Because the world has enough bad news
Veritasium: Veritasium Stole $10,000 from MKBHD's Locked iPhone and Here Is Exactly How

Veritasium Stole $10,000 from MKBHD’s Locked iPhone and Here Is Exactly How

Marques Brownlee set his locked iPhone face-down on what looked like an ordinary payment terminal, and within seconds his phone chimed with a receipt he never approved: $10,000, charged without a password, a fingerprint, or a single glance at his screen. The vulnerability is real, it has been publicly documented since 2021, and it still works today. Understanding how it operates is the first step toward knowing whether your wallet is sitting in the same exposure.

Three lies and one very convincing magic trick

The attack is a classic man-in-the-middle operation built from two pieces of off-the-shelf hardware and a Python script. A device called the Proxmark sits between the target iPhone and a real retail card reader. The phone talks to the Proxmark; the Proxmark relays and modifies the data to a second phone, which then taps the actual reader. The phone and the reader each believe they are speaking directly to each other.

Getting in the middle is, as Veritasium host Henry put it, actually the easy part. The genuinely difficult work is the three bits of data that have to be flipped before the transaction clears.

The first lie unlocks the phone without touching it. Apple’s Express Transit Mode, introduced in 2019, lets commuters tap through subway gates without unlocking their device. Transit readers broadcast a specific code that triggers this mode automatically. Professors Ioana Boureanu and Tom Chothia from the University of Surrey discovered that code by sitting at the London Underground with their laptops and scanning the signals the gates sent to phones. The Proxmark simply rebroadcasts that same code, convincing the iPhone it is standing at a tube station.

The second lie erases the $10,000 figure entirely. To decide whether a transaction is high value and therefore needs a pin or biometric check, the iPhone does not read the dollar amount. It reads a single binary bit the reader attaches to the transaction: 1 for high value, 0 for low. Flipping that one bit from 1 to 0 makes the phone treat a $10,000 charge exactly like a $2 subway fare, and it approves without asking for verification.

The third lie reassures the reader. When the phone responds, it honestly reports that no customer verification was performed. A legitimate reader would reject that response on a high-value charge. So the script intercepts the phone’s reply and flips the relevant bit again, telling the reader that the customer did verify. The reader forwards a clean-looking transaction to the bank, the bank sees what appears to be a verified payment, and the receipt prints.

Why Visa and not MasterCard

The attack requires a specific combination: an iPhone with a Visa card assigned to the Express Transit slot. MasterCard requires an asymmetric cryptographic signature, sometimes called RSA verification, between the card and the reader on every transaction. That signature is tied to the exact transaction data, so a single flipped bit produces a mismatch the reader catches immediately. Visa waives this asymmetric check when the reader is online, relying instead on the bank-level symmetric check. Because the attack keeps the reader online throughout, the asymmetric layer is never invoked, and the three flipped bits sail through unchallenged.

Boureanu and Chothia had informed Apple and Visa privately before making the research public in 2021. Apple’s written response to Veritasium framed it as a Visa system concern. Visa’s representative told the team that the vulnerability is ‘likely within a controlled setting, very unlikely from a scaled real world setting,’ and noted that cardholders are covered by Visa’s zero liability policy if a fraudulent charge does appear.

Henry pressed the Visa representative directly: ‘Would it not be even better to just say this type of fraud is not possible?’ The response pointed to broader fraud statistics: across all in-person card transactions, roughly 2 cents of every $100 is lost to fraud.

The practical fix available to users right now is straightforward: check your Apple Wallet settings and either remove the Visa card from the Express Transit slot or disable Express Transit Mode entirely. Apple turns the feature on by default as soon as a compatible card is added.

The CFO who just wanted a drink

A channel CFO who lives nearby agreed to meet Henry for a drink, unaware that the Proxmark was already running.

Full-circle, Marques Brownlee held a printed receipt marked ‘Credit verified on device, $10,000’ and summed up the experience plainly: ‘I never unlock my phone. I never put in a password. I never did what I would normally do to verify a transaction. It just happened to be on top of that.’

The receipt exists. The money came back. The bit that makes the transaction possible is still set to zero by default.

Looking for more positive news to brighten your day? Browse our latest articles for inspiring happy news stories. #OnlyHappyNews

More Good News