Starling Bank pushed a weekend app update that retires push-payment tokens after first use at point-of-sale terminals, closing a gap Liverpool trading-standards investigators found when a Baltic Market stall allegedly split one wallet tap into multiple merchant captures without fresh customer authentication.
What broke
Trading standards began probing after three Starling customers reported duplicate charges within seconds on Saturday receipts from a household-goods trader. Forensic copies of terminal logs—shared with the bank under a voluntary industry fraud protocol—showed the same device-bound payment token presented four times while the handset displayed a single “approved” animation. Amounts totaled £186 across micro-tickets designed to stay under contactless velocity limits.
Starling’s initial review found the merchant acquirer had not enforced single-tap token binding on a refurbished Android terminal running outdated kernel software. Wallet tokens meant for one authorisation were cached locally and replayed before the bank’s risk engine received settlement batches, a lag that can stretch to ninety minutes on market-day networks.
What Starling changed
Version 2.84.1, rolled out silently Saturday night, marks in-app push tokens as spent once the Secure Element acknowledges a point-of-sale cryptogram. Customers must unlock the app to regenerate tokens for the next tap unless they fall back to plastic contactless, which still routes through Mastercard’s fresh cryptogram per tap. Starling said the patch does not alter Faster Payments APP flows or reimbursement eligibility under PSR rules.
Push notifications now flag “token reused” declines in real time rather than waiting for end-of-day chargeback windows. Support scripts direct victims to in-app dispute paths distinct from APP scam claims, because the bank classifies terminal replay as merchant-acquirer fraud rather than customer-authorised push payment deception.
Regulatory context
The Payment Systems Regulator exempts merchant acquiring from Confirmation of Payee checks, meaning payee-name mismatch warnings never appear at card terminals. That exemption keeps checkout fast but leaves wallet provisioning as the last inline control. Ombudsman decisions on Apple Pay and Google Pay emphasise that tokens tied to registered devices shift liability toward customers when biometrics are shared; terminal replay attacks sit in a grey zone Starling now addresses at the token layer.
Liverpool City Council’s trading standards team is assessing whether the stall breached Consumer Rights Act fair-trading duties by obscuring split charges. Criminal referrals are not confirmed; the trader’s leaseholder has suspended the unit pending acquirer re-certification.
What is still unknown
Starling has not disclosed how many accounts saw replay attempts beyond the three complainants who triggered the probe. Acquirer identity remains confidential while PCI forensic work continues. It is unclear whether other neobanks using similar token caches were vulnerable; Starling said it shared indicators with UK Finance’s wallet fraud working group Sunday afternoon.
Customers who paid cash after failed taps are not affected. Refunds for confirmed replays post automatically within five days, the bank said, without requiring Mastercard chargeback cycles unless merchants dispute liability.
What customers should check
Starling users should install the latest app build and review Saturday–Sunday market receipts for duplicate merchant IDs with identical authorization codes. “Need help with this transaction” remains the dispute entry point; mention trading-standards reference LV-MKT-0926 if corresponding with investigators.
For wallet hygiene, disable SMS OTP fallbacks where possible and treat repeated terminal beeps as a stop signal—legitimate split baskets require separate customer approvals under the patched flow. Starling reiterated it will never call asking customers to approve token resets over the phone; use in-app chat or 159 if unsure.
Merchant and acquirer pressure
Market operators told InfoHandle they will require terminal attestation certificates before Christmas trading. Acquirers face pressure to push kernel updates to stallholders who bought second-hand hardware during pandemic outdoor trading expansions. Starling’s patch shifts cost toward issuers rather than waiting for acquirer remediation—a choice the bank said prevents further weekend losses while Liverpool’s probe runs.
Comparison with card chargebacks
Starling’s chargeback guidance stresses that Faster Payments sit outside Mastercard’s dispute rails, but contactless replays remain card-scheme territory when plastic is used. The Liverpool case mixed wallet tokens with acquirer batching quirks, illustrating why PSR reimbursement reforms for APP scams do not automatically fix point-of-sale abuse. Trading standards officers said they want acquirers to publish terminal software versions in consumer receipts—a proposal issuers back if it speeds fraud triage without exposing merchant PCI data.
For now, Baltic Market traders received a circular reminding them that repeated taps without customer presence breach lease conditions. Starling customers with other neobanks should still compare app versions; UK Finance has not issued a sector-wide alert, but wallet working-group minutes from Sunday note Starling’s nonce binding as a candidate best practice pending acquirer kernel timelines.








