Mifare Classic - A digression on old vulnerabilities

October 8, 2026

Introduction

Ever since I first came into contact with RFID cards back in 2011 the topic hasn't let go of me. At the time my teachers didn't want me opening doors with them – worried I might get up to do something bad :(

That only made me more curious. I've been digging into the subject ever since and by now I've built up a whole collection of cards from all sorts of manufacturers. Camera

Main part

NXP is one of those microchip manufacturers I personally think is very cool. One of Its company brought a chip to market before the 2000th that is still widely used today: a 13.56 MHz RFID chip based on the ISO 14443A standard with the name Mifare Classic. Because of the nature of these chips an update isn't just a matter of rolling out new software – it usually involves swapping out hardware as well. That's exactly what makes replacing them such a hassle and it's the reason you still find them in use all over the place today. There are companies that clearly aren't familiar with the subject and keep relying on this outdated technology. Since the consequences of that are hard to predict I want to share this with you for doing your own research. At the end there are censored real-world examples for the nerds out there ;)

0 – Publications

Sadly I can no longer find the publication I liked the most but the ones listed still offer a great overview.

link.springer.com, gerhard.dekoninggans.nl pure.tue.nl and eprint.iacr.org

1 – Install the required software

Around the proxmark3 you'll find software that can basically do everything with all kinds of cards – I find it especially handy for identification of card types. Proxmark3Easy

2 – Identify the card with the Proxmark

Place the card on the Proxmark and start the client. Use those commands:

pm3 --> hf search or pm3 --> auto

The device will tell you the type. Keep in Mind at a high frequency Chip might not work when placing it on the low frequency antenna.

4 – Ultra cheap setup for experimenting (advanced users)

This can be used if you want to check nfc-tools more advanced software like "mfoc-hardnested"... I advice to use version 1.7.2 for libnfc Arduino PN532 Module connected via uart using arduinos serial

Where to find Mifare in the real world?

  • There are several water parks in and around Hamburg using Mifare Classic. Some even have lockers based solely on the UID – without checking whether it's actually one of the operator's cards. Even worse: with a master key that opens every single door.
  • Well-known casinos rely on this card standard, with winnings either referenced or written directly onto the cards. On top of that, instead of upgrading the system, proprietary Mifare Classic cards from China were installed – so not the official ones from the manufacturer. FM11RF08
  • Many employee cards are based on the system and until recently some even had credit loaded onto them that you could pay with.

The thing about IT systems is that they're interconnected – and that's exactly what you want. But the impact can be huge: I know of at least one company, for instance, whose employee IDs are publicly viewable. Its called Broken Access Control. That alone is horribly stupid – but combined with the well-known vulnerability of Mifare Classic cards, it means I could recreate any employee card remotely for entering specific buildings. I probably don't need to spell out that this is a bad thing. At this point I hope nobody else ever figures that out.

🏳️‍🌈