---
title: Recovering MIFARE Classic keys
slug: zero/nfc/mfkey32
description: Learn how to conduct the MFKey32 attack, both with and without physical access to the card, as well as card-only attacks for which you don’t need access to the reader to calculate the keys
image: https://archbee-image-uploads.s3.amazonaws.com/3StCFqarJkJQZV-7N79yY/84UBz6YQPLSxD_CSrKqi6_recovering-mifare-classic-keys-prev-1.png
docTags: 
createdAt: 2023-01-24T12:34:52.000Z
---

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-LcbRRk6BTxstYEl2WJYmP-20241025-092032.png)

If you couldn’t read all the MIFARE Classic® card’s sectors with the [Read](https://docs.flipper.net/zero/nfc/read) function or the sectors you read aren’t enough to get access, you can try exploiting vulnerabilities in MIFARE Classic NFC cards to get access.

On this page, you’ll learn how to conduct the MFKey32 attack, both with and without physical access to the card, as well as card-only attacks for which you don’t need access to the reader to calculate the keys.

***

# MFKey32 attack

The MFKey32 attack [exploits weaknesses](https://www.cs.bham.ac.uk/~garciaf/publications/Dismantling.Mifare.pdf) in the [Crypto-1](https://en.wikipedia.org/wiki/Crypto-1) encryption algorithm. MFKey32 is the name of a tool/algorithm used to recover the MIFARE Classic keys from the reader’s Crypto-1 [nonce](https://en.wikipedia.org/wiki/Cryptographic_nonce) pairs. It works by recovering the initial state of the Crypto-1 [Linear Feedback Shift Register](https://en.wikipedia.org/wiki/Linear-feedback_shift_register) which contains the key.

## With access to the reader and card

The best way to conduct the MFKey32 attack is to have access to the card, even if not all sectors were read. After getting the reader’s key, you can read more sectors of the card, which might be enough to get access.

To get the reader’s keys and read the MIFARE Classic card, do the following:

:::::WorkflowBlock
:::WorkflowBlockItem
[Read and save the card](https://docs.flipper.net/zero/nfc/read) with your Flipper Zero.
:::

:::WorkflowBlockItem
Go to **Main Menu -> NFC -> Saved -> Name of the saved card -> Extract MF Keys**. Flipper Zero will emulate this card for the MFKey32 attack.

![](https://api.archbee.com/api/optimize/3StCFqarJkJQZV-7N79yY/aRTJ3BCig7LCW4CH1YDNL_monosnap-miro-2023-08-03-19-50-38.jpg "Your Flipper Zero is ready to collect the reader’s nonces")
:::

:::WorkflowBlockItem
**Tap the reader** with your Flipper Zero, as shown below. When near the reader, your Flipper Zero will collect the reader’s nonces. Depending on the reader, you may need to tap the reader with your Flipper Zero several times until all 10 nonces are collected.

On your Flipper Zero’s screen, the number of collected nonce pairs should increase with each new tap of the reader. If the number of nonce pairs doesn’t increase, the reader is not trying to authenticate the card emulated by your Flipper Zero.

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-nh8jrj31z6hOnHThNEcw7-20241107-112652.png "To collect nonces, tap your Flipper Zero against the reader, pull it away, and repeat the process")
:::

:::WorkflowBlockItem
Press %ok%**OK** to save the collected nonce pairs to the microSD card. Once the required number of nonce pairs is collected, the screen will display a **Completed** message. After that, you can press the %ok%**OK** button to view the captured data, including the sector and key from which it was obtained.

![](https://api.archbee.com/api/optimize/3StCFqarJkJQZV-7N79yY/sR4_86WJB_5haA4HoEwHc_mfkey32noncepairscollected.jpg "Once nonces are collected, you can save them to the microSD card")
:::

::::WorkflowBlockItem
**Recover keys** from the collected nonces. You can do it via:

**Flipper Mobile App**

1. On your phone, run [Flipper Mobile App](https://docs.flipper.net/zero/mobile-app) and synchronize it with your Flipper Zero.

