Which Access Cards Can't Be Cloned? (Proximity vs Smart Cards vs Encrypted Credentials)
The short answer: cards that use cryptographic mutual authentication — encrypted 13.56 MHz smart cards running AES, and secure smart cards operating at their highest security level — cannot be practically cloned. Almost everything else can. That includes every 125 kHz proximity card on the market and, importantly, the original 13.56 MHz smart card, which is a 13.56 MHz card but is cryptographically broken. The deciding factor is not the frequency printed on the spec sheet — it is whether the card encrypts its data and forces the reader to prove its identity before the card responds.
This guide tells the truth about which credentials can and cannot be reproduced, because that honesty matters when you are deciding what to buy. American Key Cards supplies non-OEM credentials made to published specifications — and a core part of doing that responsibly is telling you, plainly, when a credential cannot be cloned and why that is good for your security.
The One Thing That Actually Decides It: Mutual Authentication
Verdict: if a card and reader cryptographically authenticate each other before any data moves, the card cannot be cloned. If the card just broadcasts its number, it can.
Most people sort access cards by frequency — “low-frequency 125 kHz prox is old and insecure; high-frequency 13.56 MHz smart cards are secure.” This is the single most common and costly misconception in access control. It is wrong.
The real dividing line is cryptographic mutual authentication:
- An unencrypted credential energizes in the reader’s field and immediately transmits its stored number in the clear. Any device that can listen to that RF signal captures the credential. It can then be written to a cheap programmable blank. Done.
- A cryptographically authenticated credential refuses to hand over anything until the reader proves it holds the correct secret key — and the card proves the same to the reader. The credential payload is AES-encrypted and, on the best platforms, digitally signed and bound to the specific chip. Capturing the transmission gets an attacker nothing usable.
A 13.56 MHz card with no real cryptography (the original legacy smart card) is clonable. A credential with strong mutual authentication (an encrypted AES smart card) is not. Frequency is a red herring. Keep that in mind as you read the table below.
The Master Clonability Table
This covers the credential families you are most likely to encounter in commercial, residential, and institutional access control. “Clonable today” reflects what is achievable with commercially available tools as of this writing.
| Credential family | Frequency | Encryption | Clonable today? | Notes |
|---|---|---|---|---|
Standard 125 kHz proximity (H10301 and most 125 kHz formats) | 125 kHz | None | Yes | Broadcasts a fixed number; reads and writes with a Proxmark3 + T5577 blank. The most-cloned class in the world. |
| EM4100 / EM4102 read-only prox | 125 kHz | None | Yes | The simplest read-only prox chip; trivially copied. |
| Extended 125 kHz formats (33/34/36-bit) | 125 kHz | None | Yes | Larger code space, but unencrypted RF — still clonable. |
| Standard / legacy 13.56 MHz smart card | 13.56 MHz | Legacy cipher (broken) | Yes | High frequency does not help; keys recovered in seconds with nested/darkside/hardnested attacks. |
| Secure 13.56 MHz smart card (highest security level) | 13.56 MHz | AES-128 | No | At its highest security level, mutual authentication makes it not practically clonable. |
| Encrypted 13.56 MHz smart card | 13.56 MHz | AES-128, CC EAL5+ | No | AES mutual authentication on a certified secure element. No public cloning attack. |
| Encrypted AES smart-credential platform (signed, chip-bound) | 13.56 MHz | AES-128 + signed container | No | Credential cryptographically bound to the chip; cannot be third-party programmed. |
| Early / legacy smart-card keying (publicly known keys) | 13.56 MHz | Weak / broken keys | Yes (legacy) | First-generation smart cards whose standard keys are public; cloning is demonstrated. End-of-life. |
Two patterns jump out of that table. First, every 125 kHz proximity format is clonable — frequency-band, not brand, determines this. Second, 13.56 MHz is split right down the middle: the old broken-cipher and first-generation chips are clonable, while the AES-based platforms hold.
