You people forget that the public key is visible. Therefore you cannot invalidate the card because you can look up the bitcoin address on blockexplorer.com to see if it has the funds in that the card claims.
Once someone decides to crack open the card, they'll be the first to spend them.
BitBills should include some kind of serial code id number which can be used to verify it on their website. That way you can verify that the card actually came from them. Maybe they could sell POS scanners that verify the tokens when swiped.
Problem is, a counterfeit operation could just add the same serial number to a card with the same public key. So they print everything on the exterior the same, but the private key inside is invalid. They could keep the real card and maintain the balance in the account so anyone checking the balance could see that it has a balance, but they can't actually access the balance because the private key inside of the card is fake.
Very cool, you can even store more of your bitcoins in the bitbill address.
But I think paying directly with them isn't very secure.
Here's an attack:
1) I purchase a bitbill.
2) I put out the stick and scan the private key.
3) I put back the stick
4) I pay with the billbit. When the merchant verifies the bitbill, your server says. "Yes, the 20 btc are still there".
5) I use the private key to extract the bitcoins
Maybe the sticks are so special that make 3 impossible, but I don't think so.
Anyway, It will work great for gift cards and physical storing.
A bitcoin client that imports private keys from IQ-codes would be useful.
The private key can only be accessed by destroying the card. It is literally hidden between layers of plastic. A hologram must be destroyed, and the card has to be cut apart in order to access it. At least, that's how I understand it.