Informational

Can HID Prox Cards Be Cloned? (Honest Answer)

By American Key Cards

Editorial access-control image for Can HID Prox Cards Be Cloned? (Honest Answer)

HID Prox cards can be cloned. That is the direct answer. Standard HID Prox — the H10301 26-bit format that runs on most legacy access systems — operates at 125 kHz with no encryption and no authentication, which means any device that can interrogate the card’s RF field can capture and reproduce the credential data. American Key Cards supplies HID Prox H10301-compatible cards and key fobs programmed from your facility code and card number — built to specification, not copied from existing cards. If you are reading this because you need to replace lost badges, add credentials to an existing system, or decide whether to upgrade for security, the rest of this guide gives you the honest technical picture without the sales spin.

Is HID Prox Encrypted? (No — and That Is the Whole Point)

Verdict: Standard 125 kHz HID Prox has zero cryptographic protection. It was never designed to have any.

Every HID Prox credential — whether it is a thin 1326 ProxCard II, a printable 1386 ISOProx II, or a 1346 ProxKey III fob — contains a passive RFID chip that wakes up inside a reader’s electromagnetic field. The reader energizes the card, the card broadcasts its stored data, and the reader passes that data to the access controller as a Wiegand output. That broadcast is a fixed, plain FSK-modulated signal. It carries the same facility code and card number every single time, with no key, no rolling code, and no back-and-forth challenge between card and reader.

This is fundamentally different from a modern smart credential. With encrypted formats, the reader issues a challenge, the card proves it holds a secret key without ever transmitting the key itself, and the actual credential data is encrypted with AES. None of that exists in 125 kHz Prox. The card is, in effect, a wireless barcode that anything with a 125 kHz antenna can read.

The Standard HID Prox Card Line (OEM Part Numbers)

If you are trying to identify what you already have, HID’s 125 kHz Prox catalog uses a consistent part-numbering scheme. These are the most commonly searched OEM credentials — every one of them is the same unencrypted H10301-capable 125 kHz technology, differing only in form factor:

OEM Part NumberCommon NameForm Factor
1326ProxCard IIThin clamshell (non-printable)
1386ISOProx IIISO PVC, direct-print card
1346ProxKey IIIKey fob / tag
1336DuoProx IIPrintable card with magstripe slot
1586Smart ISOProx IIISO card with embedded contactless smart chip
1391ProxPass / adhesive tagAdhesive label / vehicle tag variant

OEM HID cards are sold through HID’s authorized distributor channel, often with minimum order quantities and dealer markup. That distribution model — not any technical lock — is the main reason buyers look for compatible alternatives. There is no proprietary cryptographic barrier preventing a third party from producing a card to the same open specification.

Can HID Prox Cards Be Cloned? (The Technical Reality)

Verdict: Yes, easily, with hardware that costs less than a tank of gas.

Here is exactly how it works, in plain terms:

Reading the card. A device such as a Proxmark3 — a widely available RFID research tool — captures the facility code and card number from an HID Prox card when held within a few inches of it. The capture takes a second or two. Even simpler $30 handheld “key copiers” sold online can read many 125 kHz Prox cards.

Writing the copy. That captured data is written to a T5577 blank card — a multi-frequency programmable RFID transponder that costs a few dollars and is sold openly. The T5577 is configured to emulate the HID Prox protocol and broadcast the same facility code and card number.

Using the copy. The cloned card works in the reader exactly like the original. The reader has no mechanism to distinguish an OEM HID chip from a T5577 that is transmitting identical data in the identical format. There is no serial-number check, no encryption to fail, nothing to flag the duplicate.

This is not a flaw unique to HID. It applies to the entire category of 125 kHz proximity credentials. The same class of tools clones Kantech ioProx (XSF), Indala FlexPass 26-bit, AWID, DoorKing DKProx, and essentially every other unencrypted low-frequency format. AWID is a frequent point of confusion here because it shares HID’s 26-bit output — our explainer on the difference between AWID and HID 26-bit shows why the cards still are not interchangeable despite the identical clone exposure. The technology was standardized in an era when the cloning hardware did not exist on the open market. It does now.

