The solution
Security researcher Samy Kamkar discovered that when an American Express card is reported stolen, the replacement card's number could be predicted from the original — and the replacement's expiration date too, inferred from the date the old card was cancelled. 'The day that card is cancelled, as soon as it gets rejected, two seconds later I know what your new number and expiration date will be,' he told WIRED in 2015. 'If I were doing fraud, that would be pretty useful.' The trick could repeat forever, stealing new card numbers as fast as AmEx could issue them.
Three months after flagging it, Kamkar had built the proof: MagSpoof, a watch-sized device costing about $10, which implements his prediction algorithm and can spoof a card's magnetic stripe wirelessly at standard readers. If a spoofed card is declined — the telltale sign it was cancelled — pressing a button switches the device to the predicted next number. A fraudster could then steal the replacement almost instantly, over and over.
Limitations were real: the attack can't get the four-digit CVV, and MagSpoof doesn't look like a card. But Kamkar showed a digital card device like Coin could store the predicted numbers, making the trick presentable to a waiter; he demonstrated successful MagSpoof transactions at two restaurants, including a high-end one where he spent over $100. Coin responded that its security steps — SSN digits and billing zip verification — prevent fraud, which Kamkar disputed ahead of a Kiwicon talk on defeating them.
American Express declined to treat the predictability as a fixable risk. After Kamkar's repeated contacts, an AmEx engineer assured him in an hour-long discussion that predictable numbers weren't a serious security risk the company planned to fix. A spokesperson added that AmEx users were protected by an extra security code embedded in the magstripe data — which Kamkar confirmed blocked the attack in some cases — and by the chip-and-PIN rollout, noting the security code 'changes with the card number and is impossible to predict.'
Why it worked
The insight inverts an assumption baked into card policy: reissue — the universal response to a stolen number — is only a reset if the new number is unpredictable.
The attack loop is self-feeding: each decline reveals the cancellation, each cancellation reveals the next number, so one compromised card never stops compromising.
MagSpoof made the theory cheap and physical: $10 of hardware turns a prediction algorithm into a working payment spoof demonstrated at real restaurants.
The vendor's response — an engineer ruling the flaw not worth fixing — makes the case a study in how institutions price unglamorous risks.
What can be applied
Any security rotation that is deterministic is not rotation: if defenders can compute the next secret, so can attackers — and the fix has to be entropy, not procedure.
Aftermath
AmEx publicly leaned on its magstripe security code and EMV chip rollout as mitigations rather than changing its number-generation scheme. Kamkar continued the research with a planned Kiwicon talk on defeating Coin's verification. WIRED published the findings on November 24, 2015.
FOLLOW THE EVIDENCE