{"id":1040644,"date":"2024-08-22T11:41:35","date_gmt":"2024-08-22T18:41:35","guid":{"rendered":"https:\/\/theaegisalliance.com\/?p=1040644"},"modified":"2026-10-05T11:00:06","modified_gmt":"2026-10-05T18:00:06","slug":"hardware-backdoor-found-in-rfid-cards-used-in-offices-and-hotels-all-over-the-world","status":"publish","type":"post","link":"https:\/\/theaegisalliance.com\/fr\/2024\/08\/22\/hardware-backdoor-found-in-rfid-cards-used-in-offices-and-hotels-all-over-the-world\/","title":{"rendered":"Fudan FM11RF08S Hotel And Office Cards Still Hide A Factory Backdoor, And Proxmark Guides Now Walk Attackers Through The Keys"},"content":{"rendered":"<p><iframe loading=\"lazy\" title=\"Millions of Cards at Risk: The FM11RF08S Backdoor Exposed or the tale of the single encrypted nonce.\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/obGOgzh862o?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>A hotel keycard that looks like every other white rectangle in a front-desk drawer can be carrying a factory backdoor. In August 2024, Philippe Teuwen of Quarkslab, working with the Proxmark3 community, published the technical note and <a href=\"https:\/\/eprint.iacr.org\/2024\/1275\" target=\"_blank\" rel=\"noopener\">IACR ePrint 2024\/1275<\/a> on Shanghai Fudan Microelectronics&rsquo; FM11RF08S. The chip, sold from 2020 as the hardened \u00ab\u00a0static encrypted nonce\u00a0\u00bb version of MIFARE Classic, was supposed to survive the card-only attacks that had embarrassed Classic for more than a decade. Teuwen showed that a one-bit change in a command field moves authentication off the property&rsquo;s Key A and Key B and onto a hidden key. For FM11RF08S that key is A396EFA4E24F. With it, someone who can sit next to the card recovers the diversified user keys and writes a clone. The AEGIS Alliance is keeping this in the hacker file because the repair is not a software patch. The repair is different plastic.<\/p>\n<p>The <a href=\"https:\/\/blog.quarkslab.com\/mifare-classic-static-encrypted-nonce-and-backdoors.html\" target=\"_blank\" rel=\"noopener\">Quarkslab write-up<\/a> is blunt about what diversification was supposed to buy. Hotels and offices were told that even if one room key leaked, the next sector would use a derived key, so a single stolen card would not open the building. Teuwen&rsquo;s line cuts that pitch apart: the backdoor \u00ab\u00a0allows us to launch new attacks to dump and clone these cards, even if all their keys are properly diversified.\u00a0\u00bb One global constant walks around the derivation. The same family of hidden keys turned up on older Fudan parts \u2014 FM11RF08, FM11RF32, FM1208-10 \u2014 and on some NXP MF1ICS5003 and MF1ICS5004 cards and Infineon SLE66R35 cards that date to the late 1990s and early 2000s. A supply-chain clone with the backdoor baked in is enough. The usual requirement is physical proximity, not a remote exploit. A front desk cannot \u00ab\u00a0update\u00a0\u00bb a Classic-compatible card any more than it can update a stamped brass key.<\/p>\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">&quot;FM11RF08S chip by Shanghai Fudan Microelectronics was thought to be the most secure implementation of MIFARE Classic &#8230; However, we have demonstrated various attacks, uncovered the existence of a hardware backdoor and recovered its key&quot;<a href=\"https:\/\/t.co\/mdzId1AeWz\">https:\/\/t.co\/mdzId1AeWz<\/a><\/p>\n<p>&mdash; Lup Yuen Lee \u674e\u7acb\u6e90 (@MisterTechBlog) <a href=\"https:\/\/x.com\/MisterTechBlog\/status\/1827904701343715740?ref_src=twsrc%5Etfw\">August 26, 2024<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/p>\n<p>On September 10, 2024, the Proxmark3 Iceman fork shipped version 4.18994, tagged Backdoor, with FM11RF08S helpers including <em>hf mf isen<\/em>. That release turned a paper into a field routine. The routine then got harder to ignore. Standard attacks contradict each other on this silicon. Nested authentication complains that the PRNG is not predictable. Static-nested attacks say they see a normal nonce. Hardnested attacks abort because they hit a static encrypted nonce. The chip&rsquo;s first authentication nonce behaves like a weak generator, while the nested nonce is static and encrypted. Automated scripts die in that gap. In February 2026 the Iceman project merged a manual recovery guide, tested on an RDV4 running firmware 4.20728, that walks an operator from <em>hf mf info<\/em> through nonce collection, offline candidate generation, and a dictionary check. The author of that guide reported recovering all 32 keys from a hotel card mixing Vingcard, Timelox, and ENKOA encodings after autopwn left three keys unsolved and the recovery script crashed. A research backdoor had become a cookbook for the exact locks still screwed to guest-room doors.