Flipper Zero and RFID cloning: hype versus reality
By Elias Lankinen13 min read
A door that opens in under five seconds
Walk up to a badge reader in an older office building, hold a $169 orange-and-white plastic brick against it, press the down arrow, and the door unlocks. No jammer, no lockpick, no exploit chain. The Flipper Zero read the badge in your other pocket a minute earlier, stored a number, and is now transmitting that number back. That demonstration is real. It is also, in a sense, the least interesting thing about the device — because the same brick held against your hotel room door, your contactless Visa, or your car's key fob mostly does nothing at all. The gap between those two outcomes is where almost every argument about the Flipper Zero goes wrong, in both directions.
The Flipper is a pocket multi-tool for wireless protocols, funded by a 2020 Kickstarter that raised $4.8 million against a $60,000 goal. TechCrunch reported in June 2023 that the company was on track for roughly $80 million in sales that year. It is not a new capability. It is a user interface — a Tamagotchi-shaped front end bolted onto fifteen years of published academic cryptanalysis that previously required a laptop, a soldering iron, and a tolerance for command-line tools. Whether that repackaging matters is a genuinely open question. Whether it invented anything is not.
The clone that genuinely takes five seconds
Start with the part that works, because the hype is downstream of a real vulnerability. A huge fraction of the world's building access badges run at 125 kHz, in what the industry calls low-frequency or "prox" (proximity) technology. The dominant formats are EM4100 (from EM Microelectronic) and HID Prox. Both date to the late 1980s and early 1990s, and both do exactly one thing: when a reader energises the card's coil, the card broadcasts a fixed number. There is no encryption, no challenge-response, no way for the reader to distinguish a real card from anything else transmitting the same bits. Flipper Devices describes this plainly in its own September 2021 technical write-up: low-frequency tags "can only transmit their short ID," and "in most cases, data is not authenticated and it's not protected in any way." The most common HID format, H10301, is 26 bits total: one leading parity bit, an 8-bit facility code, a 16-bit card number, one trailing parity bit. That is a keyspace of about 16.7 million — and in practice a single site uses one facility code, collapsing it to 65,536 possible cards. Some organisations have been successfully attacked simply by guessing. None of this requires a Flipper. The security-camera trade publication IPVM bought a generic 125 kHz copier online for $30 and, in testing first published in 2017 and revised in April 2021, duplicated HID Prox, ISOProx, Prox II, EM4100 and AWID credentials across more than fifteen cards without a single failure. Each copy took under five seconds, and the resulting clones were "indistinguishable from the HID factory original" to the access control system. Blank rewritable T5577 cards cost about a dollar each.
So the honest framing of the Flipper's 125 kHz capability is this: it does something a $30 no-name device has done for a decade, but with a nicer screen, and it also stores hundreds of cards, lets you type in an ID by hand, and fits on a keyring. The vulnerability is in the credential, not the tool. It has been public since before the iPhone existed.
Why it can't lift your badge across a lobby
The single most persistent misconception — the one that powers most viral videos — is that a Flipper Zero can silently harvest cards from bags and pockets as someone walks past. It cannot, and the reason is physics rather than software. Both 125 kHz and 13.56 MHz RFID work by inductive coupling: the reader's coil generates a magnetic field, and the card's coil harvests energy from it. Field strength in the near field falls off roughly with the cube of distance. Doubling the range doesn't require twice the power, it requires something closer to eight times — and the coupling depends on coil area, number of turns, and tuning. The Flipper's antennas have to fit inside a device the size of a pack of cards, wrapped around its own PCB. In practice this means near-contact. Practitioners who compare it against purpose-built kit consistently report a couple of centimetres for reliable low-frequency reads; IPVM's $30 copier needed under an inch. You have to hold the thing against the card. Contrast that with what a dedicated attacker actually uses. Bishop Fox's Tastic RFID Thief, released at DEF CON and Black Hat in 2013, takes a commercial HID MaxiProx 5375 long-range reader — a wall-mounted unit the size of a laptop, drawing mains or battery power through a large tuned antenna — and adds a microcontroller that silently logs every badge it captures to a text file on an SD card. Depending on card and configuration, that reaches one to six feet. Concealed in a clipboard, a briefcase, or a fake delivery box, it is the tool that actually steals credentials from pockets. The Flipper is the opposite of covert. The long-range threat is real; the Flipper is not it.