How a Cloned Card Differs From a Compatible Replacement

The word “cloning” gets thrown around loosely, and the difference is worth being precise about — legally and operationally.

A cloned card is an unauthorized copy of a specific, existing credential. It carries the exact facility code and card number of a real card that was read without the cardholder’s consent. The intent is to use someone else’s valid identity to gain access. Depending on jurisdiction and circumstances, making one can run afoul of computer-fraud or property-access laws.

A compatible replacement card is a brand-new credential, legitimately programmed by the authorized system owner. American Key Cards encodes HID-compatible cards from your facility code and your card number range, written to the H10301 specification during manufacture — the same process the OEM uses. The card is not duplicated from any existing card; it is produced to spec.

The analogy is straightforward: cloning is photocopying a banknote; ordering a compatible replacement is asking your bank for a new checkbook. What makes a credential valid in your building is not secrecy — it is that the facility code and card number match an entry your administrator added to the access database. The specification itself is open.

American Key Cards is not affiliated with HID Global. Our compatible cards are produced by specification, not reverse-engineered from OEM cards, and every card carries a lifetime parts and workmanship guarantee.

Which HID Formats Are Clone-Resistant and Which Are Not

Not all “HID” credentials are the same. The brand name spans both the wide-open 125 kHz Prox family and genuinely secure 13.56 MHz smart formats. If security is your concern, this table is the one that matters:

FormatFrequencyEncryptionAuthenticationPractically Clonable?
HID Prox (H10301 26-bit)125 kHzNoneNoneYes — Proxmark3 + T5577
HID iCLASS Legacy13.56 MHzWeak / compromisedLimitedYes — known key attacks exist
HID iCLASS SE13.56 MHzAES (Secure Identity Object)MutualNo — not with off-the-shelf tools
HID Seos13.56 MHzAES-128, standards-basedMutualNo — current best-in-class
MIFARE DESFire EV2 / EV313.56 MHzAES-128MutualNo

The takeaway: “HID” alone tells you nothing about security. A 1326 ProxCard II is trivially clonable; a Seos credential is not. The middle row is the one that trips people up — our separate look at whether HID iCLASS legacy can be cloned explains why that 13.56 MHz format is not the safe upgrade its frequency suggests. If a vendor tells you your old 125 kHz Prox cards are “secure,” they are either confused or selling you something.

Should You Worry? (An Honest Risk Assessment)

Verdict: For most buildings, the cloning risk is real but tolerable. For a few doors, it is not.

We will not pretend the risk is zero, and we will not inflate it to sell an upgrade. Cloning an HID Prox card requires an attacker to get a reading device within a few inches of a live card for a second or two — close enough to physically bump someone or briefly handle their badge. That is a meaningful barrier in practice. The overwhelming majority of commercial, residential, and institutional deployments run 125 kHz Prox and accept this risk because the cost and disruption of ripping out every reader is not justified by the threat.

Where it stops being acceptable is at high-value doors: server and network rooms, pharmacies and drug storage, cash rooms, executive suites, research labs, and anywhere a compliance regime explicitly requires it. For those, 125 kHz proximity — HID Prox included — is the wrong long-term answer.

How to Make Your HID System Clone-Resistant

You do not have to convert your whole building at once, and you should not let anyone tell you that you do.

The practical path is to upgrade the readers at your high-risk doors to HID multiCLASS SE or iCLASS SE readers, which read 13.56 MHz encrypted credentials — iCLASS SE or Seos. These formats use AES encryption and mutual authentication: the data is never transmitted in the clear and cannot be lifted and replayed with a Proxmark3 or any commercially available hardware as of this writing.