<\/p>\n<p>A separate access-control assessment published in June 2026 shows how little some installations needed the cookbook. The card under test was a MIFARE Classic 1K on an FM11RF08S. Every sector still used the factory key FFFFFFFFFFFF. The reader, the assessor found, authenticated on the card&rsquo;s serial number alone and never read the encrypted sectors. A blank \u00ab\u00a0magic\u00a0\u00bb card with a copied UID would have been enough, even before the backdoor. The backdoor made full key recovery a matter of seconds on a Proxmark regardless of what keys had been set. The organization acknowledged the finding. The write-up said no remediation had been taken at the time it was posted. That is the unglamorous version of a supply-chain failure: not a spy in a lobby, a purchasing order that never asked which chip was inside the laminate.<\/p>\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Deliberate backdoors<\/p>\n<p>Fudan FM11RF08S \/ FM11RF08 (2024) \u2014 Quarkslab&#39;s Philippe Teuwen found a hardware backdoor in the FM11RF08S, a MIFARE Classic variant released in 2020 by Shanghai Fudan Microelectronics, that lets anyone who knows it compromise all user-defined keys on a\u2026<\/p>\n<p>&mdash; KimchiHodl\ud83c\udf72\ud83c\udfb2 (@KimchiHodl) <a href=\"https:\/\/x.com\/KimchiHodl\/status\/2098373186538668489?ref_src=twsrc%5Etfw\">September 11, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/p>\n<p><a href=\"https:\/\/www.keysight.com\/blogs\/en\/tech\/nwvs\/2024\/08\/27\/security-highlight-backdoor-key-found-in-mifare-classic-cards\" target=\"_blank\" rel=\"noopener\">Keysight<\/a> and <a href=\"https:\/\/thehackernews.com\/2024\/08\/hardware-backdoor-discovered-in-rfid.html\" target=\"_blank\" rel=\"noopener\">The Hacker News<\/a> told operators in August 2024 to get off Classic-compatible badges. Quarkslab had already found the Fudan chips in hotels across the United States, Europe, and India. Buyers rarely see the part number. They see a card that works in a lock bought during the last renovation. MIFARE Classic was broken as a cipher long before this backdoor. Academic attacks on CRYPTO1 are old enough to have their own case law. Static encrypted nonces were the cheap retrofit: keep the readers, swap the card, claim resistance to the known card-only attacks. FM11RF08S was that retrofit, shipped with a master override. Anyone who knows the constant can dump sectors a property manager believed were unique to one wing of one hotel.<\/p>\n<p>The practical threat is smaller and more common than a national-security briefing. It is a person with a Proxmark or a comparable reader, a few quiet minutes next to a badge left on a caf\u00e9 table or a keycard left on a nightstand, and a lock that still speaks Classic. Hotel hallways are worse than offices in one respect and better in another. Worse, because keys are handed to strangers every night. Better, because many large chains already moved flagship towers onto MIFARE DESFire or another AES-backed card. The leftover risk sits in independent hotels, older office parks, gym turnstiles, parking garages, and any \u00ab\u00a0compatible\u00a0\u00bb stock bought because it was cheap and fit the encoder the desk already owned. Wholesale listings were still advertising hotel key cards on MIFARE Classic 1K in September 2026, alongside DESFire as an optional upgrade. The broken chip is not a museum piece. It is a line item.<\/p>\n<p>Cloning is the product, not a side effect. Once the sector keys are known, a blank Classic-compatible card can be written to look like the original. The lock does not know the difference. Some systems check that a serial number has not been reported stolen. Many do not. A clone that keeps the original UID walks through a lazy allow-list, which is exactly what the June 2026 assessment found in the wild. A housekeeper&rsquo;s master, a night auditor&rsquo;s override, and a contractor&rsquo;s weekend badge are the same radio problem if they sit on this silicon. Losing a card is a credential incident, not a three-dollar reorder from the print shop.