Fudan FM11RF08S Hotel And Office Cards Still Hide A Factory Backdoor, And Proxmark Guides Now Walk Attackers Through The Keys
A hotel keycard that looks like every other white rectangle in a front-desk drawer can be carrying a factory backdoor. In August 2024, Philippe Teuwen of Quarkslab, working with the Proxmark3 community, published the technical note and IACR ePrint 2024/1275 on Shanghai Fudan Microelectronics’ FM11RF08S. The chip, sold from 2020 as the hardened “static encrypted nonce” version of MIFARE Classic, was supposed to survive the card-only attacks that had embarrassed Classic for more than a decade. Teuwen showed that a one-bit change in a command field moves authentication off the property’s Key A and Key B and onto a hidden key. For FM11RF08S that key is A396EFA4E24F. With it, someone who can sit next to the card recovers the diversified user keys and writes a clone. The AEGIS Alliance is keeping this in the hacker file because the repair is not a software patch. The repair is different plastic.
The Quarkslab write-up is blunt about what diversification was supposed to buy. Hotels and offices were told that even if one room key leaked, the next sector would use a derived key, so a single stolen card would not open the building. Teuwen’s line cuts that pitch apart: the backdoor “allows us to launch new attacks to dump and clone these cards, even if all their keys are properly diversified.” One global constant walks around the derivation. The same family of hidden keys turned up on older Fudan parts — FM11RF08, FM11RF32, FM1208-10 — and on some NXP MF1ICS5003 and MF1ICS5004 cards and Infineon SLE66R35 cards that date to the late 1990s and early 2000s. A supply-chain clone with the backdoor baked in is enough. The usual requirement is physical proximity, not a remote exploit. A front desk cannot “update” a Classic-compatible card any more than it can update a stamped brass key.
On September 10, 2024, the Proxmark3 Iceman fork shipped version 4.18994, tagged Backdoor, with FM11RF08S helpers including hf mf isen. That release turned a paper into a field routine. The routine then got harder to ignore. Standard attacks contradict each other on this silicon. Nested authentication complains that the PRNG is not predictable. Static-nested attacks say they see a normal nonce. Hardnested attacks abort because they hit a static encrypted nonce. The chip’s first authentication nonce behaves like a weak generator, while the nested nonce is static and encrypted. Automated scripts die in that gap. In February 2026 the Iceman project merged a manual recovery guide, tested on an RDV4 running firmware 4.20728, that walks an operator from hf mf info through nonce collection, offline candidate generation, and a dictionary check. The author of that guide reported recovering all 32 keys from a hotel card mixing Vingcard, Timelox, and ENKOA encodings after autopwn left three keys unsolved and the recovery script crashed. A research backdoor had become a cookbook for the exact locks still screwed to guest-room doors.
A separate access-control assessment published in June 2026 shows how little some installations needed the cookbook. The card under test was a MIFARE Classic 1K on an FM11RF08S. Every sector still used the factory key FFFFFFFFFFFF. The reader, the assessor found, authenticated on the card’s serial number alone and never read the encrypted sectors. A blank “magic” card with a copied UID would have been enough, even before the backdoor. The backdoor made full key recovery a matter of seconds on a Proxmark regardless of what keys had been set. The organization acknowledged the finding. The write-up said no remediation had been taken at the time it was posted. That is the unglamorous version of a supply-chain failure: not a spy in a lobby, a purchasing order that never asked which chip was inside the laminate.
Keysight and The Hacker News told operators in August 2024 to get off Classic-compatible badges. Quarkslab had already found the Fudan chips in hotels across the United States, Europe, and India. Buyers rarely see the part number. They see a card that works in a lock bought during the last renovation. MIFARE Classic was broken as a cipher long before this backdoor. Academic attacks on CRYPTO1 are old enough to have their own case law. Static encrypted nonces were the cheap retrofit: keep the readers, swap the card, claim resistance to the known card-only attacks. FM11RF08S was that retrofit, shipped with a master override. Anyone who knows the constant can dump sectors a property manager believed were unique to one wing of one hotel.
The practical threat is smaller and more common than a national-security briefing. It is a person with a Proxmark or a comparable reader, a few quiet minutes next to a badge left on a café table or a keycard left on a nightstand, and a lock that still speaks Classic. Hotel hallways are worse than offices in one respect and better in another. Worse, because keys are handed to strangers every night. Better, because many large chains already moved flagship towers onto MIFARE DESFire or another AES-backed card. The leftover risk sits in independent hotels, older office parks, gym turnstiles, parking garages, and any “compatible” stock bought because it was cheap and fit the encoder the desk already owned. Wholesale listings were still advertising hotel key cards on MIFARE Classic 1K in September 2026, alongside DESFire as an optional upgrade. The broken chip is not a museum piece. It is a line item.
Cloning is the product, not a side effect. Once the sector keys are known, a blank Classic-compatible card can be written to look like the original. The lock does not know the difference. Some systems check that a serial number has not been reported stolen. Many do not. A clone that keeps the original UID walks through a lazy allow-list, which is exactly what the June 2026 assessment found in the wild. A housekeeper’s master, a night auditor’s override, and a contractor’s weekend badge are the same radio problem if they sit on this silicon. Losing a card is a credential incident, not a three-dollar reorder from the print shop.
The same contactless habit is already being used for cash, which is why readers of Hacker News should not treat a door badge as a cousin of a payment card that happens to be safe. The AEGIS Alliance report on NGate Android malware describes a relay that lets an attacker tap a victim’s contactless card at an ATM while the real card is still in a pocket. Door credentials and bank cards are different products. They share a radio band and a public that treats a tap as magic. A building that “upgraded” from metal keys to FM11RF08S did not leave the 2000s. It imported them.
What an owner can do is short and expensive in the way that actually works. Inventory the chip, not the artwork. If the card answers as FM11RF08S, or as an older Fudan Classic clone, retire the stock. Move readers to DESFire EV2 or EV3, or to an equivalent AES card the lock vendor will support with a real encoder, not a compatible blank from the cheapest export lot. For a hotel, that means the lock firmware and the front-desk encoder change together. Printing a new logo on the same silicon decorates the problem. For an office, the badge that opens the garage should not still be a 2008 Classic part under a newer lanyard. Treat a lost card as a revoked credential the same day. Guests can do less, but not nothing: keep the card in a pocket rather than on a restaurant table, and ask whether the property has left Classic-compatible stock. A desk that cannot answer has answered.
Publishing the key helped every hotel that was willing to listen, and it helped every thief who already owned a reader. That is how hardware disclosure works. Once the constant is public, pretending it is still a secret is policy theater. No Fudan recall that pulls FM11RF08S cards out of hotel drawers has appeared in a form a night manager can act on. The Proxmark documentation still treats the backdoor as live. The manual guide still recovers hotel keys when the scripts fail. The cards are still plastic. Related reporting on this desk lives in Technology, including the keystroke-exposure file and the 700Credit exposure of car-buyer data. Those are vendor and software failures that can, in principle, be patched. This one cannot. Until the readers change, the hallway is a radio problem wearing a hotel logo.