13.56 MHz, and the cipher that took a decade to die
Above the legacy prox band sits the 13.56 MHz world, and the dominant name there is MIFARE Classic — NXP's contactless smartcard family, launched in 1994, which went on to underpin transit systems, office badges and hotel locks worldwide. NXP has cited figures in the range of ten billion MIFARE ICs shipped across its whole portfolio. MIFARE Classic protects its memory sectors with a proprietary stream cipher called Crypto-1, using 48-bit keys. Both design choices proved fatal. The unravelling started in public in December 2007, when Karsten Nohl and Henryk Plötz presented "MIFARE, Little Security, Despite Obscurity" at the 24th Chaos Communication Congress. They had physically ground down a chip, imaged its logic gates under a microscope, and reconstructed the cipher. The full method appeared in Reverse-Engineering a Cryptographic RFID Tag at USENIX Security in July 2008. Once the algorithm was public, the attacks compounded fast. By the 2009 IEEE Symposium on Security and Privacy, Flavio Garcia, Peter van Rossum, Roel Verdult and Ronny Wichers Schreur published "Wirelessly Pickpocketing a Mifare Classic Card", demonstrating four card-only attacks — no eavesdropped session, no legitimate reader needed — the most serious of which recovered a secret key "in less than a second on ordinary hardware." What the Flipper adds is packaging. It ships with a dictionary of well-known default keys — an embarrassing number of real deployments never changed the factory values — and it implements mfkey32, which recovers keys from the reader rather than the card. Flipper's documentation describes the workflow honestly: the Flipper emulates the card, you tap it against the reader repeatedly until ten nonce pairs are collected, then the on-device app grinds through the Crypto-1 LFSR state. It takes "several minutes" on the Flipper's modest processor. And it frequently fails: "in some cases, the keys can't be recovered from the nonces because the reader won't recognize the Flipper Zero emulation properly." That is the texture the demo videos leave out. Ten taps at a reader you do not control, several minutes of computation, and a meaningful failure rate.
The backdoor nobody put in the datasheet
Two things happened in 2024 that matter more than anything the Flipper itself did. In March, a team including Ian Carroll and Lennert Wouters disclosed Unsaflok: a chained set of vulnerabilities in dormakaba's Saflok electronic locks, installed on roughly three million doors across more than 13,000 properties in 131 countries. By breaking both dormakaba's key-derivation scheme and the underlying MIFARE Classic layer, an attacker holding any keycard from the property — including an expired one from a checked-out room — could forge a pair of cards that opened every door in the building. The flaws had been reported to the vendor in September 2022. At disclosure eighteen months later, the researchers estimated only about 36% of affected locks had been updated. Then in August, Philippe Teuwen of Quarkslab published MIFARE Classic: exposing the static encrypted nonce variant. The target was the FM11RF08S, a MIFARE-compatible chip released in 2020 by Chinese manufacturer Fudan Microelectronics, specifically hardened against every known card-only attack. Teuwen fuzzed the command set and found that flipping a single bit switched authentication from the user's Key A or Key B to a hidden backdoor key — the same key on every FM11RF08S card ever made. Quarkslab's write-up puts the resulting attack at a few minutes of physical access to recover all of a card's user keys, and reports finding these chips in hotels across the US, Europe and India. A related backdoor turned up in the earlier FM11RF08, in FM11RF32 and FM1208-10, and — notably — in some old NXP and Infineon parts. Neither of these is a Flipper story. Both were found with a Proxmark3, and both matter far more to your actual physical security than anything a teenager films in a Walmart.
