Contactless cards can be skimmed in a narrow technical sense, but the data a thief captures is almost worthless. Every tap produces a one-time cryptogram that expires the instant it’s used, the three-digit code on the back of the card is never sent wirelessly, and the wireless range tops out at roughly four inches. The FBI actually recommends tapping your card over swiping or inserting it, calling tap-to-pay “more secure and less likely to be compromised.”1FBI. Skimming
How Close a Thief Would Have to Get
Contactless cards use Near Field Communication at 13.56 MHz. There’s no battery inside. The card only wakes up when a reader’s electromagnetic field is close enough to power its chip, and the entire exchange takes a fraction of a second.
Standard NFC operates within about 10 centimeters, roughly four inches. Researchers using custom antennas under ideal laboratory conditions have stretched that to 13.4 centimeters and no further. The physics gets in the way: the reader has to supply the power that runs the card, and the card’s return signal is inherently weak. Cranking up the reader doesn’t help you hear a whisper from across the room. To skim your card, someone essentially has to bump their device against your pocket or bag.
What a Skimmer Could Actually Read
If a rogue reader does get close enough, the card responds with the Primary Account Number and the expiration date. Those come out in a standard format any compatible reader can interpret. That sounds bad, and it would be bad, except for what isn’t transmitted.
The three-digit security code printed on the back of the card is never part of the contactless data stream. Most online retailers require that code, so skimmed card data alone won’t complete a typical e-commerce purchase. The card also transmits a one-time cryptogram in place of any reusable authentication data, and that’s the piece that makes the whole attack collapse.
Why the Cryptogram Makes Captured Data Useless
Every contactless transaction generates a unique cryptogram. The chip creates it using an internal algorithm, the transaction amount, a counter, and other variables specific to that moment. The issuing bank runs the same calculation on its end. If the codes match and the code hasn’t already been used, the transaction goes through. If it’s been seen before, the bank rejects it.
A thief who records the full exchange between your card and a hidden reader ends up with a cryptogram that’s already spent. It can’t authorize a second charge. The next legitimate tap of your card generates a completely different code. What the skimmer captured is closer to a used receipt than a copy of your key.
This is the break from the magnetic stripe era. Stripes stored static data that never changed, so cloning a swiped card was straightforward. EMV chips fixed that by making every interaction unique. Each transaction uses a fresh session key derived from the issuer’s master key and transaction-specific inputs, and there is no reusable secret sitting on the card for a thief to lift.
How Often This Actually Happens
Documented cases of criminals making money from contactless skimming in the wild are essentially nonexistent. Security researchers have shown at conferences that reading card data remotely is technically possible, but converting that data into fraud runs into every barrier above: no CVV for online purchases, no reusable cryptogram for in-person purchases, and a card number the bank is already watching.
The threats that actually cost people money look different. Physical overlay skimmers on ATMs and gas pumps still capture magnetic stripe data every day. Phishing emails and retailer data breaches spill card numbers by the millions. Tapping your card at a legitimate terminal sidesteps the stripe reader entirely, which is why the FBI treats tap-to-pay as one of the better defenses against the skimming that actually happens.1FBI. Skimming
Mobile Wallets Go a Step Further
Apple Pay and Google Pay build on the same contactless technology but add two safeguards a plastic card can’t offer. First, tokenization: when you add a card to the wallet, the bank issues a Device Account Number that replaces your real card number. The actual number is never stored on the phone, never sent to merchants, and never backed up to the cloud.2Apple Support. Apple Pay Security and Privacy Overview
Second, the phone won’t broadcast anything until you unlock the transaction with a fingerprint, face scan, or passcode. A physical contactless card responds automatically to any reader that powers it. A phone in your pocket does not. Someone walking past you with a hidden NFC reader gets nothing from a locked wallet.
Simple Habits That Lower the Risk Further
- Use a mobile wallet where you can. Biometric authentication and tokenization together close off passive scanning entirely.
- Favor a credit card over a debit card for tap-to-pay. If fraud does happen, credit card protection keeps the disputed money off your checking account while the issuer investigates.
- Check your statements regularly. Consumer liability limits depend on how quickly you report unauthorized charges, and catching them early is what keeps your exposure minimal.
- Skip the RFID-blocking wallet. The dynamic cryptogram already renders captured data useless, so the product is aimed at a fear that doesn’t match the actual threat. An ordinary aluminum-lined sleeve works if you want one anyway, but it’s solving a theoretical problem.
If Fraud Does Happen Anyway
Federal law caps what you can lose. Under the Truth in Lending Act, liability for unauthorized credit card charges tops out at $50, and every major issuer waives even that with a zero-liability policy.3Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card Debit cards fall under the Electronic Fund Transfer Act, and the numbers get worse the longer you wait: $50 if you report within two business days, up to $500 if you report after two business days but within 60 days of your statement, and potentially the full loss if you wait longer than that.4Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability A compromised debit card also drains real money from your account while the bank investigates, which is the practical reason to reach for credit when you tap.
Contactless cards were designed with skimming in mind. The one-time cryptogram is the reason this particular attack has never scaled into a real-world problem, and it’s why the agencies warning consumers about card fraud point them toward tapping rather than away from it.