 GB, 256 GB, and Quest 3 512 GB prices

    Meta hikes Quest 3S 128 GB, 256 GB, and Quest 3 512 GB prices

    Price rise effective April 19, 2026, cites memory‑chip cost pressures

    Carter Brooks2 days ago
    Surface Laptop 8 OLED to debut this summer

    Surface Laptop 8 OLED to debut this summer

    Top‑tier models will feature OLED; Intel units arrive in May, and Snapdragon later

    Carter Brooks2 days ago
    Pixel 11 Leaks Pixel Glow Notification LEDs

    Pixel 11 Leaks Pixel Glow Notification LEDs

    Android 17 beta code shows Pixel 11 will add back‑panel lighting for alerts

    Carter Brooks3 days ago
    Apple adds camera shortcuts to iOS 27

    Apple adds camera shortcuts to iOS 27

    iOS 27 shortcuts turn photos into nutrition logs, contacts, and ticket scans

    Carter Brooks3 days ago
    Intel AI Quiet Plus Debuts on April 15, 2026

    Intel AI Quiet Plus Debuts on April 15, 2026

    Core Ultra 200HX Plus NPU caps noise at 43 dBA, retains 92% performance

    Priya Desai3 days ago
    Redmi Buds 8 Launches with 50 dB ANC and 11 mm Driver

    Redmi Buds 8 Launches with 50 dB ANC and 11 mm Driver

    Xiaomi Rolls Out Budget Earbuds in China on April 22, with 4 kHz ANC

    Carter Brooks3 days ago
    AMD re‑releases Ryzen 7 5800X3D for Q2 2026

    AMD re‑releases Ryzen 7 5800X3D for Q2 2026

    AMD offers performance to AM4 builders, extending platform life

    Priya Desai3 days ago
    OpenAI’s Codex gets gpt‑image‑1.5 and 90+ plugins

    OpenAI’s Codex gets gpt‑image‑1.5 and 90+ plugins

    The April 15, 2026 update adds autonomous screen control and a built‑in browser

    Ben Ramos3 days ago
    Apple to debut OLED iPad Air in 2027

    Apple to debut OLED iPad Air in 2027

    Affordable OLED display aims to revamp mid-range tablets

    Carter Brooks4 days ago
    Capcom orders GrizzoUK to delete 1,004 videos

    Capcom orders GrizzoUK to delete 1,004 videos

    Cease‑and‑desist nukes his Resident Evil: Requiem and Street Fighter mods, warning creators

    Ben Ramos4 days ago
    Allbirds' Pivot Fuels 600% Stock Surge

    Allbirds' Pivot Fuels 600% Stock Surge

    Marcus Dillard4 days ago
    DaVinci Resolve Beta Adds Photo Editor

    DaVinci Resolve Beta Adds Photo Editor

    Photo Manager lets creators edit RAW images inside the video timeline

    Ben Ramos5 days ago
    Loading...