Open-source project
ikarus23/MifareClassicTool avatar
ikarus23/MifareClassicTool

MifareClassicTool: an Android NFC workbench for MIFARE Classic tags

An Android NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.

6,425 stars1,033 forksJavaGPL-3.0

At a glance

What is it?
MifareClassicTool reads, writes and diffs MIFARE Classic tags from an Android phone, using key dictionaries instead of cracking. It is a low-level tool for people who already know what a sector trailer is.
Who is it for?
Adopt MifareClassicTool if you already hold keys for the tags you work with and want a phone-based reader, writer and diff tool without a desktop reader. Do not adopt it if you expect it to recover unknown keys, if your phone's NFC controller is on the incompatible list, or if you need iOS or Windows.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 101 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What MifareClassicTool is for, and who should not pick it up

MifareClassicTool (MCT) is an Android app for interacting with MIFARE Classic RFID tags and, as the README puts it, "only with" MIFARE Classic tags. It reads tags, writes them block by block, clones dumps, formats tags back to their delivery state, and displays the raw data as hex, 7-bit US-ASCII, decoded value blocks and access-condition tables. The package name is de.syss.MifareClassicTool, and it ships on Google Play, F-Droid and as a direct APK from the project site.

The README is unusually blunt about the audience: users with "at least basic familiarity with the MIFARE Classic technology" who also understand hexadecimal, because every input and output is hex. There is no friendly layer that writes a URL to a tag. If you want that, this is the wrong tool.

The second boundary is harder. The app cannot crack or recover keys. It has no brute-force capability, and the README explains why: brute forcing is "way too slow due to the protocol." You must arrive with keys already in hand, obtained from a Proxmark3, mfcuk, mfoc or another reader. Anyone searching for an app that unlocks an unknown card will be disappointed, and that is a deliberate design position rather than a missing feature.

How the key-file dictionary model works

MCT does not ask you which key belongs to which sector. You give it a plain text file with one key per line, and the app tries every key against every sector, reading as much as it can. The README calls this a dictionary attack and lists the payoff directly: "You don't have to worry about which key is for which sector."

Three key files ship with the app: std.keys, extended-std.keys and hotel-std.keys, holding well-known keys and standard keys the author found through a short web search. They are starting points, not a solution. Edits to the shipped files are lost, so the README tells you to create your own key file for your own keys. You can build one on the phone through "Edit or Add Key File," or write it on a PC and bring it in through the import/export tool.

The consequence of the dictionary model is that read time scales with the size of your key file. A large dictionary tried against every sector of every tag is slower than a short, precise one. The README does not document how MCT orders or short-circuits that search, so treat a long key file as a cost you are choosing to pay.

Reading a tag: install and first run

Get the app from Google Play, from F-Droid, or as an APK from the project's release page. There is no desktop build, so installation means an Android device with an NFC controller that supports MIFARE Classic. That last condition matters: the README states the app "will not work" on some devices because their NFC controller lacks MIFARE Classic support, and points to INCOMPATIBLE_DEVICES.md in the repository.

Once installed, the first real task is producing a key file. The README describes the format as "a simple text file (one key per line)," and the three files that ship with the app are named std.keys, extended-std.keys and hotel-std.keys. Import your own file through the import/export tool if you wrote it on a PC, or create it in the app via "Edit or Add Key File." Then choose "Read Tag" from the main menu and hold the phone against the tag. What you should see is the sectors MCT managed to authenticate against, with the unread ones left blank. Partial reads are normal: the dictionary only opens the sectors whose keys it contains.

If you want to inspect a dump later, MCT saves it as a file. Note the README's warning that uninstalling the app deletes all dumps and keys it saved, permanently. Export anything you care about before removing the app.

Cloning, magic tags and where the Android NFC API stops you

The clone feature writes a dump from one tag onto another. For an original MIFARE Classic tag this cannot be a complete clone, because the first block of the first sector is read-only. Special tags sold as "magic tag gen2" or "CUID" accept a plain write to the manufacturer block, and MCT can write to those, producing a fully correct clone. The README says FUID and UFUID tags should also work but have not been tested.

Here is the real limitation. Some special tags need a special command sequence to enter the writable state, and the README states that sequence cannot be sent "due to limitations in the Android NFC API." Those tags are commonly labeled gen1, gen1a or UID. So a tag that clones fine with a Proxmark3 may be unreachable from MCT on the same phone. This is a platform boundary, not a bug that a future release will lift.

If you only need to copy a UID, the README directs you to the separate "Clone UID Tool" rather than the full clone path. It also warns that BCC, SAK and ATQA values must be correct for the clone to behave, and provides a BCC Calculator Tool for that check.

