A banking transaction can be triggered without your card ever leaving the bottom of your bag, and the cause lies in a flaw in the design of contactless payments that few people suspect. We’ve been told that NFC only works over a few centimeters, that tiny distance meant to guarantee that a payment requires a deliberate gesture, card in hand, extended toward the terminal. Yet a method known as relay attack challenges this comforting certainty. The idea is as elegant as it is troubling: instead of physically bringing the card closer to the reader, its information is carried remotely, thanks to two smartphones acting as intermediaries. No science-fiction film, no dramatic hacking, just a well-oiled technical chain and a victim who notices absolutely nothing. Let us decode this phenomenon together, a topic that deserves our attention.
NFC Has Never Been as Short-Range as You Think
The acronym NFC, for Near Field Communication, designates this close-proximity communication technology that equips our bank cards and our phones. Its selling point rests on a simple promise: the range is limited to roughly 4 centimeters. In other words, for an exchange to take place, you must press or nearly press the card against the reader. This short distance has long been presented as a natural safeguard against abuse. After all, how could someone siphon money from you if they must bring a device within a few centimeters of your pocket without you noticing?
The problem, however, is that this physical reach of a few centimeters is only part of the equation. What current cards do not verify is the logical reach of the exchange. In plain terms, as long as the dialogue between the chip and the reader proceeds normally, the card does not question whether its correspondent is truly at four centimeters or four kilometers away. It is precisely in this blind spot that fraudsters take advantage.
How Two Phones Make Your Card Travel Without Moving
Imagine a phone conversation between two people who do not share a common language, yet each has a live translator. The relay attack operates on this principle. It relies on two accomplices, each equipped with a smartphone bearing an NFC reader. The first approaches the victim discreetly—while they stand in a queue, in a crowded transport, or within a dense crowd—and places their phone a few centimeters from the contactless card tucked away in a bag or pocket. This phone acts as a false reader: it captures the data emitted by the chip.
These data are then transmitted in real time, via the Internet, to the second accomplice who is near a real payment terminal, sometimes hundreds of kilometers away. Their smartphone replays the information as if the card were physically present. The terminal, unable to distinguish, approves the transaction. The victim’s card has been used to pay for an item without ever exiting the bag. The attacker’s device functions as a simple intermediary, capturing legitimate information to relay it to a place where it will be exploited.
What Fraudsters Can Actually Extract, and What Still Blocks Them
This kind of fraud is made possible by the absence, in today’s generations of cards and terminals, of a security mechanism called DBP, for Distance-Bounding Protocol. This protocol would allow the terminal to time the duration of its dialogue with the chip. Since data travels via the Internet inherently introduces a tiny but measurable delay, the terminal could detect that its counterpart is not truly at a few centimeters. Until this safeguard becomes widespread, the door remains ajar.
The sums involved are not negligible. This method lets crooks collect quickly, as several mules can string together payments almost simultaneously using the same stolen data. In recent years, NFC-related attacks have focused more on Android smartphones and relay scenarios than on merely reading a card out in the street. A highly refined relay system has already been tested at scale, with no real barrier to its expansion beyond borders.
Shielded Pocket, Simple Gestures: Reclaiming Control Over Your Contactless Payments
Does this mean you should abandon contactless and revert to a four-digit code for every tap? Not necessarily. A few simple actions can significantly reduce the risk. An RFID-blocking case or a shielded wallet physically blocks NFC exchanges when the card is not in use. Storing your card deep inside your bag, surrounded by other cards, also makes it much harder for prying hands. Regularly monitoring your bank statements remains the most effective habit to spot suspicious transactions early.
Good news on the financial front: banks are obligated to reimburse all contactless payments made without the customer’s authorization. Even better, in case of dispute, the burden of proving any negligence rests with the financial institution, not you. So you are not alone facing this risk.
Contactless payments remain a tremendous time-saver in everyday life, and it would be excessive to demonize them. But the relay attack reminds us of a universal truth in technology: no barrier is insurmountable, only more or less costly to breach. The real protection will likely come from the broader adoption of mechanisms such as the timing of exchanges. In the meantime, one question deserves consideration: how far are we willing to sacrifice a bit of convenience for an added layer of security?