Cloning and Emulating RFID/NFC Cards with Flipper Zero
Cloning and Emulating RFID/NFC Cards with Flipper Zero The Flipper Zero can read, save, and emulate many common RFID and NFC card formats. Useful for testing access systems, making backup copies of your own cards, and research. ⚠️ Legal Notice Only clone/emulate cards you own or have explicit permission to test. Cloning access cards you don't own is illegal in most jurisdictions. This guide is for personal cards and security research only. Supported Formats Reading a Card 125kHz (Low Frequency) 1. Go to 125 kHz RFID on Flipper 2. Hold card to back of Flipper (RFID logo area) 3. Press Read 4. Card type and UID display if successful 5. Save with a descriptive name 13.56MHz (High Frequency / NFC) 1. Go to NFC 2. Press Read 3. Hold card to back of Flipper 4. For MIFARE Classic: Flipper runs a Dictionary Attack to find sector keys - Common keys (0000...., FFFF...., A0A1A2...) tried automatically - Takes 30–90 seconds 5. Save when complete Emulating a Card 1. Open saved card from 125kHz RFID or NFC app 2. Press Emulate 3. Hold Flipper to the reader as you would the real card 4. Works for most 125kHz formats and some NFC formats MIFARE Classic Keys Many MIFARE Classic cards use default or common keys. Flipper's dictionary handles most. For non-standard keys you need a MFKEY32 attack (requires being present during legitimate reads). Tips Gym fobs, hotel keys, office badges — most are EM4100 or HID Prox (125kHz) — read and emulate easily Transit cards — usually DESFire or proprietary — read UID only, cannot clone NFC payment cards — read metadata only, cannot clone (cryptographically protected) Hotel keycards — MIFARE Classic, keys often default — backup your own room card Use Unleashed or Momentum firmware for additional card format support
Related Guides
- How to Hack RFID and NFC with the Flipper Zero: LF, HF, MIFARE, and iButton
- Flipper Zero: Getting Started with BadUSB, Sub-GHz, and NFC
- Flipper Zero — IR, Sub-GHz and NFC Cheat Sheet
- How to Analyze EMV Payment Cards with the Flipper Zero: NFC, APDU Commands, and Security Architecture
- How to Hack Sub-GHz Radios with the Flipper Zero: Protocols, Analysis, and Signal Crafting
- How to Read Bad Blocks on a Flipper Zero — NFC Deep Dive
- How to Use Flipper Zero to Test Smart Lock Vulnerabilities
- Scanning and Logging NFC Tags on the Go with Flipper Zero