I wonder if the BIN/IIN (Bank/Issuer Identification Number[0]) of canary cards give it away. For this to work against sophisticated attackers, I'd expect a canary card to be indistinguishable from a regular one, though I still love the ingenuity of it.
edit: They mention this in the article, I missed it.
edit: They mention this in the article, I missed it.
[0] https://en.wikipedia.org/wiki/Payment_card_number#Issuer_ide...