Aren't most mifare carding systems hooked up so transactions are logged, so to detect fraud? Like the australian gocard system for example, isn't every legitimate transaction on the card recorded on an online database somewhere? To exploit a gocard, or similar technology, wouldn't you also need to hack their system database? Eg. taps on to pay; records total transaction value and balance on card<i>; taps off records total transaction value and balance</i>; user rewrites card data<i>; balance on the database isnt updated because a direct payment wasn't recorded</i>; fraudulent card detected; idk correct me HN if I missed anything