Which Access Cards Can't Be Cloned? (Prox vs MIFARE vs DESFire vs Seos)
The short answer: cards that use cryptographic mutual authentication — MIFARE DESFire EV1/EV2/EV3, MIFARE Plus in security level 3, and HID iCLASS SE and Seos — cannot be practically cloned. Almost everything else can. That includes every 125 kHz proximity card on the market and, importantly, the original MIFARE Classic, which is a 13.56 MHz card but is cryptographically broken. The deciding factor is not the frequency printed on the spec sheet — it is whether the card encrypts its data and forces the reader to prove its identity before the card responds.
This guide tells the truth about which credentials can and cannot be reproduced, because that honesty matters when you are deciding what to buy. American Key Cards supplies non-OEM credentials made to published specifications — and a core part of doing that responsibly is telling you, plainly, when a credential cannot be cloned and why that is good for your security.
The One Thing That Actually Decides It: Mutual Authentication
Verdict: if a card and reader cryptographically authenticate each other before any data moves, the card cannot be cloned. If the card just broadcasts its number, it can.
Most people sort access cards by frequency — “low-frequency 125 kHz prox is old and insecure; high-frequency 13.56 MHz smart cards are secure.” This is the single most common and costly misconception in access control. It is wrong.
The real dividing line is cryptographic mutual authentication:
- An unencrypted credential energizes in the reader’s field and immediately transmits its stored number in the clear. Any device that can listen to that RF signal captures the credential. It can then be written to a cheap programmable blank. Done.
- A cryptographically authenticated credential refuses to hand over anything until the reader proves it holds the correct secret key — and the card proves the same to the reader. The credential payload is AES-encrypted and, on the best platforms, digitally signed and bound to the specific chip. Capturing the transmission gets an attacker nothing usable.
A 13.56 MHz card with no real cryptography (MIFARE Classic) is clonable. A credential with strong mutual authentication (DESFire EV3, Seos) is not. Frequency is a red herring. Keep that in mind as you read the table below.
The Master Clonability Table
This covers the credential families you are most likely to encounter in commercial, residential, and institutional access control. “Clonable today” reflects what is achievable with commercially available tools as of this writing.
| Credential family | Frequency | Encryption | Clonable today? | Notes |
|---|---|---|---|---|
HID Prox (H10301, ProxCard II, ISOProx) | 125 kHz | None | Yes | Reads and writes with a Proxmark3 + T5577 blank. The most-cloned format in the world. |
| Kantech ioProx (XSF) | 125 kHz | None | Yes | XSF expands the code space but adds no encryption. Still clonable. |
| Indala (FlexPass 26-bit / 27-bit) | 125 kHz | None | Yes | Custom Indala encoding, but unencrypted RF. (Indala ASP/FlexSecur adds a check value — see notes below.) |
| AWID (26-bit / 37-bit) | 125 kHz | None | Yes | Standard passive prox; no cryptographic layer. |
| EM4100 / EM4102 | 125 kHz | None | Yes | The simplest read-only prox chip; trivially copied. |
| Keri / others (125 kHz prox) | 125 kHz | None | Yes | Same class of technology, same exposure. |
| MIFARE Classic 1K / 4K | 13.56 MHz | Crypto-1 (broken) | Yes | High frequency does not help. Crypto-1 is broken; keys recovered in seconds with nested/darkside/hardnested attacks. |
| MIFARE Plus (SL3) | 13.56 MHz | AES-128 | No | In security level 3 with AES enabled, mutual authentication makes it not practically clonable. |
| MIFARE DESFire EV1 | 13.56 MHz | AES (3DES/AES) | No | AES with mutual authentication. Not practically clonable. |
| MIFARE DESFire EV2 / EV3 | 13.56 MHz | AES-128, CC EAL5+ | No | AES mutual authentication on a certified secure element. No public cloning attack. |
| HID iCLASS legacy (standard / Elite) | 13.56 MHz | Weak / broken keys | Yes (legacy) | Standard-key legacy iCLASS keys are publicly known and cloning is demonstrated. Elite keying is stronger but the platform is end-of-life. |
| HID iCLASS SE | 13.56 MHz | AES-128 + SIO | No | Secure Identity Objects + AES mutual authentication. Not clonable; cannot be third-party programmed. |
| HID Seos | 13.56 MHz | AES-128 + SIO Data Binding | No | Credential cryptographically bound to the chip. The strongest mainstream HID platform. Not clonable. |
Two patterns jump out of that table. First, every 125 kHz proximity format is clonable — frequency-band, not brand, determines this. Second, 13.56 MHz is split right down the middle: the old Crypto-1 and legacy-iCLASS chips are broken, while the AES-based platforms (DESFire, MIFARE Plus SL3, iCLASS SE, Seos) hold.
The 125 kHz Proximity Cards: All Clonable
Verdict: every standard 125 kHz prox credential can be copied with a Proxmark3 and a few-dollar blank. None of them are secure against duplication.
This family includes HID Prox H10301, HID ProxCard II and ISOProx, Kantech ioProx, Indala FlexPass, AWID, EM4100/EM4102, and Keri proximity cards. They were designed in an era when the cloning hardware did not exist outside specialized labs. Today a Proxmark3 — a widely available RFID research tool — reads the credential in under a second when held within a few inches of the card, and writes it to a T5577 multi-frequency blank.
These formats add convenience features (larger code spaces, facility-code structures, dual-encoding) but none of them add encryption. The data leaves the card in the clear. For the format-by-format honest breakdown, see our dedicated guides on whether HID Prox cards can be cloned, whether Kantech ioProx cards can be cloned, whether DoorKing DKProx cards can be cloned, and whether Indala FlexPass cards can be cloned.
