
The payment card for refugees has been a hotly debated topic for years. It is intended to ensure that refugees do not receive cash directly from local authorities, but that all purchases and transactions are carried out exclusively via a prepaid credit card, or that cash can only be withdrawn from cash machines. There is criticism of the payment card; for example, extensive restrictions (on cash withdrawals, online purchases and bank transfers) are criticised, and it is argued that this jeopardises the right to a decent minimum standard of living. For these reasons, the Society for Civil Liberties is taking legal action against the payment card in several cases.
Gradual introduction across the federal states
The payment card for refugees has been in use in every federal state in Germany since May 2024 and is being rolled out on an ongoing basis. The federal states had previously agreed on corresponding minimum requirements. However, the Asylum Seekers’ Benefits Act (AsylbLG) does not set out any specific requirements regarding the functioning or configuration of the payment card. The specific implementation is the responsibility of the federal states, and there are, in some cases, considerable differences. In some federal states, any amount of cash may be withdrawn, whilst in others, a maximum of €50 per month per person is permitted (in some cases with extremely high additional fees for cash withdrawals). In some federal states, online purchases are strictly prohibited, whilst in others they are permitted subject to checks.
Ethical IT security research uncovers flaws in payment card
Back in April 2024, our employees Tim Philipp Schäfers and Niklas Klee took a closer look at the payment card for refugees and the associated apps, and published a 39-page security report on the subject. The report contains findings on vulnerabilities and data protection issues present at the time in the various solutions, which were responsibly reported to the manufacturers. Among other things, it was found that unique identifiers of devices in use (AdvertisingIDs) were being transmitted to big tech companies such as Google or Facebook without consent. Furthermore, there were serious security vulnerabilities, such as XSS (Cross-Site Scripting), in the solutions.
At the time, the report was covered by Netzpolitik.org, golem.de and fragdenstaat.de. There was also a feature on the topic on WDR.
Tim and Niklas also gave a talk in May 2024 at the Chaos Computer Club’s ‘Gulaschprogrammiernacht 22’ in Karlsruhe, where they presented their findings. The full talk can be viewed here: Click here

Recent coverage in Kohero magazine
Journalists Jessica Chen and Lucia Junker took a closer look at the implementation of the payment card for refugees in Hamburg. They also interviewed Tim and Niklas about the investigation at the time. As a result, an interview about the payment card – including the shortcomings highlighted at the time – and a report on the payment card in general have recently been published in the migrant and charitable magazine Kohero.
The full interview can be read here (after completing a free login): Click here
There is also a more comprehensive report on the payment card (in Hamburg) and the criticism levelled at it (after free login) available to read: Click here
Mint Secure GmbH

How Mint Secure supports you in this
Independent, ethical security research is particularly needed for sensitive, socially relevant IT systems such as the payment card for refugees. We support this with the following services:
Responsible security research
We identify vulnerabilities in apps and systems and report them to the manufacturers in accordance with the principles of Responsible Disclosure.
App & API security audits
We test apps and interfaces used by public bodies for tracking, data protection and security vulnerabilities such as XSS.
Advice for local authorities and public bodies
We advise local authorities and government bodies on the secure and data-protection-compliant design of digital social benefits systems.
Want to get started? We offer a free initial consultation.
Get in touch now.
Conclusion
The payment card for refugees serves as a prime example of how important independent IT security research is for projects involving sensitive digital policy issues. The vulnerabilities uncovered in 2024 and the non-consensual tracking via advertising IDs make it clear that even systems with a public mandate must be carefully scrutinised.
The ongoing media and legal debate surrounding the payment card also shows that technical and societal issues are closely intertwined in such projects.
Mint Secure continues to address digital policy topics through ethical IT security research.
Please get in touch.

