Logo
My feedToday
Logo
Decide better.Live better.
My feedToday
Logo
My feedToday

Stay Curious. Stay Wanture.

© 2026 Wanture. All rights reserved.

  • Terms of Use
  • Privacy Policy
Logo
My feedTodayTechScienceHealthMobilityMindProductivityHomeExperiencesLongevity
Logo
Decide better.Live better.
My feedTodayTechScienceHealthMobilityMindProductivityHomeExperiencesLongevity
Logo
My feedTodayTechScienceHealthMobilityMindProductivityHomeExperiencesLongevity
Tech/Security

iPhone Express Transit Flaw Lets Thieves Steal $10,000

20 April 2026

—

News

Carter Brooks

A security flaw discovered by UK researchers allows thieves to steal up to $10,000 from a locked iPhone using Apple Pay's Express Transit feature, and neither Apple nor Visa seems eager to own the problem.

The vulnerability bypasses Visa's built in transaction limits when Express Transit is enabled. That's the feature designed to let you tap your phone at subway turnstiles without unlocking it, convenient for commuters, but a gift to anyone with a homemade NFC reader and bad intentions.

Here's the kicker: your phone can be completely locked, Face ID dormant, Touch ID idle, and a thief can still authorize a payment well beyond what transit systems normally allow. Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using a custom NFC reader that mimics a transit terminal, tricking the phone into transmitting payment credentials without your biometric approval.

This isn't a universal Apple Pay meltdown. The exploit only works with Visa cards linked to Express Transit on iPhone. If you're using Mastercard, you're fine. Samsung Pay users? Also safe. It's a narrow technical crack, but it's a deep one.

The researchers went public with a full demonstration on the Veritasium YouTube channel, where they successfully extracted $10,000 from the locked iPhone of popular tech YouTuber Marques Brownlee (MKBHD). The video walks through the attack step by step, the kind of demonstration that makes you want to immediately open your Wallet app and start reviewing your settings.

Visa's official response boils down to: "This is a theoretical problem we don't expect to see in the wild, and even if it happens, you're covered." The company pointed to its zero liability policy, which reimburses cardholders for fraudulent charges. That's reassuring, until you think about the hassle of disputing a $10,000 phantom charge while you're just trying to get to work.

Apple, for its part, said the issue lies with the payment system, not the iPhone hardware. Translation: not our problem. Visa says it's a device issue. Apple says it's a payment network problem. Meanwhile, your phone is sitting there like a very expensive, very hackable transit pass.

Security experts recommend disabling Express Transit for Visa cards or removing the card from Apple Pay entirely until a fix arrives. It's not elegant, but it's effective. Go to Settings, tap Wallet & Apple Pay, select your Visa card, and turn off Express Transit Mode. You'll have to unlock your phone at the turnstile like it's 2015, but you won't wake up to a four figure charge from a transit system you've never visited.

As of now, neither Apple nor Visa has announced a timeline for patching the vulnerability. So for the moment, convenience loses to security, and honestly, that's the way it should be.

What is this about?

  • News
  • Carter Brooks
  • Tech
  • Security
  • Client Security
  • Apple Pay Express Transit Vulnerability
  • Visa Card Payment Exploit

Feed

    UCSD reverses aging in blood stem cells via lysosomal repair

    Breakthrough in gene modulation restores 78% differentiation efficiency in aged human cells

    James Whitmore1 day ago

    Scientists Reverse Blood Stem Cell Aging by Restoring Cellular Recycling

    James Whitmore1 day ago
    Amazon Acquires Globalstar for $11.57 Billion

    Amazon Acquires Globalstar for $11.57 Billion

    Deal gives Amazon control of Apple Watch Ultra 3 satellite network

    Carter Brooks2 days ago
    We Are as Gods: Peter Diamandis's Survival Guide for the Age of Abundance

    We Are as Gods: Peter Diamandis's Survival Guide for the Age of Abundance

    Marcus Dillard2 days ago
    Daemon Tools 12.5.0.2421‑2434 Compromised, 12.6.0.2445 Fixed

    Daemon Tools 12.5.0.2421‑2434 Compromised, 12.6.0.2445 Fixed

    Kaspersky flags 12.5.0.2421‑2434 installers compromised; upgrade to 12.6.0.2445

    Logan Price6 May 2026
    Xiaomi Mijia Robot Vacuum and Mop 6 Launches in China

    Xiaomi Mijia Robot Vacuum and Mop 6 Launches in China

    The 28 000 Pa suction robot adds roller‑wet cleaning, but U.S. must wait

    Logan Price6 May 2026
    Apple unveils iOS 27 AI overhaul at WWDC on June 8, 2026

    Apple unveils iOS 27 AI overhaul at WWDC on June 8, 2026

    Siri gets a standalone app, AI Photos tools, and health coaching in iOS 27

    Carter Brooks5 May 2026

    Google Workspace Icon Redesign: From Flat Color Blocks to Gradient‑Rich, Rounded Designs

    Google replaced its 2020 four‑color Workspace icons with gradient‑rich, rounded versions. The redesign cut misclicks, eased app recognition, and underscored the importance of usability over strict brand uniformity.