The tools that professionals actually reach for
The Proxmark3, now in its RDV4 generation with the community-maintained Iceman firmware, is where RFID research happens: raw trace capture, arbitrary protocol fiddling, hardnested and darkside attacks with real compute behind them, swappable tuned antennas. The Chameleon Ultra specialises in high-fidelity emulation. The iCopy-X trades flexibility for speed on the narrow task of duplicating badges in the field. Against these the Flipper is a generalist. Its nested-attack support was ported from Proxmark3. Its 125 kHz protocol handling covers the common cases and not the odd ones. Where a Proxmark gives you the bus, the Flipper gives you a menu — which is exactly why it sold a million units and the Proxmark did not.
What it flatly cannot do
The list of failures is as informative as the list of successes.
- Contactless bank cards. A Flipper can read the card number and expiry from many EMV cards. It cannot clone one. Contactless EMV transactions are authorised by a dynamic cryptogram — a per-transaction value computed by a tamper-resistant chip using a key that never leaves it, bound to an incrementing counter. Replay the same cryptogram and the issuer rejects it. This is the entire architectural point of EMV, and Amazon's April 2023 decision to ban the Flipper as a "card skimming device" was, on the technical merits, simply wrong.
- MIFARE DESFire EV2/EV3. AES-128 with mutual authentication, per-application keys, Common Criteria EAL5+ certification. There is no published card-only break.
- HID Seos and iCLASS SE. AES-based, with per-credential diversified keys. Legacy iCLASS is a different matter entirely — Milosch Meriac's 2010 Heart of Darkness work at 27C3 extracted reader firmware and showed that legacy iCLASS Standard cards worldwide shared a single master key, with the Elite variant's key recoverable from about fifteen authentication attempts. Legacy iCLASS is broken; its successors are not.
- Writing to an unmodified MIFARE Classic. Even with all sixteen sector keys recovered, block 0 holds the UID and is read-only on genuine cards. Cloning requires a "magic" card with a writable UID — an extra purchase, and a card that some readers detect. The recurring pattern: everything designed before roughly 2000 falls, and everything designed after it with a real cryptographic budget holds.
The panic, and the one place it landed near the truth
Regulators have repeatedly tried to legislate the tool rather than the credential. Brazil's telecom regulator Anatel began seizing imported Flipper Zeros in March 2023, refusing certification on the grounds the device facilitates crime. Amazon banned it the following month. Then in February 2024, after a national summit on vehicle theft, Canadian Industry Minister François-Philippe Champagne announced a ban on consumer hacking devices, naming only the Flipper Zero. The technical response was immediate and largely unanimous. The EFF called it a "zero accountability approach to security," and CBC News found security experts arguing the measure would not touch car theft rates. Flipper Devices' own March 19, 2024 response made the hardware argument: the device has a single sub-1 GHz radio, while the relay attacks actually used to steal keyless cars need multiple coordinated radios, and rolling-code fobs defeat naive replay by design. The company stated it was "not aware of any officially confirmed cases of theft using a Flipper Zero." Ottawa softened the proposal in March 2024 to restricting use "to legitimate actors," and no import ban has since been enacted. Where it gets genuinely uncertain is 2025. Custom "DarkWeb" firmware, sold commercially and demonstrated by YouTube channel Talking Sasquach, claims to defeat rolling-code entry on Chrysler, Dodge, Fiat, Ford, Hyundai, Jeep, Kia, Mitsubishi and Subaru vehicles from a single captured signal. The underlying technique is plausible: it appears derived from RollBack, presented at Black Hat USA 2022 by CrySyS Lab researchers, which replays captured signals consecutively to force a fob's counter to resynchronise backwards, without jamming. But the paper itself reports RollBack succeeding against about 70% of tested systems, not all, and the Flipper firmware is closed-source, paid, and has not been independently verified in a peer-reviewed setting. Treat the claim as credible in mechanism and unproven in scope. Note also what it is not: sub-GHz remote keyless entry has nothing to do with RFID. The Flipper's car-theft reputation and its badge-cloning capability live in different subsystems, on different frequencies, and the public conversation merges them constantly.
