That little gold square on your card is not decoration. It is a tiny computer, and it exists for one purpose: to make a stolen copy of your card worthless. Here is how a chip turns a payment into a one-time secret handshake, why the old magnetic stripe could be copied in seconds, and where fraud still gets through.
The day cards stopped being copyable
Years ago I sat in a meeting with a fraud team at a mid-sized bank. A chart on the wall showed counterfeit card losses climbing for a decade. Then, a few months after chip cards went mainstream in a particular market, the line bent downward. Nobody in the room had changed their software or hired a hundred investigators. The only difference was a small piece of hardware inside the card.
Most people use the chip every day without ever wondering what it does. They insert the card, wait a moment, type a PIN, and carry on. In those few seconds, though, a carefully designed conversation takes place between the card, the terminal and your bank, and it is built so that anything a thief overhears is useless.
This article explains that conversation in plain language. You will learn why the magnetic stripe was easy to copy, what the chip does differently, how a one-time code defeats replay attacks, and what the chip cannot protect against. There are small interactive parts, real-world scenarios, a quiz and an FAQ.
The short answer. A magnetic stripe stores fixed data that can be copied and reused. A chip stores a secret key that never leaves it, and uses that key to create a fresh, one-time code for every payment. A copy of one transaction cannot be reused for another.
How the old magnetic stripe worked (and why it failed)
The magnetic stripe on the back of a card is a strip of tiny magnetised particles. It stores a short block of data: your card number, expiry date and a few service codes. When you swipe it, the reader simply reads that data out and sends it to the bank.
The critical weakness is that the data is static. It is the same on Monday as on Friday, at a petrol station as at a restaurant. Anything that can read it once can write it onto another card, because the card has no way of proving it is the original. It simply says the same words every time.
Think of it as showing a photocopy-able ID. If a stranger photocopies your ID card while you are not looking, the copy looks as good as the original to anyone who only checks the print. Criminals used devices called skimmers, hidden in card slots at ATMs, fuel pumps and ticket machines, to capture exactly this fixed data, then wrote it onto blank cards. This is what “cloning” means.
What the chip actually is
The standard behind chip cards is called EMV, named after its founders: Europay, Mastercard and Visa. Inside that gold plate is a tiny secure microcontroller, a very small computer with its own processor and memory, designed to resist tampering.
It does three jobs a stripe never could:
- It stores a secret key that is built into the chip during manufacturing and is not designed to be read out. Only the card and the issuing bank know it.
- It does calculations using that key. The terminal asks a question, and the chip works out an answer that only the real card could produce.
- It counts. The chip keeps a transaction counter that goes up with every use, so no two payments look alike.
The crucial design principle is simple: the secret never leaves the chip. The terminal does not read the key. It only receives the results of calculations done with it. A recording of those results does not reveal the key, just as hearing someone’s signed answers does not reveal their private pen.
The one-time code: the cryptogram
When you pay, the terminal sends the chip the details of the sale: the amount, the currency, the date and a fresh random number it just generated. The chip mixes these with its internal counter and its secret key and produces a short code called a cryptogram.
Your bank, which also holds the matching key material, performs the same calculation on its side. If the answer matches the cryptogram, the bank knows two things: the card is genuine, and the transaction details were not altered along the way. Change the amount by a rupee and the cryptogram no longer matches.
Because the terminal generates a new random number every time, and the chip’s counter keeps climbing, the cryptogram is different for every payment, even when you buy the same coffee at the same shop for the same price. A recorded cryptogram is a receipt for one specific event. It cannot be reused for a different purchase.
