# Chameleon Ultra: what the NRF52840 RFID tool does and how to build its CLI

> Chameleon Ultra is an open hardware RFID/NFC device from RfidResearchGroup that emulates, reads, writes and decrypts cards. The repository holds firmware, hardware files and a command line client, but no install guide in the README itself.

**RfidResearchGroup/ChameleonUltra** — The new generation chameleon based on NRF52840 makes the performance of card emulation more stable. And gave the chameleon the ability to read, write, and decrypt cards.

- Repository: https://github.com/RfidResearchGroup/ChameleonUltra
- Stars: 3,035 · Forks: 459
- Language: C
- License: GPL-3.0
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/rfidresearchgroup-chameleonultra

## What problem Chameleon Ultra solves, and who it is actually for

A physical access card is a small computer with no screen and no logs. To understand one you either carry a laptop with a large reader, or you carry something pocket-sized that can present itself as a card and answer the reader's questions. Chameleon Ultra is the second kind: an NRF52840-based device that the repository describes as a new generation of Chameleon with more stable card emulation, plus the ability to read, write and decrypt cards. The topics list on the repository names the concrete targets: 125khz, iso14443a, mifare, ntag and ultralight.

The audience is narrower than the marketing suggests. This is a tool for people who already know the difference between a UID and a sector key, who are comfortable flashing firmware, and who are testing systems they are authorized to test. It is not a consumer gadget. The README's first substantial section is a list of authorized distributors in France, the United States, the UK, Canada, China and Singapore, which tells you the project expects you to buy hardware through a reseller rather than assemble it. The documentation, including usage instructions, lives in a separate wiki repository rather than in the README, so a new user's first stop is a different URL.

## The mechanism: firmware on NRF52840, clients over BLE and USB

The repository is organized as a hardware and software project rather than an application. The top level contains firmware/, hardware/, software/, resource/ and docs/, alongside AUTHORS.md, CHANGELOG.md and CONTRIBUTING.md. That layout is the architecture in miniature: the NRF52840 runs firmware that implements the radio work, and everything else is a client that talks to it.

Clients are the interesting part, because the project does not insist on one. The README lists ChameleonUltraGUI, MTools BLE, an iOS-only app called Mifare Chameleon Tool marked Beta, and a Sailfish OS client, plus chameleon-ultra.js as a notable project. There is also an official CLI, which the linked video describes as being downloaded and compiled rather than installed from a package manager. That means the device is a peripheral with several front ends, and the protocol between them is the real interface. If you write tooling, you are writing a client, not modifying the card logic.

The firmware is written in C. Nothing in the README describes a plugin system, a scripting layer on the device, or over-the-air update support; the release notes are not reproduced here, so treat update mechanics as something to confirm in the wiki before you plan a fleet.

## Building the official CLI and taking a first look at the device

The README does not contain install steps. It says to read the available documentation, which links to the project wiki, and it links a video titled Downloading and compiling the official CLI. So the commands below are the shape of the workflow rather than a copied recipe: clone, inspect the software tree, build. If the wiki disagrees with anything here, the wiki wins.

Start by getting the source and seeing what build systems exist:

```bash
git clone https://github.com/RfidResearchGroup/ChameleonUltra.git
cd ChameleonUltra
ls software firmware
```

The two directories are separate concerns. software/ holds the host-side clients, including the CLI; firmware/ holds the code that runs on the NRF52840. You build the first on your laptop and flash the second to the device. The README's video link is specifically about compiling the CLI, so expect a compiler and the usual C toolchain rather than a single binary download.

If you would rather not build anything, the README points at ChameleonUltraGUI as a compatible application, and at MTools BLE, with a video walkthrough titled How to clone a card with ChameleonUltra. That is the shortest path from unboxing to a first card operation, and it avoids the CLI build entirely. For a first real use, the honest sequence is: confirm your hardware came from one of the listed distributors, install one of the GUI clients, connect over BLE, and only then decide whether you need the CLI.

## Where Chameleon Ultra is the wrong tool

The repository does not document rollback. If a firmware flash goes wrong, nothing in the README tells you how to return to a known-good state, and there is no mention of a recovery mode or a factory image procedure. That is a real operational risk for anyone flashing devices they cannot easily replace, and it is the kind of gap that only matters after it matters.

The release history is the second constraint. The tagged releases listed for the repository are v2.2.0 from 2026-07-04, v2.1.0 from 2025-09-02, and a dev tag from 2023-08-19. There is a long gap between the dev tag and the versioned releases, and the last push to the default branch was on 2026-09-11. That pattern suggests active work, but it also means main is not a release channel. If you build from the default branch you are testing unreleased firmware, and the CHANGELOG.md at the top level is where you would check what changed.

