Hacker NewsNews

Hardware Backdoor In Fudan FM11RF08S MIFARE Classic RFID Cards Lets Attackers Clone Hotel Keys And Office Badges Worldwide

A hotel key or office badge that looks like a normal MIFARE Classic card can hide a factory backdoor. In August 2024, Philippe Teuwen of Quarkslab and the Proxmark3 community published the technical write-up and IACR ePrint 2024/1275 on Shanghai Fudan Microelectronics’ FM11RF08S, a 2020 chip sold as the hardened « static encrypted nonce » version of MIFARE Classic. The AEGIS Alliance is keeping this in the hacker file because the fix is not a firmware update. The fix is new plastic.

Hotel RFID door lock and contactless card illustrating the Fudan FM11RF08S MIFARE Classic backdoor risk
The secret key is common to existing FM11RF08S cards and can be abused through supply-chain clones. (DreamStudio AI)

Fuzzing flipped one bit in the command field and moved authentication off KeyA and KeyB onto a hidden key. For FM11RF08S that key is A396EFA4E24F. With it, an attacker who can sit next to the card for a few minutes can recover every diversified user key and clone the badge. Teuwen wrote that the backdoor « allows us to launch new attacks to dump and clone these cards, even if all their keys are properly diversified. » Diversification was the whole sales pitch. Properties were told that even if one room key leaked, the next room would use a different derived key. The silicon backdoor walks around that story. One global key opens the derivation.

The same family of hidden keys showed up on older Fudan FM11RF08, FM11RF32, and FM1208-10 parts, and on some NXP MF1ICS5003/5004 and Infineon SLE66R35 cards that date to the late 1990s and 2000s. A supply-chain clone with the backdoor baked in is enough. Physical proximity is the usual requirement. There is no over-the-air patch. A front desk cannot « update » a Classic-compatible card any more than it can update a stamped metal key. It can only throw the stock away and issue a different chip.

On September 10, 2024, the Proxmark3 Iceman fork shipped v4.18994 « Backdoor » with FM11RF08S helpers such as hf mf isen. That release turned a research paper into a field tool. Community write-ups through 2026 still treat the silicon as live. Keysight and The Hacker News told operators to migrate off Classic-compatible badges. Quarkslab found the chips in hotels across the United States, Europe, and India. Buyers often never see the Fudan part number. They see a white card that works in last decade’s lock.

MIFARE Classic was already a broken protocol before the backdoor. Academic attacks on Crypto1 are old. Static encrypted nonces were supposed to be the cheap retrofit: keep the same readers, change the card, claim resistance to the known card-only attacks. FM11RF08S was that retrofit. The backdoor means the retrofit shipped with a master override. Anyone who knows the constant can dump sectors that a property manager thought were unique. That is a supply-chain story as much as a crypto story. A hotel that ordered « secure » stock from a wholesaler may have received Fudan silicon labeled as a generic Classic card. The lock vendor never opened the card. The brand on the encoder software never listed Shanghai.

The threat model is not a nation-state standing in a lobby with a van. It is a person with a Proxmark or a comparable reader, a few quiet minutes next to a badge left on a cafe table, and a lock that still speaks Classic. Hotel hallways are worse than offices in one way and better in another. Worse: keys are handed to strangers every night and left on nightstands. Better: many chains already moved high-rise and flagship properties to MIFARE DESFire or other AES-backed cards. The leftover risk sits in independent hotels, older office parks, gym turnstiles, and « compatible » stock purchased because it was cheap and fit the installed readers.

Cloning is the product. Once sector keys are recovered, a blank Classic-compatible card can be written to look like the original. The lock does not know the difference. Some systems add a backend check that the card serial has not been reported stolen. Many do not. Even when they do, a clone that keeps the original unique identifier can pass a lazy allow-list. That is why Teuwen’s line about diversified keys still being dumpable is the sentence that should have ended procurement of these chips. A maid’s master, a night auditor’s override, and a contractor’s weekend badge are all the same radio problem if they sit on Classic silicon.

The same contactless stack is already being abused for cash. See The AEGIS Alliance report on NGate Android malware that relays NFC payment cards. NGate turns a victim phone into a relay so an attacker can tap a cloned card at an ATM. Door badges and payment cards are not the same product, but they share a radio band and a public that treats a tap as magic. A reader who understands one should not pretend the other is safe because the logo on the plastic looks official.

What a building owner can do is finite and unglamorous. Inventory the chip, not the print shop. If the card is FM11RF08S or an older Fudan Classic clone, retire it. Move readers to DESFire EV2/EV3 or an equivalent AES card. Stop buying « MIFARE compatible » blanks from the cheapest export lot. Treat a lost badge as a credential incident, not a three-dollar replacement. For hotels, that means cutting over the lockset firmware and the encoder at the desk, not just ordering new artwork. For offices, it means the same badge that opens the garage should not still be a 2008 Classic part hiding under a 2024 lanyard. Security teams that only rotate printed expiration dates are decorating the problem.

Researchers did the industry a favor by publishing the key. They also did thieves a favor. That is how hardware disclosure works. Once the constant is public, pretending it is not public is policy theater. The only remaining control is distance and silicon. Distance means do not leave the badge on a bar. Silicon means stop issuing cards that contain a documented backdoor. Through early September 2026, no Fudan recall that pulls FM11RF08S out of hotel drawers has been posted in a form operators can act on. The cards are still plastic. The backdoor is still in the plastic. Guests who want a practical habit can keep the key in a pocket, not on a restaurant table, and ask the desk whether the property has moved off Classic-compatible stock.

Related coverage on this desk lives in Hacker News and Technology, including the keystroke-exposure file and later breach reporting such as the 700Credit exposure. Those stories are about software and vendors. This one is about a chip that cannot be patched. Until the readers change, the hallway remains a radio problem wearing a hotel logo.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Articles similaires

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Bouton retour en haut de la page
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link