A toy version you can follow with a calculator
Real chips use serious cryptography, such as 3DES or AES-based message authentication codes. To make the idea visible, here is a deliberately simple toy version. Pretend the card’s secret key is 7, and the cryptogram is calculated as:
Here are four purchases by the same card with the same secret key.
| Counter | Amount | Terminal random | Cryptogram |
|---|---|---|---|
| 41 | ₹450 | 38 | 35 |
| 42 | ₹1,299 | 71 | 10 |
| 43 | ₹4,999 | 15 | 65 |
| 44 | ₹450 | 62 | 1 |
Look at the first and last rows. Both are purchases of ₹450, yet the cryptograms differ, because the counter and the terminal’s random number changed. Now imagine a thief recorded the ₹4,999 purchase, where the cryptogram was 65, and tries to reuse it for a new ₹4,999 purchase. The new terminal produces a different random number, and the bank expects the counter to have moved on. The bank calculates 85. That does not match 65, so the replay is declined.
Even this toy shows the heart of the matter: the proof of a payment is bound to that one payment. Real systems add much stronger maths so nobody can work backwards to the key, but the logic is the same.
The five steps of a chip payment
- Step 1: the terminal tells the card the details of the sale and a fresh random number.
- Step 2: the chip signs those details with its secret key, producing a cryptogram.
- Step 3: the terminal forwards the cryptogram to your bank.
- Step 4: the bank recomputes it, checks your balance and fraud rules, and approves or declines.
- Step 5: the approval comes back, and the transaction completes.
Notice what travels across the network. It is the transaction details and a cryptogram, not a reusable secret. A thief who taps into the cable, or plants a device inside the terminal, captures a record of a finished event.
Proving the card itself is real
There is a second layer. Terminals also check that the chip is a genuine card issued by a real bank, and not a clever fake that merely answers questions. EMV does this with digital signatures. The card carries data signed by the issuer, and the terminal can verify that signature using a chain of trusted certificates.
Different cards support different strengths of this check. The simplest, called static data authentication, proves that the card’s data was signed by the issuer. The stronger methods, dynamic and combined data authentication, make the card create its own signature for each transaction using a unique key pair inside the chip. A copy of the card data cannot do that, because the private key never leaves the original chip. For beginners, the takeaway is this: modern cards do not just claim to be real, they prove it, freshly, every time.
Proving you are the right person: PIN and friends
Authenticating the card is not the same as authenticating the cardholder. For that, chip cards support several methods.
- Chip and PIN: you type a PIN. It is checked either by the chip itself or by your bank. Because the PIN is secret, a stolen card alone is much less useful.
- Chip and signature: you sign a slip or screen. This is weaker and has been fading in many countries.
- No verification: small contactless taps are often allowed without a PIN, up to a limit set by the bank and local rules.
In India, the Reserve Bank of India directed banks to migrate magnetic stripe cards to EMV chip and PIN cards by the end of 2018, and later rules gave cardholders control over how a card can be used, for example switching online, international or contactless use on and off in the bank’s app. Limits and rules do change, so check your own bank’s current settings.
How the world moved to chips
The EMV standard was developed in the mid-1990s, and countries adopted it at different speeds. Several European markets moved first, with the UK rolling out chip and PIN in the mid-2000s. The United States was later, and a key push was the “liability shift” in October 2015: after that date, for most in-store payments, whichever side of the transaction had not upgraded (the merchant or the card issuer) became financially responsible for counterfeit fraud. That is a business rule rather than a technology, but it changed behaviour overnight, because shops that ignored chip terminals suddenly carried the cost.
Industry bodies in countries that completed the migration generally reported steep falls in counterfeit card fraud afterwards. I will not quote single numbers here because they vary by country and year, but the pattern was consistent: fraud on cloned physical cards dropped.
Real situations: where the chip helps and where it does not
Tap through six everyday situations to see what the chip is doing in each.
Tap at a cafe
You tap your card on a reader for a ₹180 coffee. Nothing is inserted and nothing is swiped.
What is happening. Contactless payments use the same chip, powered by the reader’s radio field over a few centimetres. The chip still creates a one-time cryptogram. Intercepting it gives a thief a code useful for one transaction only. Limits for no-PIN taps exist as a safety net, and banks set them, so check yours.
Insert and PIN
You insert your card at a shop and type your four- or six-digit PIN for a ₹12,000 purchase.