Finally, consider the form factor. A handheld emulator is good at presenting a card and at short field operations. It is not a replacement for a bench setup where you need to hold a session open, capture long traces, or run automated sequences across many cards. If your work is analysis rather than emulation, a laptop-attached reader with a scripting environment is the more natural fit, and the Chameleon's strength, being small and untethered, becomes irrelevant.

## Proxmark3 and the difference in approach

The comparison people reach for is Proxmark3, and the difference is not which one is better but what each assumes about the operator. Proxmark3 is a bench instrument: it connects to a host, it is driven by a large client application, and its value comes from the depth of what you can do while attached to a computer. Chameleon Ultra inverts that. It is a device that stands alone, presents itself as a card, and is controlled from a phone or a small GUI over BLE, with the CLI as an option for people who want to script it.

That inversion has consequences. On the Chameleon side you get portability and a stable emulation target, which is exactly what the README claims for the NRF52840 generation. You give up the bench depth. On the Proxmark3 side you get a wider surface for analysis and a mature host toolchain, at the cost of carrying a laptop. Neither project's README is a substitute for the other's documentation, and the Chameleon README does not attempt a feature comparison.

A second, less obvious alternative is doing nothing at the hardware level and using a client-only workflow with an existing reader. If all you need is to read a card and inspect its contents, the Chameleon's emulation and decryption features are unused weight.

## Licence, maintenance and what an upgrade actually costs

The repository is licensed GPL-3.0. For most users that is a non-issue: you are flashing firmware onto hardware you own and running a CLI on your own machine. It matters if you intend to ship a product that links the firmware or the client code, because GPL-3.0 carries source disclosure obligations for distributed derivatives. Nothing here is legal advice, and the LICENSE file at the top level is the authoritative text.

Maintenance is the more practical cost. The default branch saw its last push on 2026-09-11, and the most recent tagged release is v2.2.0 from 2026-07-04. Versioned releases are roughly annual in the listed history, so treat the tag as your upgrade unit, not the branch. Upgrading means rebuilding the firmware for the NRF52840 and reflashing, and the README does not document a rollback path, so the cost of an upgrade includes the cost of a device you cannot easily revert.

The client side is cheaper to move. Because the README lists several independent clients, including ChameleonUltraGUI and chameleon-ultra.js, you can change your front end without touching the device. That separation is the project's most useful structural decision, and it is the reason the upgrade story is not as bad as the release cadence suggests.

## Conclusion

Adopt Chameleon Ultra if you already work with 125 kHz or ISO14443A cards and want a pocket-sized emulator you flash yourself from the firmware directory, or if you need the CLI as a scripting layer over a BLE or USB connection. Do not adopt it expecting a finished product: the README points to the wiki for usage, the newest tagged release in the repository is v2.2.0 from 2026-07-04, and the dev tag dates to 2023, so pin a tag instead of tracking main. Before buying hardware, verify the vendor is one of the authorized distributors listed in the README, and before writing firmware, confirm the toolchain in the wiki matches the NRF52840 target you have.

## FAQ

### What does the Chameleon Ultra do?

It is an NRF52840-based RFID and NFC device that the repository describes as making card emulation more stable while adding the ability to read, write and decrypt cards. The listed topics cover 125khz, iso14443a, mifare, ntag and ultralight.

### How do you use the Chameleon Ultra?

The README does not contain usage instructions. It points to the project wiki for documentation and lists compatible applications such as ChameleonUltraGUI and MTools BLE, with a video walkthrough on cloning a card.

### How do you use the Chameleon Ultra GUI?

ChameleonUltraGUI is listed in the README as a compatible application, and the README links two videos about it: one on downloading it and one on its features. The README itself gives no step-by-step instructions, so the videos and the wiki are the sources.

### How does the Chameleon Ultra compare with the Proxmark3?

The repository does not publish a comparison. The structural difference visible in the README is that Chameleon Ultra is controlled by clients over BLE or USB, including phone and desktop GUIs, while the project itself is firmware plus a CLI, so the choice depends on whether you want a standalone emulator or a host-attached instrument.

### Is the Chameleon Ultra worth buying?

The repository does not make that judgement. What it does show is that the device is sold through authorized distributors, that clients exist for desktop, Android, iOS and Sailfish OS, and that firmware is built from source rather than updated over the air in any documented way.

## Sources

- [Issues](https://github.com/RfidResearchGroup/ChameleonUltra/issues)
- [License: GPL-3.0](https://github.com/RfidResearchGroup/ChameleonUltra/blob/main/LICENSE)
- [README](https://github.com/RfidResearchGroup/ChameleonUltra/blob/main/README.md)
- [Releases](https://github.com/RfidResearchGroup/ChameleonUltra/releases)
- [RfidResearchGroup/ChameleonUltra on GitHub](https://github.com/RfidResearchGroup/ChameleonUltra)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/rfidresearchgroup-chameleonultra