The migration-friendly detail: multiCLASS SE readers are dual-technology. They read your existing 125 kHz Prox cards and new encrypted credentials simultaneously. That lets you swap readers door by door, issue encrypted cards to the people who need access to sensitive areas, and keep your legacy Prox population working everywhere else during the transition. No flag-day cutover required.

If you are not sure which HID format your readers actually use, our guides on identifying your access card format and the iCLASS SE vs. Seos security comparison walk through it.

What You Need to Order Compatible HID Prox Cards

If you have decided that compatible 125 kHz Prox replacements are right for your situation — replacing lost badges, adding credentials, or building a standing inventory — ordering is straightforward. You need:

  1. Facility code — the site-level code (0–255) assigned when the system was installed. It is usually printed on existing cards or available from your installer or panel records.
  2. Card number range — the sequential numbers (0–65,535) you want encoded. For replacements, provide the original card number so the new card inherits the same access rights in your panel; for additions, specify unused numbers in your range.
  3. Form factor — clamshell (1326-style), printable ISO card (1386-style), or key fob (1346-style).

American Key Cards supplies these direct, with no dealer account required, no OEM minimum order, and pricing at a fraction of OEM. Every card is encoded to your exact specification before it ships and is backed by a lifetime parts and workmanship guarantee.

Ordering Compatible HID Prox Cards

If you manage an HID Prox system and need to replace lost cards, issue new credentials, or stock spares, contact American Key Cards with your facility code, card number or range, quantity, and preferred form factor. We will confirm the format, encode the cards to the H10301 specification, and ship direct.

And if this article convinced you that the doors that matter deserve better than 125 kHz, tell us that too — we will point you toward the right encrypted upgrade path rather than sell you more of a format we just told you can be cloned.

Frequently asked questions

Can HID Prox cards be cloned?

Yes. Standard HID Prox cards (the H10301 26-bit format) operate at 125 kHz with no encryption and no authentication between card and reader. A Proxmark3 or even an inexpensive handheld duplicator can read the facility code and card number off a card held within a few inches, then write that data to a blank T5577 transponder. The copy works in the reader identically to the original because the reader cannot tell them apart.

Is HID Prox encrypted?

No. Standard 125 kHz HID Prox transmits a fixed facility code and card number as a plain FSK-modulated radio signal every time it is presented to a reader. There is no cryptographic key, no mutual authentication, and no rolling code. Encryption only enters the picture with HID's 13.56 MHz smart credentials — iCLASS SE and Seos — which use AES and challenge-response and are not practically clonable.

What is the difference between a cloned HID card and a compatible replacement card?

A cloned card is an unauthorized copy of a specific existing credential — it carries the exact facility code and card number of someone's real card, captured without their consent. A compatible replacement card from American Key Cards is a new credential, legitimately programmed by the system owner using their own facility code and card number range, built to the H10301 specification rather than copied off an existing card. Same end result as ordering from the OEM, properly issued.

If HID Prox can be cloned, why is it still everywhere?

Because cloning requires physical proximity to an active card for a few seconds, and for the vast majority of buildings that risk is acceptable against the cost and disruption of replacing every reader. HID Prox is cheap, reliable, and universally compatible. The right question is not 'can it be cloned' (it can) but 'does my threat model justify upgrading the doors that matter' — server rooms, pharmacies, executive floors.

How do I make my HID system clone-resistant?

Move the high-risk doors to encrypted 13.56 MHz credentials — HID iCLASS SE or Seos — which require multiCLASS SE or iCLASS SE readers. These use AES encryption and mutual authentication, so the data cannot be lifted and replayed with off-the-shelf tools. You do not have to convert the whole building at once; multiCLASS SE readers can read both your existing 125 kHz Prox cards and new encrypted credentials during a phased migration.

Not sure which format you have?

Send us the numbers printed on your card — we'll identify the format and quote a compatible card, usually within one business day.

Lifetime parts & workmanship guarantee on every card