What is happening. Two things are checked: the card is genuine (the chip answers the cryptogram challenge) and the person holds the secret (the PIN). A stolen card without the PIN is far less useful, and a copied card cannot answer the chip’s challenge at all.
Old stripe swipe
A small shop with an old terminal asks you to swipe the stripe, or the chip reader fails and falls back to the stripe.
What is happening. This is the weak spot. A stripe holds fixed data, so a hidden skimmer that records it can write the same data onto a blank card. Banks watch for “fallback” transactions closely. If a chip reader keeps failing, treat it as a reason to pay another way.
Online shopping
You pay for shoes on a website by typing the card number, expiry and CVV.
What is happening. The chip is not involved, so it cannot protect you. Criminals who steal card numbers from breached websites or phishing pages use them online. That is why banks add one-time passwords, app approvals and card controls. After chips arrived in many countries, fraud shifted from counterfeit cards toward online use.
Petrol pump abroad
You travel and fill the tank at an unattended pump that has an older reader.
What is happening. Unattended terminals such as pumps and ticket machines were among the last to be upgraded in several countries, and they are easier for criminals to tamper with. Choose an attended counter when you can, and use a phone wallet, which adds its own protections.
Lost or stolen card
You realise your wallet is gone after a busy day.
What is happening. Block the card in your bank’s app or helpline immediately. A chip stops copying, but it does not stop a thief from spending small amounts by tapping, so speed matters. Prompt reporting also protects you under most banks’ fraud rules.
Notice the pattern. The chip is strongest where it is actually used: insert or tap on a modern terminal. It is weakest where it is bypassed, which is on a magnetic stripe fallback and in online payments where you type your card number.
Where fraud went next
Security is a moving target. When you make one door hard to open, determined criminals look for another. After chips became common, three weak points became more attractive.
1. Card-not-present fraud
When you buy online, the chip is not part of the process. The website receives a card number, an expiry date and a security code, all of which can be stolen from a breached merchant, a phishing page or a malicious script. Banks respond with one-time passwords, app approvals, risk scoring and virtual card numbers. Many countries saw online fraud take up a larger share of the total as in-store counterfeiting shrank.
2. Magnetic stripe fallback
Some cards still carry a stripe so they work on old terminals. A terminal that cannot read the chip may offer a swipe instead. Criminals sometimes try to force that fallback, for example by damaging a card, so issuers treat fallback transactions with suspicion and may decline them. If a chip reader keeps failing on your card at a shop, the sensible response is to pay another way, not to swipe.
3. Social engineering
No chip can stop you from reading out a one-time password to a stranger posing as your bank. Scams that trick people into approving payments themselves are among the fastest-growing problems, because the technology cannot tell a genuine you from a convincing story. Your bank will never ask you to share a PIN or OTP, so any call that does is a red flag.
Contactless and phone wallets: the same idea, one step further
Tapping a card works through short-range radio, and the chip behind it still creates a one-time cryptogram. Phone wallets add another layer called tokenisation: instead of your real card number, the phone stores a substitute number valid only for that device. If a merchant’s systems are breached, the thief gets a token that is useless elsewhere. Pairing this with your fingerprint or face unlock means a payment needs something you have and something you are.
That is why security people often suggest a phone wallet for travel or for unfamiliar shops. It combines the chip’s protection with tokenisation and biometric confirmation.
Eight habits that keep your card safe
- Insert or tap rather than swipe whenever a chip option exists.
- Cover the keypad when you type your PIN. Hidden cameras still work against humans.
- Turn on instant alerts for every transaction in your bank’s app.
- Use card controls to disable online, international or contactless use when you do not need them.
- Prefer wallets or virtual cards for online purchases and unfamiliar sites.
- Look at the terminal. Loose parts, odd overlays or a card slot that wobbles are warning signs, especially at unattended machines.
- Never share OTPs or PINs, even with someone who sounds official.
- Report loss at once. Block the card in the app first, then call the bank.