Analysis features that do not involve a tag at all

A large part of MCT works on data rather than on radio. The Diff Tool compares two dumps, which is the practical way to find what changed after a write or to check whether two tags that should be identical actually are. Value blocks can be decoded and encoded, access conditions can be decoded, encoded and shown as a table, and the BCC can be calculated. The generic tag information view covers UID, SAK and ATQA values.

This offline half is where the app is strongest for careful work, because it does not depend on the NFC controller at all. You can read a tag on a compatible phone, export the dump, and analyze it anywhere. The README also notes that help and information are available offline inside the app, which matters when you are standing next to a reader with no signal.

One gap worth naming: the README documents no rollback or undo for a write. Once a block is written, the previous contents exist only if you kept a dump. Treat the Diff Tool as something you use before writing, not after.

MifareClassicTool against desktop RFID tooling

The obvious alternative is a desktop setup: a Proxmark3 or a PC-connected reader such as the ACR122U with software like mfcuk or mfoc. The difference in approach is where the work happens. Desktop tools do the key recovery that MCT refuses to do, and the README itself sends you to Proxmark3, mfcuk and mfoc when you need keys you do not have. If your problem is an unknown tag, the desktop route is the only route here.

MCT's counter-argument is convenience and portability. It runs on hardware you already carry, needs no laptop, and its dictionary model removes the sector-to-key bookkeeping that raw reader software often exposes. It can also talk to external readers like the ACR122U, per the Help & Info section, so it is not strictly phone-only in terms of hardware.

Pick MCT when you have keys and want to read, write, diff or clone in the field. Pick a Proxmark3 when you need to recover keys or when your magic tags require the special command sequence Android cannot send.

Maintenance, licence and upgrade cost

The repository is not archived, and the last push was on 2026-06-21. Release 4.3.1 is dated 2026-01-25, following 4.3.0 on 2026-01-22 and 4.2.3 on 2024-08-31. The gap between 4.2.3 and 4.3.0 is roughly seventeen months, which tells you releases arrive when there is something to ship rather than on a schedule. Plan upgrades around releases, not around a cadence.

The project is licensed GPL-3.0, with LICENSE.txt at the repository root. Distribution matters here: if you ship a modified build, the GPL's source-availability terms apply to what you distribute. That is a statement about the licence text, not legal advice, and anyone embedding MCT in a product should read LICENSE.txt rather than this paragraph.

The upgrade cost itself is low. There is no server, no database and no configuration file to migrate. The state that matters lives in key files and dumps on the device, and the README warns that uninstalling the app destroys both. Back up your key files and dumps through the import/export tool before any reinstall.

Editorial conclusion

Adopt MifareClassicTool if you already hold keys for the tags you work with and want a phone-based reader, writer and diff tool without a desktop reader. Do not adopt it if you expect it to recover unknown keys, if your phone's NFC controller is on the incompatible list, or if you need iOS or Windows. Before relying on it, verify three things: that your device model appears in COMPATIBLE_DEVICES.md, that your key file covers the sectors you need, and that your target tags are writable in the block you intend to change, since an original MIFARE Classic tag keeps block 0 read-only.

Frequently asked questions

How do I use MifareClassicTool?

Create a key file with one hex key per line, import it or build it with "Edit or Add Key File," then pick "Read Tag" from the main menu and hold the phone to the tag. MCT authenticates with every key in the file against every sector and reads whatever it can open.

What is MifareClassicTool?

It is an Android NFC app for reading, writing, analyzing, cloning and formatting MIFARE Classic RFID tags, distributed on Google Play, F-Droid and as a direct APK. It also decodes value blocks and access conditions, compares dumps and calculates BCC values.

Can I clone an RFID card using an Android app?

MCT can clone MIFARE Classic tags, but only if you already have the keys and the target tag is writable in its manufacturer block. Original tags keep block 0 read-only, so a full clone needs a special tag such as a magic gen2 or CUID, and some of those require a command sequence the Android NFC API cannot send.

Is MIFARE Classic still used today?

The repository does not discuss current deployment numbers or market adoption, so it gives no basis for answering this. It does describe MIFARE Classic as a technology with known weaknesses, which is why the README directs users to tools like Proxmark3, mfcuk and mfoc for key recovery.

Can MIFARE Ultralight be cloned with MifareClassicTool?

No. The README states the tool interacts with MIFARE Classic RFID tags and only with those, so MIFARE Ultralight tags are outside its scope.

What can I use instead of MifareClassicTool?

The README points to Proxmark3, mfcuk and mfoc for retrieving keys, which MCT deliberately cannot do. Those are desktop-oriented tools, so the trade is key recovery and special-command support on one side against phone-based convenience on the other.

Official sources

  1. ikarus23/MifareClassicTool on GitHub
  2. License: GPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ikarus23-mifareclassictool.svg)](https://hysenlabs.com/projects/ikarus23-mifareclassictool)