Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a patch.

KioSoft payment card hack

SEC Consult, a cybersecurity consulting firm under Eviden, says payment solutions company KioSoft took a long time to address a serious vulnerability affecting some of its NFC-based cards.

KioSoft manufactures unattended self-service payment machines, including for laundromats, arcades, vending machines, and car washes. The company is based in Florida and has offices in seven countries around the world. Its website claims it has deployed over 41,000 kiosks and 1.6 million payment terminals across 35 countries. 

SEC Consult researchers discovered back in 2023 that some of KioSoft’s stored-value cards — digital wallets that customers reload for use at specific payment terminals — are affected by a vulnerability (CVE-2025-8699) that can be exploited for free balance top-ups. The hack relies on the fact that the balance is stored locally on the card rather than a secure online database. 

The impacted cards identified by SEC Consult relied on MiFare Classic NFC card technology, which is known to have significant security issues.

Building on the known MiFare card vulnerabilities and analyzing how data is stored on the cards, SEC Consult researchers managed to read data from the card and write data on the card, enabling them to “create money out of thin air”. A hacker can increase the card’s balance to up to $655, but the process can be repeated, SEC Consult’s Johannes Greil told SecurityWeek.

An attacker can conduct an attack using a hardware tool such as the Proxmark, which is designed for RFID security analysis, research and development. The attacker also needs to have some knowledge of the MiFare card vulnerabilities to carry out a hack, Greil explained.

Advertisement. Scroll to continue reading.

SEC Consult published an advisory describing its research this week. The company has made available a detailed timeline of its interaction with KioSoft, revealing that it took the vendor well over a year to release a patch.

The security firm first contacted KioSoft in October 2023, but the vendor was unresponsive until the CERT Coordination Center at the Software Engineering Institute of Carnegie Mellon University became involved. 

SEC Consult claims to have sent many requests for a status update since October 2023, with many going unanswered. The timeline shows that the vendor has requested several extensions to the disclosure deadline, and ultimately informed the security firm that a firmware patch was released in the summer of 2025. The vendor indicated that new hardware would also be rolled out in the future. 

KioSoft refused to provide version numbers of impacted and patched releases, arguing that affected customers would be privately notified, the security firm said. While KioSoft’s products are widely used, the vendor told SEC Consult that most of its solutions do not use the vulnerable MiFare card technology.

SEC Consult no longer has access to the terminals it initially conducted its research on and it could not verify the vendor’s patch. 

KioSoft has not responded to SecurityWeek’s request for comment. 

Related: eSIM Hack Allows for Cloning, Spying

Related: Major Backdoor in Millions of RFID Cards Allows Instant Cloning

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.