The 125 kHz Proximity Cards: All Clonable
Verdict: every standard 125 kHz prox credential can be copied with a Proxmark3 and a few-dollar blank. None of them are secure against duplication.
This family includes standard 26-bit proximity cards, the extended 125 kHz formats, and read-only EM4100/EM4102 cards. They were designed in an era when the cloning hardware did not exist outside specialized labs. Today a Proxmark3 — a widely available RFID research tool — reads the credential in under a second when held within a few inches of the card, and writes it to a T5577 multi-frequency blank.
These formats add convenience features (larger code spaces, facility-code structures, dual-encoding) but none of them add encryption. The data leaves the card in the clear. For a full walkthrough of confirming exactly which 125 kHz format you have, see how to identify your access card format.
One nuance worth noting: a few 125 kHz formats add a secret check value the reader validates, which blocks naive copies — a meaningful speed bump, though not encryption in the modern sense. It is the exception that proves the rule that 125 kHz is, as a category, not clone-resistant.
The Original 13.56 MHz Smart Card: High Frequency, Still Broken
Verdict: the original 13.56 MHz smart card is clonable despite being a “smart card.” Its proprietary cipher has been broken for over a decade.
This is the credential that breaks the frequency myth most clearly. The original standard 13.56 MHz smart card runs at 13.56 MHz and uses a proprietary legacy stream cipher. It looks and feels like a secure smart card. It is not.
That legacy cipher was reverse-engineered and cryptographically broken years ago. A series of practical attacks — known as the darkside, nested, and hardnested attacks — recover the sector keys in seconds to minutes using nothing more than a Proxmark3 and free open-source software. Once the keys are recovered, the card’s contents can be read and written to a “magic” UID-changeable blank, producing a functional clone.
If your access system runs on this original smart card, you are not meaningfully more protected against cloning than a 125 kHz prox site, even though you paid for a higher-frequency platform. This is a genuinely important thing to know, and most vendors will not say it out loud.
The Cards That Actually Cannot Be Cloned
Verdict: secure smart cards at their highest security level and encrypted 13.56 MHz smart cards use AES mutual authentication and have no practical public cloning attack.
These are the credentials worth specifying when duplication resistance actually matters.
Encrypted 13.56 MHz smart cards are the workhorse of clone-resistant access control worldwide — used in transit systems, universities, and corporate campuses. They use AES-128 with mutual authentication: the reader and card each prove possession of the correct key before any application data is exchanged. The best of them add a Common Criteria EAL5+ certified secure element. There is no commercially available tool that clones a properly configured encrypted smart card.
Secure 13.56 MHz smart cards at their highest security level upgrade an older form factor to genuine AES-based authentication. The key word is highest security level — a card left in a lower security level does not get the full benefit. Configured correctly, it is not practically clonable.
Top-tier encrypted credential platforms wrap the credential in an encrypted, digitally signed container and use AES-128 mutual authentication. The strongest go further and cryptographically tie the credential to the specific chip, so a captured payload cannot be replayed or transplanted. Note that early / legacy smart cards — the first-generation platforms whose standard keys became public — are a different story: those keys are known and the cards are clonable, which is exactly why the industry replaced them.
Why American Key Cards Will Not Sell You a “Clone” of a Secured Card
Here is where we will be more candid than most suppliers are willing to be.
For unencrypted 125 kHz prox and the broken original smart card, the credential is just a number written to a chip. American Key Cards can supply compatible credentials for those systems — programmed to your facility code and card-number range from scratch, made to the published specification, never copied from one of your existing cards. That is a legitimate, by-specification product, the same way an aftermarket key blank is cut to a code rather than carved from your existing key.
For encrypted AES smart cards, the situation is different — and we will tell you so directly: we cannot and will not sell a clone of one of these credentials, because it is cryptographically impossible. The data is AES-encrypted and bound to a facility-specific key set (and, on the strongest platforms, to the individual chip). No third party can read it, copy it, or re-encode a blank to impersonate it without the issuing organization’s secret keys and the manufacturer’s issuance infrastructure.