Six common myths (tap to open)
1. “A chip makes my card unhackable”
It makes physical cloning far harder, but it does nothing against stolen card numbers used online, scams that trick you, or a stripe fallback on an old terminal.
2. “Someone can copy my chip by standing near me”
Contactless chips talk only over a few centimetres, and even a recorded exchange gives a one-time code that cannot be reused for another purchase.
3. “The chip stores my PIN where thieves can read it”
Cards are designed so the PIN and keys are not readable from outside. Verification happens inside the chip or at your bank.
4. “If the cryptogram is stolen, they can spend my money”
A stolen cryptogram belongs to one transaction. Replaying it fails because the bank expects a different value each time.
5. “Contactless is always unsafe”
It uses the same chip security. The practical risk is small unauthorised taps if the card is stolen, which alerts, limits and quick blocking handle.
6. “Chips ended card fraud”
They ended much of the easy fraud and pushed criminals toward online and social-engineering methods, so vigilance still matters.
Quick quiz: test yourself
Tap each question to reveal the answer and the reasoning behind it.
Why can a magnetic stripe be cloned easily?
- It uses too much power
- It stores fixed data that is the same every time
- It has no number printed on it
- It only works abroad
The stripe holds static data. Anyone who reads it can write the same data onto another card.
What does the chip create for every transaction?
- A new card number
- A photograph
- A one-time cryptogram
- A new PIN
The chip combines transaction details and a counter with its secret key to produce a cryptogram that is valid only for that transaction.
A thief records the cryptogram from your ₹4,999 purchase and tries to reuse it. What happens?
- The bank rejects it because the transaction details and counter do not match
- The bank approves it
- The chip refunds you
- The card number changes
The expected cryptogram depends on the amount, the random number and the counter. A replay does not match, so it is declined.
Which type of fraud did chips NOT stop?
- Counterfeit in-store cards
- Skimmed copies used at chip terminals
- Lost cards used with a PIN check
- Card-not-present fraud online
Online payments do not use the chip, so stolen card numbers can still be misused there. Banks add extra checks such as one-time passwords.
Where does the chip’s secret key live?
- On the printed card number
- Inside the chip, never sent out
- On the terminal
- On the receipt
The key stays inside the chip’s secure hardware (and in the bank’s secure systems). Only results of calculations leave the chip.
Frequently asked questions
How does a chip stop card cloning?
The chip holds a secret key that never leaves it, and uses that key to create a fresh one-time cryptogram for each payment. A thief who records the exchange gets a code that works for that transaction only, and cannot copy the key.
Can chip cards be cloned at all?
Copying the secret key out of a modern chip is not practical for ordinary criminals. The realistic weak points are fallback to the magnetic stripe, tampered terminals and online card-number theft, which is why the stripe is still a risk.
Why do cards still have a magnetic stripe?
For backwards compatibility with older terminals, mainly outside countries that completed migration. As terminals upgrade, many issuers are moving toward cards without one.
Is contactless payment safe?
Contactless uses the same chip and cryptogram idea. The main risk is small unauthorised taps if a card is stolen, so keep the limits sensible, enable alerts and report loss quickly.
What is the difference between chip and PIN and chip and signature?
Both use the chip to prove the card is genuine. They differ in how the cardholder is verified: a PIN that only you know, or a signature, which is weaker and less used today.
Does a chip protect online purchases?
Not directly, because the chip is not used when you type your card details into a website. Protection comes from extra authentication such as one-time passwords, app approvals, tokenised wallets and virtual cards.
The takeaway
A magnetic stripe says the same thing every time, so anyone who hears it can repeat it. A chip answers a fresh question every time, using a secret that never leaves the card, so a recording is useless. That is the whole trick: replace a fixed password with a one-time proof.
The chip is not magic. It stops physical cloning, but not stolen numbers online or a convincing phone call. Use the chip, switch on alerts and treat OTPs as secrets, and you will have taken advantage of nearly everything this clever piece of engineering offers.
