Wouldn't the attacker only charge these after charging dozens/hundreds of legitimate customer cards too?
Seems to me this is the wrong solution to the problem this is trying to solve.
Seems to me this is the wrong solution to the problem this is trying to solve.
So if you can find out that one of your canary cards have been tested, you can have some confidence that your whole set has been compromised.