Here's How Researchers Stole $10,000 From MKBHD's Locked iPhone - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Here's How Researchers Stole $10,000 From MKBHD's Locked iPhone

An iPhone exploit that involves a linked Visa card can allow attackers to steal money from a locked device using NFC, but the process is complex, requiring physical access and specialized hardware. The exploit was highlighted by popular YouTube channel Veritasium, and it involves tricking an iPhone into thinking it's making a payment at a mass transit terminal, a process that can be completed from a locked iPhone.


Cybersecurity researchers from the University of Surrey and the University of Birmingham developed the attack to bypass an iPhone's locked status and steal funds from a mobile wallet. The exploit was first publicized in 2021, and it bypasses traditional limits on transaction size. Veritasium demonstrated the attack by collecting $10,000 from YouTuber Marques Brownlee's locked iPhone.

The attack works using an NFC card reader that intercepts the communication between an iPhone and a tap-to-pay terminal when a payment is made. The card reader is connected to a laptop that collects payment data and sends it to a separate burner phone, which is then tapped on a legitimate card reader. The NFC device has to be tuned to the same transit terminal identifier as a legitimate transit reader.

The process requires the victim to have Express Transit Mode enabled for payments, and a Visa card linked for those payments, among other steps. As it turns out, it's a Visa-related security loophole rather than an iPhone issue, and it doesn't work with a Mastercard or an American Express card because other cards use different security methods. It also doesn't work with Samsung Pay on Samsung devices, and it requires the specific combination of a Visa card and an iPhone. Apple told Veritasium that it's an issue with the Visa system, but something unlikely to occur in the real world.

This is a concern with the Visa system, but Visa does not believe this kind of fraud is likely to take place in the real world. Visa has made it clear that their cardholders are protected by Visa's zero liability policy.

Visa also told Veritasium that the exploit was very unlikely from a scaled real world setting, and any such transactions can be disputed. The researchers who shared the exploit said users can protect themselves by not using a Visa card on the iPhone for transit purposes.

Popular Stories

macworld iphone 18 pro colors

iPhone 18 Pro's Four Rumored Colors Revealed, Including 'Dark Cherry'

Friday April 17, 2026 3:50 am PDT by
A source said to be familiar with Apple's supply chain today revealed the color options Apple is planning for the iPhone 18 Pro, iPhone 18 Pro Max, and the upcoming foldable iPhone. Image via Macworld. The information comes from Macworld, which says the signature new color for this year's Pro models will be Dark Cherry, a deep wine-like red. While other sources had previously reported on a...
ipad mini 7 feature red and blue

OLED iPad Mini: Release Date, Pricing, and What to Expect

Wednesday April 15, 2026 8:15 am PDT by
According to the latest rumors, Apple is close to launching its next-generation iPad mini. So what should we expect from the successor to the iPad mini 7 that Apple released over a year ago? Read on to find out. Processor and Performance Apple is working on a next-generation version of the iPad mini (codename J510/J511) that features the A19 Pro chip, according to information found in code...
apple design award 2025

Apple Announces 2025 Design Award Winners Ahead of WWDC 2025

Tuesday June 3, 2025 10:14 am PDT by
As we wait for WWDC to kick off next Monday, Apple today announced the winners of its annual Apple Design Awards, recognizing apps and games for their innovation, ingenuity, and technical achievement. The 2025 Apple Design Award winners are listed below, with one app and one game selected per category: Delight and Fun - CapWords (App) and Balatro (Game) Innovation - Play (App) and PBJ -...

Top Rated Comments

BeatsByTim Avatar
2 days ago at 02:16 pm
They should steal his ability to drive and make YouTube videos next.
Score: 48 Votes (Like | Disagree)
BeatsByTim Avatar
2 days ago at 02:23 pm

Did they return the money?
No. He's broke and living on the street now.
Score: 26 Votes (Like | Disagree)
2 days ago at 02:23 pm
Ok wow, so how is he going to pay his tickets for speeding in a school zone now?
Score: 20 Votes (Like | Disagree)
ikramerica Avatar
2 days ago at 03:09 pm
Change the headline. They stole $10,000 from VISA using a man in the middle and a spoof.

And of course it’s on VISA to explain why there is no limit on a transit transaction. Those $10k subway rides really add up.
Score: 19 Votes (Like | Disagree)
Apple_Robert Avatar
2 days ago at 02:24 pm
This is a non-issue in a typical real world setting.
Score: 15 Votes (Like | Disagree)
BeatsByTim Avatar
2 days ago at 02:19 pm

We’re all fxck’d!
Whoa! Buddy! Come on down off that ledge... I mean... yes. But not because of this.
Score: 14 Votes (Like | Disagree)