<\/p>\n<p>The same contactless habit is already being used for cash, which is why readers of <a href=\"https:\/\/theaegisalliance.com\/category\/news\/hacker-news\/\">Hacker News<\/a> should not treat a door badge as a cousin of a payment card that happens to be safe. The AEGIS Alliance report on <a href=\"https:\/\/theaegisalliance.com\/2024\/08\/25\/ngate-android-malware-steals-nfc-data-clones-no-contact-payment-cards\/\">NGate Android malware<\/a> describes a relay that lets an attacker tap a victim&rsquo;s contactless card at an ATM while the real card is still in a pocket. Door credentials and bank cards are different products. They share a radio band and a public that treats a tap as magic. A building that \u00ab\u00a0upgraded\u00a0\u00bb from metal keys to FM11RF08S did not leave the 2000s. It imported them.<\/p>\n<p>What an owner can do is short and expensive in the way that actually works. Inventory the chip, not the artwork. If the card answers as FM11RF08S, or as an older Fudan Classic clone, retire the stock. Move readers to DESFire EV2 or EV3, or to an equivalent AES card the lock vendor will support with a real encoder, not a compatible blank from the cheapest export lot. For a hotel, that means the lock firmware and the front-desk encoder change together. Printing a new logo on the same silicon decorates the problem. For an office, the badge that opens the garage should not still be a 2008 Classic part under a newer lanyard. Treat a lost card as a revoked credential the same day. Guests can do less, but not nothing: keep the card in a pocket rather than on a restaurant table, and ask whether the property has left Classic-compatible stock. A desk that cannot answer has answered.<\/p>\n<p>Publishing the key helped every hotel that was willing to listen, and it helped every thief who already owned a reader. That is how hardware disclosure works. Once the constant is public, pretending it is still a secret is policy theater. No Fudan recall that pulls FM11RF08S cards out of hotel drawers has appeared in a form a night manager can act on. The Proxmark documentation still treats the backdoor as live. The manual guide still recovers hotel keys when the scripts fail. The cards are still plastic. Related reporting on this desk lives in <a href=\"https:\/\/theaegisalliance.com\/category\/news\/technology\/\">Technology<\/a>, including the <a href=\"https:\/\/theaegisalliance.com\/2024\/04\/25\/major-security-flaws-expose-keystrokes\/\">keystroke-exposure file<\/a> and the <a href=\"https:\/\/theaegisalliance.com\/2025\/12\/17\/inside-the-700credit-breach-that-exposed-nearly-6-million-car-buyers\/\">700Credit exposure of car-buyer data<\/a>. Those are vendor and software failures that can, in principle, be patched. This one cannot. Until the readers change, the hallway is a radio problem wearing a hotel logo.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shanghai Fudan&rsquo;s FM11RF08S MIFARE Classic cards carry the hardware backdoor key A396EFA4E24F, which dumps diversified hotel and office keys. A 2026 Proxmark manual recovered a live hotel card after automated attacks failed. The chips cannot be patched.<\/p>\n","protected":false},"author":296,"featured_media":1040646,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,21],"tags":[208657,191867,192022,3674,207540,207252,214241,214240],"class_list":["post-1040644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacker-news","category-news","tag-cyber","tag-cybersecurity","tag-hacker-news","tag-hackers","tag-hacking","tag-hotels","tag-offices","tag-rfid"],"jetpack_featured_media_url":"https:\/\/theaegisalliance.com\/wp-content\/uploads\/Hardware-Backdoor-Found-in-RFID-Cards-Used-in-Offices-and-Hotels-All-Over-the-World.jpg","_links":{"self":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1040644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/users\/296"}],"replies":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/comments?post=1040644"}],"version-history":[{"count":5,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1040644\/revisions"}],"predecessor-version":[{"id":1203426,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1040644\/revisions\/1203426"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media\/1040646"}],"wp:attachment":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media?parent=1040644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/categories?post=1040644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/tags?post=1040644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}