Here's How Researchers Stole $10,000 From MKBHD's Locked iPhone

· MacRumors ·

4 min read Original article ↗

An iPhone exploit that involves a linked Visa card can allow attackers to steal money from a locked device using NFC, but the process is complex, requiring physical access and specialized hardware. The exploit was highlighted by popular YouTube channel Veritasium, and it involves tricking an iPhone into thinking it's making a payment at a mass transit terminal, a process that can be completed from a locked iPhone.

Cybersecurity researchers from the University of Surrey and the University of Birmingham developed the attack to bypass an iPhone's locked status and steal funds from a mobile wallet. The exploit was first publicized in 2021, and it bypasses traditional limits on transaction size. Veritasium demonstrated the attack by collecting $10,000 from YouTuber Marques Brownlee's locked iPhone.

The attack works using an NFC card reader that intercepts the communication between an iPhone and a tap-to-pay terminal when a payment is made. The card reader is connected to a laptop that collects payment data and sends it to a separate burner phone, which is then tapped on a legitimate card reader. The NFC device has to be tuned to the same transit terminal identifier as a legitimate transit reader.

The process requires the victim to have Express Transit Mode enabled for payments, and a Visa card linked for those payments, among other steps. As it turns out, it's a Visa-related security loophole rather than an iPhone issue, and it doesn't work with a Mastercard or an American Express card because other cards use different security methods. It also doesn't work with Samsung Pay on Samsung devices, and it requires the specific combination of a Visa card and an iPhone. Apple told Veritasium that it's an issue with the Visa system, but something unlikely to occur in the real world.

This is a concern with the Visa system, but Visa does not believe this kind of fraud is likely to take place in the real world. Visa has made it clear that their cardholders are protected by Visa's zero liability policy.

Visa also told Veritasium that the exploit was very unlikely from a scaled real world setting, and any such transactions can be disputed. The researchers who shared the exploit said users can protect themselves by not using a Visa card on the iPhone for transit purposes.

Popular Stories

New Apple TV 4K Leaked

Friday September 25, 2026 8:16 am PDT by

MacRumors contributor Aaron Perris has uncovered an image file from Apple for an unreleased Apple TV 4K, suggesting that a new model will finally be released soon. The image is specifically for an "Apple TV 4K (4th generation)" model. Apple TV 4K (4th generation) image (on a gradient) The image reveals that the Apple TV will have the same external design as the current model, with all of its...

Amazon Just Knocked $900 Off Apple's Latest 16-Inch MacBook Pro

Amazon has introduced a major discount on the 16-inch MacBook Pro with the M5 Max chip, 32-Core GPU, 36GB RAM, and 2TB SSD, now available for $3,499.00, down from $4,399.00. This is a massive $900 markdown on the high-end MacBook Pro, and it's joining a few other MacBook Pro discounts on Amazon this week. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a...

iPad Mini 8 Leaked: A20 Pro Chip, Landscape Camera, and More

Apple's next-generation iPad mini will feature the A20 Pro chip, a rearranged front-facing camera, and a new speaker system, leaked code reveals. The information originates from Apple's own code (spotted by MacRumors contributor Aaron Perris) and also shows clear product images of the new iPad mini. Although images of the device only show the front, leaving any design changes of the rear or ...