2. Go to **Tools -> Mfkey32 (Extract MF Keys)**.

**Flipper Lab**

1. Connect your Flipper Zero to your computer via a USB-C cable.

2. On your computer, go to [lab.flipper.net](https://lab.flipper.net/).

3. Go to **NFC tools**, then click the **GIVE ME THE KEYS** button.

**MFKey app**

:::Iframe{iframeHeight="0" code="<div class=&#x22;info flipper-callout&#x22;>&#xA;    <div class=&#x22;callout-header&#x22;></div>&#xA;To use this feature, install the <a href=&#x22;https://lab.flipper.net/apps/mfkey&#x22; onclick=&#x22;next.router.push('https://lab.flipper.net/apps/mfkey')&#x22;><u>MFKey</u></a> app on your Flipper Zero from the Apps Catalog.&#xA;<br>&#xA;<br>&#xA;Learn more about the <a href=&#x22;https://docs.flipper.net/zero/apps&#x22; onclick=&#x22;next.router.push('https://docs.flipper.net/zero/apps')&#x22;><u>Apps Catalog</u></a>.&#xA;</div>"}

:::

If you don’t have access to a smartphone or computer, you can recover keys from the collected nonces using only your Flipper Zero. Keep in mind that it takes several minutes to recover the keys due to the limited computing power of the device.

1. On your Flipper Zero, go to **Main Menu -> Apps -> NFC**.

2. Run the **MFKey** app and press the %ok%**OK** button.

The recovered keys will be displayed on the screen. After that, they can be added to the **User dictionary**. In some cases, the keys can’t be recovered from the nonces due to the reader not recognizing the Flipper Zero’s emulation properly.
::::

:::WorkflowBlockItem
Once new keys are added to the User dictionary, **read the card again**. The number of found keys and read sectors may increase, which indicates that the necessary data is collected.
:::

:::WorkflowBlockItem
[Emulate the card](https://docs.flipper.net/zero/nfc/read#Cy_5M) and hold your Flipper Zero near the reader to get access.

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-r7Ac9hzhZeg8dR59XFOv--20241107-112730.png "While emulating the NFC card, hold your Flipper Zero near the reader")
:::
:::::

:::Iframe{iframeHeight="0" code="<div class=&#x22;warning flipper-callout&#x22;>&#xA;    <div class=&#x22;callout-header&#x22;></div>&#xA;    If the emulated card doesn’t open the door, try to do steps 1 through 6 again in case your reader reads multiple sectors sequentially.<br><br>&#xA;    If, after repeating steps 1 through 6, the number of the card’s keys and sectors read by your Flipper Zero didn’t increase, then the reader and the card aren’t in the same system, or the reader isn’t vulnerable to the MFKey32 attack.  &#xA;</div>"}

:::

## With access only to the reader

Even if you don’t have access to the card, you can try to get the reader’s keys and then add them to the **User dictionary** to expand it.

To get and save the reader’s keys, do the following:

::::WorkflowBlock
:::WorkflowBlockItem
Go to **Main Menu -> NFC -> Extract MF Keys**. Flipper Zero will emulate an NFC card for the MFKey32 attack.

![](https://api.archbee.com/api/optimize/3StCFqarJkJQZV-7N79yY/daUwKKVW4HBirdmwgk7tQ_monosnap-miro-2023-08-03-19-51-29.jpg "Your Flipper Zero is ready to collect the reader’s nonces")
:::

:::WorkflowBlockItem
**Tap the reader** with your Flipper Zero as shown below. When near the reader, your Flipper Zero will collect the reader’s nonces. Depending on the reader, you may need to tap the reader with your Flipper Zero several times until all 10 nonces are collected.

On your Flipper Zero’s screen, the number of collected nonce pairs should increase with each new tap of the reader. If the number of nonce pairs doesn’t increase, the reader is not trying to authenticate the card emulated by your Flipper Zero.

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-nGTWC9NTOp_sNkrlmdgce-20241107-112752.png "To collect nonces, tap your Flipper Zero against the reader, pull it away, and repeat the process")
:::

:::WorkflowBlockItem
Press %ok%**OK** to save the collected nonce pairs to the microSD card. Once the required number of nonce pairs is collected, the screen will display a **Completed** message. After that, you can press the %ok%**OK** button to view the captured data, including the sector and key from which it was obtained.

![](https://api.archbee.com/api/optimize/3StCFqarJkJQZV-7N79yY/EE9Cqc28ze8WOSjyqvNkK_mfkey32noncepairscollected.jpg "Once nonces are collected, you can save them onto the microSD card")
:::

:::WorkflowBlockItem
**Recover keys** from the collected nonces. You can do it via:

**Flipper Mobile App**

1. On your phone, run [Flipper Mobile App](https://docs.flipper.net/zero/mobile-app) and synchronize it with your Flipper Zero.