We consider that a feature, not a limitation. If we could clone your encrypted badge, so could anyone else — and that would mean your “high-security” credential was not secure at all. Any vendor advertising aftermarket clones of encrypted AES credentials is either selling something that will not work or misrepresenting what they are doing. We would rather tell you the truth and point you to your authorized issuer for those platforms.
This is also why “which card can’t be cloned” is the right question to ask before you buy or upgrade: the answer tells you exactly how much real-world duplication protection your money is buying.
So Which Should You Choose?
Match the credential to your actual threat model rather than to a frequency label:
- Low-risk doors, convenience-driven (gyms, common amenities, low-sensitivity offices): 125 kHz prox is everywhere and cheap to support. Just understand the cards are copyable, and order replacements as compatible, by-specification credentials.
- Mid-to-high security (corporate floors, multi-tenant buildings, anything with compliance exposure): specify encrypted 13.56 MHz smart cards or a secure smart card at its highest security level. These are mainstream, well-supported, and genuinely clone-resistant.
- High security and future-proofing (federal, financial, healthcare, critical infrastructure, mobile credentials): a top-tier encrypted AES credential platform, with an encrypted smart card as a strong alternative on existing reader fleets.
- Anything still on a legacy or original smart card: treat it as clonable and plan a migration to an AES platform.
A practical reality: most facilities run a mix. Keep prox on the low-risk doors, push AES credentials to the doors that matter, and upgrade readers in phases.
Get an Honest Answer for Your Specific System
If you are not sure which credential your readers actually use — or whether the cards you are holding can be cloned — that is exactly the kind of question we are happy to answer straight. Browse the full product catalog to compare technologies side by side, or contact American Key Cards with your reader model and a photo of your existing card. We will tell you what you have, whether it is clonable, whether we can supply compatible credentials for it, and — if it is a secured AES platform — exactly why we cannot, and who can.
Every credential we supply is backed by our lifetime parts and workmanship guarantee. And every answer we give you about security is the truth, including the times the truth is “this card cannot be cloned, and that is a good thing for you.”
Frequently asked questions
Which access cards genuinely cannot be cloned?
Credentials that use cryptographic mutual authentication: encrypted 13.56 MHz smart cards running AES, and secure smart cards operating at their highest security level (also AES). On these cards the credential data is encrypted and the reader and card must prove their identities to each other before any data is exchanged, so the transmission cannot simply be captured and replayed. There is no commercially available tool that clones these as of this writing.
Are 13.56 MHz smart cards clonable?
It depends entirely on which generation. The original standard 13.56 MHz smart card (using a proprietary legacy cipher) is broken and clonable — practical attacks recover the keys in seconds to minutes. Secure and encrypted 13.56 MHz smart cards running AES are not practically clonable. So 'is a smart card secure?' has no single answer; the chip generation is everything.
Is an encrypted 13.56 MHz smart card secure?
Yes. Encrypted 13.56 MHz smart cards use AES-128 encryption with mutual authentication between card and reader, and the best ones use an independently certified secure element (Common Criteria EAL5+). Encrypted smart cards are among the most widely deployed clone-resistant credential platforms in the world and have no publicly known practical cloning attack.
Can a top-tier encrypted credential be cloned?
No. The strongest encrypted credentials use AES-128 mutual authentication and store the credential inside a digitally signed container that is cryptographically bound to the specific chip. Even a full capture of the card's transmission cannot be replayed or transplanted to another chip. There is no public cloning attack against them, and they cannot be re-encoded by third parties because programming requires the issuer's secure issuance infrastructure.
What is the single factor that decides whether a card can be cloned?
Cryptographic mutual authentication, not frequency. People assume 13.56 MHz 'smart' cards are secure and 125 kHz 'prox' cards are not, but that is wrong. The original 13.56 MHz smart card is a 13.56 MHz card and is broken. What actually matters is whether the card encrypts its data and forces the reader to authenticate before the card responds. Cards that do this cannot be cloned; cards that broadcast their data in the clear can.