Mobile Wallets: Security, Tokens and Liability
A mobile wallet replaces the number with a token and requires authentication: check who is liable in case of fraud.
Published 2026-07-21

Paying with a phone worries mostly those who have never done it, and the mechanics deserve to be known before being judged: the mobile wallet never transmits the card number but a token tied to the device, unusable anywhere else, which the merchant can neither see nor store — making mobile payment more discreet than the plastic card itself. Every transaction additionally requires authentication on the device, fingerprint or code, where the contactless card asks for nothing below a certain amount. The useful preparation fits in two steps: enabling location and remote lock, which allow wiping the wallet from a lost phone through any browser, and noting the issuer's number for quick reporting. Liability follows the card agreement's rules, prompt reporting in support. This article explains the token mechanics, the complete security setup and the procedure for the day the phone disappears.
Understand the token replacing the number
A mobile wallet does not store your card number and does not transmit it to the merchant: it uses a token, a distinct identifier generated for your device, unusable anywhere else. The merchant receives that token, the payment network translates it, and your real number never circulates. That architecture makes mobile payment structurally more discreet than the physical card, whose number is printed on the plastic and handed to every merchant. A data breach at a merchant that received tokens does not compromise your card: stolen tokens are useless outside the device that generated them.
Require authentication at every payment
Security's second pillar is local authentication: fingerprint, facial recognition or code, demanded by the device before each transaction. That verification has no equivalent on the contactless card, which pays without asking anything below a set amount. A stolen, locked phone therefore pays for nothing, while a stolen card works until it is reported. The configuration deserves a check: the automatic screen lock should be short, the passcode strong, and biometric authentication enabled for payments. A device without a passcode cancels most of this protection, turning the mobile wallet into a permanent contactless card.
Prepare remote locking in advance
The function that matters on the day of a loss gets activated before the loss: location and remote lock, offered by the major mobile systems, allow locking the device from any browser, displaying a message and wiping the wallet. That setup takes five minutes and gets tested once to confirm it works and that you know the necessary credentials. The issuer's number is noted in parallel, somewhere other than the phone: prompt reporting remains a contractual obligation, and finding the number on the vanished device obviously does not work. These two preparations turn a loss into an administrative inconvenience.
Know your recourse for unauthorized transactions
An unauthorized transaction made through a mobile wallet is disputed like any card transaction: the agreement's rules apply, with prompt reporting as the central condition. The token actually helps the investigation, each device having its own identifier in the system, which allows distinguishing a transaction made by your phone from one made with the card number. Deactivating the token can be requested from the issuer without cancelling the physical card, useful when only the device is compromised. The usual documentation applies: reporting date, file number, chronology of exchanges — a file that speed rarely makes necessary but that protects when it is needed at all.
Quebec scenario: compare before confirming
His daughter set up mobile payments for him over the holidays; since then, a retiree in Chambly pays for groceries with his phone, half-amazed, half-worried. The worry fits in one question: what if the phone is stolen? The advisor at his caisse shows him what actually travels during a payment: never his card number, but a token, an identifier tied to the device, unusable anywhere else; the merchant neither sees nor stores the real number, which makes the mobile wallet more discreet than the plastic card itself. Every transaction also requires authentication on the device, fingerprint or code, where the tap of a contactless card asks for nothing below a certain amount. Two preparation steps remain, done together in ten minutes: enabling location and remote lock, which allow wiping the wallet from a lost phone through any browser, and noting the issuer's number for quick reporting. Liability follows the rules of his card agreement: an unauthorized transaction is disputed the same way, and prompt reporting remains the condition to honour. The following month, the phone forgotten in a grocery cart comes back to the counter within twenty minutes, locked, wallet intact. The demonstration proved more convincing than any explanation.
Checklist
- Understand the token replacing the number
- Enable the device's required authentication
- Enable location and remote lock
- Test the remote wipe once
- Note the issuer's number for reporting
- Lock the phone the moment it disappears
- Report any doubtful transaction quickly
- Dispute under the card agreement
- Keep the device's system updated
Frequently asked questions
Does the merchant see my card number when I pay by phone?
No: the mobile wallet transmits a token tied to the device, unusable anywhere else, and the merchant neither sees nor stores the real number. On that front, mobile payment is more discreet than the plastic card itself, whose number travels with every transaction.
What should I do if my phone is lost or stolen?
Lock and wipe remotely — a function to enable before the incident: from any browser, the wallet empties off a missing phone. With every payment requiring the device's authentication, fingerprint or code, a locked phone pays for nothing. Then report to the issuer.
Who is liable for an unauthorized mobile transaction?
Your card agreement's rules apply, as for any transaction: dispute through the usual process, with prompt reporting as the condition to honour. The token actually helps the investigation, each device carrying its own identifier in the system.