"Ghost tapping" — the tap-to-pay pickpocket
Tap-to-pay is safe when *you* can see the amount. "Ghost tapping" is what happens when you can't.
One version is physical: a street seller or "charity collector" insists on tap-to-pay, then keys in a far bigger amount than agreed — or a hidden terminal in a crowd is tapped against your bag. The other is sneakier: a phishing text (a fake delivery fee or "wallet verification") captures your card details plus the one-time code your bank sends — and that code quietly adds *your card to a wallet on the criminal's phone*. From then on they tap and pay with your money, anywhere.
What to do: never share a code your bank texts you — that code IS your card. Always look at the amount on the terminal before you tap, and turn on instant purchase notifications in your banking app so nothing moves without you knowing.
Threat examples
Tap the outlined parts of the message to see the red flags
Your card requires verification to remain active for contactless payments. Enter your card number and the one-time code we send you to confirm your identity: [link]