Contactless payments are encrypted, but the risk isn't zero
Contactless payments—tap your card or phone to pay—use the same encryption that protects chip card transactions. Your card number and expiration date don't transmit to the merchant. Instead, a one-time token unique to that transaction travels between your card and the payment network, making it nearly impossible for someone standing nearby to steal usable card data.
That said, contactless has a specific vulnerability that chip cards don't: someone can read your card from a distance without your knowledge. The range is short—typically a few inches to a foot—but it exists. The real security question isn't whether the technology works, but whether the practical risks match your comfort level and whether your bank's fraud protections cover you if something goes wrong.
Key Takeaways
- Contactless transactions encrypt data the same way chip cards do, so a thief cannot use stolen transaction data to make future purchases.
- Someone with a contactless reader can pull your card number and expiration date from your wallet without your knowledge, though most banks won't hold you liable for fraudulent charges.
- Transaction limits—usually $25 to $100 per tap—reduce the damage from a single unauthorized payment.
- Your bank's fraud protection is your real safety net; check your card's terms to confirm what happens if someone uses your card without permission.
- Contactless payments on phones are more find than contactless cards because they require biometric or PIN verification before the payment goes through.
What happens when your contactless card is read without permission
A contactless card broadcasts your card number, expiration date, and sometimes your name in an unencrypted format during the initial handshake with a reader. Someone with a contactless reader device—which costs under $100 and is legal to own—can capture this information from your wallet or pocket without touching your card or your phone.
Once they have that data, they face a real obstacle: most online retailers and payment processors now require a CVV (the three-digit code on the back of your card) or a billing zip code to complete a purchase. Contactless readers cannot capture the CVV. So a thief would need to either guess it, use your card in person at a merchant that doesn't check it, or sell the data to someone else. The last option is why this kind of fraud is sometimes called "skimming"—the stolen data has value on the dark web even if the thief can't use it directly.
The practical risk depends on where you live and which bank issued your card. In the United States, federal law limits your liability for unauthorized credit card charges to $50, and most major banks waive that entirely. For debit cards, your liability is $50 if you report the fraud within two business days, and up to $500 if you wait longer. Visa and Mastercard's zero-liability policies often cover contactless fraud even more broadly, though you must report it promptly.
Why transaction limits matter more than encryption
Most contactless cards cap each transaction at $25 to $100 without requiring a PIN. This limit is a deliberate security choice: it reduces the damage from a single unauthorized tap. If someone reads your card and makes a contactless purchase, they're limited to that amount per transaction. They could theoretically make multiple purchases, but each one creates a separate record and increases the chance you'll notice the fraud quickly.
The limit resets after you use your card normally—either with a chip, PIN, or online. So if you tap your card at a coffee shop for $6, someone else cannot when ready tap it for $100. The system tracks the running total and requires verification (usually a PIN or chip insertion) once the limit is reached.
This is why contactless fraud, when it happens, tends to be small and caught quickly. A thief stealing $15 to $50 per tap across multiple cards is less likely to be pursued aggressively than someone stealing $500 in a single transaction. The economics of fraud shift when the per-transaction ceiling is low.
Contactless payments on your phone are harder to abuse than contactless cards
Apple Pay, Google Pay, and Samsung Pay add a layer of security that physical contactless cards don't have: they require biometric verification (your fingerprint or face) or a PIN before the payment processes. Someone who steals your phone cannot tap it to pay without unlocking it first. Someone who reads your phone's contactless signal gets encrypted data that's useless without the phone itself.
This is why security researchers generally consider mobile contactless payments safer than contactless cards. The phone is harder to read remotely because the antenna is shielded, and even if someone does read it, they can't complete a transaction without your biometric or PIN.
The tradeoff is that you're trusting your phone's security—your lock screen, your biometric data, your app passwords—rather than just the payment network. If your phone is compromised by malware, a thief might be able to authorize payments without your knowledge. But this is a different risk from contactless skimming, and it requires more effort and technical skill.
What you should actually do to protect yourself
The most practical steps are the ones that work for any card, not just contactless:
- Check your statements monthly. Contactless fraud is usually small and frequent, so catching it early matters.
- Report unauthorized charges to your bank within two business days if you want maximum protection on a debit card. For credit cards, report as soon as you notice.
- Use a contactless card for everyday purchases under $50 rather than for large transactions. Reserve your chip or PIN for bigger purchases where the extra verification step is worth the time.
- If you're concerned about skimming, use a contactless-blocking wallet or sleeve. These are inexpensive and do work, though the real-world risk is low enough that most people don't need one.
- Prefer mobile payments (Apple Pay, Google Pay) over physical contactless cards when you have the option, because they require biometric verification.
How contactless compares to other payment methods
| Payment Method | Can be read remotely | Requires verification per transaction | Typical fraud liability |
|---|---|---|---|
| Contactless card | Yes, within a few feet | No (under transaction limit) | $0–$50 depending on card type and bank |
| Chip card | No | Yes (PIN or signature) | $0–$50 depending on card type and bank |
| Mobile contactless (Apple Pay, Google Pay) | Yes, but encrypted | Yes (biometric or PIN) | $0–$50 depending on card type and bank |
| Magnetic stripe (swipe) | No, but data is on the card | No | $0–$50 depending on card type and bank |
Frequently Asked Questions
Can someone steal my card number just by walking past me with a reader?
Yes, but only if they're within a few inches to a foot of your card, and only if your card is unshielded. They would need a contactless reader device, which is legal to own. However, stealing the card number alone isn't enough to make a purchase online—they'd also need your CVV, which contactless readers cannot capture.
What if I notice a contactless charge I didn't make?
Contact your bank or card issuer when ready. Report it as fraud. Most banks reverse unauthorized charges within one to two business days for credit cards, and within two business days for debit cards if you report promptly. Keep a record of the date, amount, and merchant name.
Is contactless payment safer than swiping my card?
Yes. Swiped magnetic stripe cards expose your full card number and expiration date on the physical card itself, making them easier to clone. Contactless uses encryption and one-time tokens, so the data transmitted is useless for future purchases. Chip cards are equally safe to contactless for in-person use.
Do I have to use contactless if my card has it?
No. You can always insert your chip or swipe instead. If you're uncomfortable with contactless, you can request a card without the feature, though most banks no longer offer that option. You can also use a contactless-blocking sleeve or wallet.
Is Apple Pay safer than my contactless card?
Yes, because it requires your fingerprint or face to authorize the payment. Someone who steals your phone cannot tap it to pay without unlocking it first. Someone who reads your phone's signal gets encrypted data they cannot use without the phone itself.