2. Go to **Tools -> Mfkey32 (Extract MF Keys)**.

**Flipper Lab**

1. Connect your Flipper Zero to your computer via a USB-C cable.

2. On your computer, go to [lab.flipper.net](https://lab.flipper.net/).

3. Go to **NFC tools**, then click the **GIVE ME THE KEYS** button.

**MFKey app**

If you don’t have access to a smartphone or computer, you can recover keys from the collected nonces using only your Flipper Zero. Keep in mind that it takes several minutes to recover the keys due to the limited computing power of the device.

1. On your Flipper Zero, go to **Main Menu -> Apps -> NFC**.

2. Run the **MFKey** app and press the %ok%**OK** button.

The recovered keys and sector numbers will be displayed on the screen. After that, they can be added to the **User dictionary**. In some cases, the keys can’t be recovered from the nonces because the reader won’t recognize the Flipper Zero emulation properly.
:::
::::

***

# Card-only attacks

:::Iframe{iframeHeight="0" code="<div class=&#x22;info flipper-callout&#x22;>&#xA;    <div class=&#x22;callout-header&#x22;></div>&#xA;This feature is currently in Beta and may not function properly, potentially even causing device freezes.&#xA;</div>"}

:::

This type of attack can be performed directly on the card exploiting [vulnerabilities in MIFARE Classic cards](https://eprint.iacr.org/2024/1275.pdf). The goal of these attacks is to recover the card’s data and keys, so that you can clone and emulate the card.

There are several card-only attacks that Flipper Zero performs based on the card type and available data: nested attack, static nested attack, and hardnested attack. These attacks begin at the stage of reading the card (NFC -> Read). If card reading fails, Flipper Zero collects and saves card nonces and runs the MFKey app to calculate the keys. The calculated keys are then added to the User dictionary of MIFARE Classic keys.


:::Iframe{iframeHeight="0" code="<div class=&#x22;warning flipper-callout&#x22;>&#xA;    <div class=&#x22;callout-header&#x22;></div>&#xA;To continue, install the <a href=&#x22;https://lab.flipper.net/apps/mfkey&#x22; onclick=&#x22;next.router.push('https://lab.flipper.net/apps/mfkey')&#x22;><u>MFKey</u></a> app on your Flipper Zero from the Apps Catalog.&#xA;<br>&#xA;<br>&#xA;Learn more about the <a href=&#x22;https://docs.flipper.net/zero/apps&#x22; onclick=&#x22;next.router.push('https://docs.flipper.net/zero/apps')&#x22;><u>Apps Catalog</u></a>.&#xA;</div>"}

:::



To get the card’s keys and emulate the card, do the following:

::::WorkflowBlock
:::WorkflowBlockItem
Read the card to collect nonces.

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-ISnbioIZSSTejlwEMToCb-20241129-133446.png)
:::

:::WorkflowBlockItem
Go to **More -> Crack nonces in MFKey32**.
:::

:::WorkflowBlockItem
Save the card by pressing **Save**.
:::

:::WorkflowBlockItem
Press **Run** to open the [MFKey](https://lab.flipper.net/apps/mfkey) app.
:::

:::WorkflowBlockItem
Press %ok%**OK** to start the calculation.
:::

:::WorkflowBlockItem
Wait until the card keys are calculated from the collected nonces — **this takes a few minutes**. After tha&#x74;*,* the new keys will be added to the User dictionary automatically.
:::

:::WorkflowBlockItem
Read the card again to unlock the sectors that were protected with the calculated key.
:::

:::WorkflowBlockItem
[Emulate the card](https://docs.flipper.net/zero/nfc/read#Cy_5M) and hold your Flipper Zero against the reader to get access.

![](https://api.archbee.com/api/optimize/3GUDYkC5JgUWgo6RW8piO-r7Ac9hzhZeg8dR59XFOv--20241107-112730.png "While emulating the NFC card, hold your Flipper Zero against the reader")
:::
::::



## If the MFKey app fails to calculate keys

- Reboot your Flipper Zero by pressing and holding the %left%**LEFT** and %back%**BACK** buttons for 5 seconds.

- Delete the file with collected nonces, located at `/ext/nfc/.nested.log`. Then try collecting the nonces again and run MFKey.

- Delete the file containing user keys, located at `/ext/nfc/assets/mf_classic_dict_user.nfc`. Then try collecting the nonces again and run MFKey. **This action will permanently delete all the user keys.&#x20;**&#x49;f you wish to retain your keys, back them up before deleting by downloading the file to your computer.

***

MIFARE and MIFARE Classic are registered trademarks of NXP B.V.