The install base is the story
The uncomfortable arithmetic is this. Crypto-1 has been broken in public for eighteen years. 125 kHz prox never had security to break. And both are still everywhere, because access control credentials are a capital expenditure with a fifteen-to-twenty-year replacement cycle, and because the readers, the panels, the wiring and the badge printers all have to move together. HID's entire product line of dual-technology "Seos + Prox" cards exists precisely because nobody can rip and replace in one weekend. So the interesting question is not whether the Flipper Zero should be legal. It is why, in 2026, a building can still be entered with a number that a $30 device copied in five seconds — and why the vendor response to Unsaflok left roughly two-thirds of three million hotel doors unpatched eighteen months after disclosure. Here is the reframe worth carrying: the Flipper is best understood as a cheap audit instrument. If it opens your door, you did not discover a new threat. You discovered that your building has been open to a decade-old attack for a decade, and you finally have something pocket-sized enough to prove it to the person who signs the purchase order. What to watch next: whether the FM11RF08S backdoor forces a reckoning among the enormous grey market of unlicensed "MIFARE-compatible" chips, and whether phone-based credentials — which put a secure element and a real key-management story in every pocket — finally break the replacement-cycle deadlock. And whether, when they do, the industry remembers that the last three generations of "secure" credential all looked secure right up until someone put a chip under a microscope.
Sources
- Karsten Nohl, David Evans, Starbug, Henryk Plötz, Reverse-Engineering a Cryptographic RFID Tag, USENIX Security Symposium (2008)
- Flavio D. Garcia, Peter van Rossum, Roel Verdult, Ronny Wichers Schreur, Wirelessly Pickpocketing a Mifare Classic Card, IEEE Symposium on Security and Privacy (2009)
- Milosch Meriac, Heart of Darkness: Exploring the Uncharted Backwaters of HID iCLASS Security, 27th Chaos Communication Congress (2010)
- Philippe Teuwen / Quarkslab, MIFARE Classic: Exposing the Static Encrypted Nonce Variant, IACR ePrint Archive 2024/1275 (2024)
- Quarkslab Blog, MIFARE Classic: exposing the static encrypted nonce variant... and a few hardware backdoors (2024)
- Ian Carroll, Lennert Wouters et al., Unsaflok: Hacking Millions of Hotel Locks (2024)
- Levente Csikor et al., RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems, Black Hat USA / arXiv (2022)
- IPVM, Hack Your Access Control With This $30 HID 125kHz Card Copier (2021)
- Flipper Devices, Diving into RFID Protocols with Flipper Zero (2021)
- Flipper Devices, Recovering MIFARE Classic keys (mfkey32) (accessed 2026)
- Flipper Devices, Our Response to the Canadian Government (2024)
- Bishop Fox, RFID Hacking Attack Tools: Tastic RFID Thief (2013, updated)
- Electronic Frontier Foundation, Restricting Flipper is a Zero Accountability Approach to Security (2024)
- Electronic Frontier Foundation, Flipper Zero Devices Being Seized by Brazil's Telecoms Agency (2023)
- BleepingComputer, Flipper Zero banned by Amazon for being a 'card skimming device' (2023)
- BleepingComputer, Canada to ban the Flipper Zero to stop surge in car thefts (2024)
- CBC News, Banning hacking devices won't prevent car thefts, security experts say (2024)
- TechCrunch, Flipper hacking device on track to make $80M worth of sales (2023)
- RTL-SDR, Flipper Zero DarkWeb Firmware Bypasses Rolling Code Security (2025)
- NXP Semiconductors, MIFARE DESFire EV3 (accessed 2026)