    Renée Ito3 May 2026

    Apple to unveil iOS 27 with standalone Siri app at WWDC on June 8

    Update brings satellite connectivity, ChatGPT-style interface, and developer extensions

    Carter Brooks3 May 2026

    iPhone 18 Pro to Launch iOS 27 Camera with f/1.5‑f/2.8 Aperture

    iOS 27 adds a “Siri” visual‑AI mode as Apple readies iPhone 18 Pro for fall

    Carter Brooks30 April 2026
    Loading...
Tech/Security

iPhone Express Transit Flaw Lets Thieves Steal $10,000

20 April 2026

—

News

Carter Brooks

A security flaw discovered by UK researchers allows thieves to steal up to $10,000 from a locked iPhone using Apple Pay's Express Transit feature, and neither Apple nor Visa seems eager to own the problem.

The vulnerability bypasses Visa's built in transaction limits when Express Transit is enabled. That's the feature designed to let you tap your phone at subway turnstiles without unlocking it, convenient for commuters, but a gift to anyone with a homemade NFC reader and bad intentions.

Here's the kicker: your phone can be completely locked, Face ID dormant, Touch ID idle, and a thief can still authorize a payment well beyond what transit systems normally allow. Researchers at the University of Birmingham and the University of Surrey demonstrated the attack using a custom NFC reader that mimics a transit terminal, tricking the phone into transmitting payment credentials without your biometric approval.

This isn't a universal Apple Pay meltdown. The exploit only works with Visa cards linked to Express Transit on iPhone. If you're using Mastercard, you're fine. Samsung Pay users? Also safe. It's a narrow technical crack, but it's a deep one.

The researchers went public with a full demonstration on the Veritasium YouTube channel, where they successfully extracted $10,000 from the locked iPhone of popular tech YouTuber Marques Brownlee (MKBHD). The video walks through the attack step by step, the kind of demonstration that makes you want to immediately open your Wallet app and start reviewing your settings.

Visa's official response boils down to: "This is a theoretical problem we don't expect to see in the wild, and even if it happens, you're covered." The company pointed to its zero liability policy, which reimburses cardholders for fraudulent charges. That's reassuring, until you think about the hassle of disputing a $10,000 phantom charge while you're just trying to get to work.

Apple, for its part, said the issue lies with the payment system, not the iPhone hardware. Translation: not our problem. Visa says it's a device issue. Apple says it's a payment network problem. Meanwhile, your phone is sitting there like a very expensive, very hackable transit pass.

Security experts recommend disabling Express Transit for Visa cards or removing the card from Apple Pay entirely until a fix arrives. It's not elegant, but it's effective. Go to Settings, tap Wallet & Apple Pay, select your Visa card, and turn off Express Transit Mode. You'll have to unlock your phone at the turnstile like it's 2015, but you won't wake up to a four figure charge from a transit system you've never visited.

As of now, neither Apple nor Visa has announced a timeline for patching the vulnerability. So for the moment, convenience loses to security, and honestly, that's the way it should be.

What is this about?

  • News/
  • Carter Brooks/
  • Tech/
  • Security/
  • Client Security/
  • Apple Pay Express Transit Vulnerability/
  • Visa Card Payment Exploit

Feed

    UCSD reverses aging in blood stem cells via lysosomal repair

    Breakthrough in gene modulation restores 78% differentiation efficiency in aged human cells

    James Whitmore1 day ago

    Scientists Reverse Blood Stem Cell Aging by Restoring Cellular Recycling

    James Whitmore1 day ago
    Amazon Acquires Globalstar for $11.57 Billion

    Amazon Acquires Globalstar for $11.57 Billion

    Deal gives Amazon control of Apple Watch Ultra 3 satellite network

    Carter Brooks2 days ago
    We Are as Gods: Peter Diamandis's Survival Guide for the Age of Abundance

    We Are as Gods: Peter Diamandis's Survival Guide for the Age of Abundance

    Marcus Dillard2 days ago
    Daemon Tools 12.5.0.2421‑2434 Compromised, 12.6.0.2445 Fixed

    Daemon Tools 12.5.0.2421‑2434 Compromised, 12.6.0.2445 Fixed

    Kaspersky flags 12.5.0.2421‑2434 installers compromised; upgrade to 12.6.0.2445

    Logan Price6 May 2026
    Xiaomi Mijia Robot Vacuum and Mop 6 Launches in China

    Xiaomi Mijia Robot Vacuum and Mop 6 Launches in China

    The 28 000 Pa suction robot adds roller‑wet cleaning, but U.S. must wait

    Logan Price6 May 2026
    Apple unveils iOS 27 AI overhaul at WWDC on June 8, 2026

    Apple unveils iOS 27 AI overhaul at WWDC on June 8, 2026

    Siri gets a standalone app, AI Photos tools, and health coaching in iOS 27

    Carter Brooks5 May 2026

    Google Workspace Icon Redesign: From Flat Color Blocks to Gradient‑Rich, Rounded Designs

    Google replaced its 2020 four‑color Workspace icons with gradient‑rich, rounded versions. The redesign cut misclicks, eased app recognition, and underscored the importance of usability over strict brand uniformity.

    Renée Ito3 May 2026

    Apple to unveil iOS 27 with standalone Siri app at WWDC on June 8

    Update brings satellite connectivity, ChatGPT-style interface, and developer extensions

    Carter Brooks3 May 2026

    iPhone 18 Pro to Launch iOS 27 Camera with f/1.5‑f/2.8 Aperture

    iOS 27 adds a “Siri” visual‑AI mode as Apple readies iPhone 18 Pro for fall

    Carter Brooks30 April 2026
    Loading...
Home
Home
Search
Search