One nuance worth noting: Indala ASP / FlexSecur adds a secret check value the reader validates, which blocks naive copies — a meaningful speed bump, though not encryption in the modern sense. It is the exception that proves the rule that 125 kHz is, as a category, not clone-resistant.
MIFARE Classic: A 13.56 MHz Card That Is Still Broken
Verdict: MIFARE Classic is clonable despite being a “smart card.” The Crypto-1 cipher has been broken for over a decade.
This is the credential that breaks the frequency myth most clearly. MIFARE Classic 1K and 4K run at 13.56 MHz and use NXP’s proprietary Crypto-1 stream cipher. They look and feel like secure smart cards. They are not.
Crypto-1 was reverse-engineered and cryptographically broken years ago. A series of practical attacks — known as the darkside, nested, and hardnested attacks — recover the sector keys in seconds to minutes using nothing more than a Proxmark3 and free open-source software. Once the keys are recovered, the card’s contents can be read and written to a “magic” UID-changeable blank, producing a functional clone.
If your access system runs on MIFARE Classic, you are not meaningfully more protected against cloning than a 125 kHz prox site, even though you paid for a higher-frequency platform. This is a genuinely important thing to know, and most vendors will not say it out loud.
The Cards That Actually Cannot Be Cloned
Verdict: MIFARE Plus (SL3), DESFire EV1/EV2/EV3, iCLASS SE, and Seos use AES mutual authentication and have no practical public cloning attack.
These are the credentials worth specifying when duplication resistance actually matters.
MIFARE DESFire EV1 / EV2 / EV3 is the workhorse of clone-resistant access control worldwide — used in transit systems, universities, and corporate campuses. It uses AES-128 with mutual authentication: the reader and card each prove possession of the correct key before any application data is exchanged. DESFire EV2 and EV3 add a Common Criteria EAL5+ certified secure element. There is no commercially available tool that clones a properly configured DESFire credential.
MIFARE Plus in security level 3 upgrades the Classic form factor to genuine AES-based authentication. The key word is SL3 — a MIFARE Plus card left in a lower security level does not get the full benefit. Configured correctly in SL3, it is not practically clonable.
HID iCLASS SE and Seos both wrap the credential in a Secure Identity Object (SIO) — an encrypted, digitally signed container — and use AES-128 mutual authentication. Seos goes further with SIO Data Binding, which cryptographically ties the credential to the specific chip so a captured payload cannot be replayed or transplanted. For the detailed differences, see our comparison of iCLASS SE versus Seos and the HID Seos and iCLASS SE format pages. Note that legacy iCLASS — the pre-SE platform — is a different story: its standard keys are public and it is clonable, which is why HID replaced it. Our breakdown of whether legacy HID iCLASS can be cloned walks through exactly where that platform stands today.
Why American Key Cards Will Not Sell You a “Clone” of a Secured Card
Here is where we will be more candid than most suppliers are willing to be.
For unencrypted 125 kHz prox and broken MIFARE Classic, the credential is just a number written to a chip. American Key Cards can supply compatible credentials for those systems — programmed to your facility code and card-number range from scratch, made to the published specification, never copied from one of your existing cards. That is a legitimate, by-specification product, the same way an aftermarket key blank is cut to a code rather than carved from your existing key.
For DESFire EV2/EV3, MIFARE Plus SL3, iCLASS SE, and Seos, the situation is different — and we will tell you so directly: we cannot and will not sell a clone of one of these credentials, because it is cryptographically impossible. The data is AES-encrypted and bound to a facility-specific key set (and, on Seos, to the individual chip). No third party can read it, copy it, or re-encode a blank to impersonate it without the issuing organization’s secret keys and the manufacturer’s issuance infrastructure.
We consider that a feature, not a limitation. If we could clone your Seos badge, so could anyone else — and that would mean your “high-security” credential was not secure at all. Any vendor advertising aftermarket DESFire EV3, iCLASS SE, or Seos “clones” is either selling something that will not work or misrepresenting what they are doing. We would rather tell you the truth and point you to your authorized issuer for those platforms.
This is also why “which card can’t be cloned” is the right question to ask before you buy or upgrade: the answer tells you exactly how much real-world duplication protection your money is buying.
So Which Should You Choose?
Match the credential to your actual threat model rather than to a frequency label:
- Low-risk doors, convenience-driven (gyms, common amenities, low-sensitivity offices): 125 kHz prox is everywhere and cheap to support. Just understand the cards are copyable, and order replacements as compatible, by-specification credentials.
- Mid-to-high security (corporate floors, multi-tenant buildings, anything with compliance exposure): specify MIFARE DESFire EV2/EV3 or MIFARE Plus SL3. These are mainstream, well-supported, and genuinely clone-resistant.
- High security and future-proofing (federal, financial, healthcare, critical infrastructure, mobile credentials): HID Seos, with iCLASS SE as a strong alternative on existing SE/Signo reader fleets.
- Anything still on legacy iCLASS or MIFARE Classic: treat it as clonable and plan a migration to an AES platform.
A practical reality: most facilities run a mix. Keep prox on the low-risk doors, push AES credentials to the doors that matter, and upgrade readers in phases.
Get an Honest Answer for Your Specific System
If you are not sure which credential your readers actually use — or whether the cards you are holding can be cloned — that is exactly the kind of question we are happy to answer straight. Browse the full card-format catalog to compare technologies side by side, or contact American Key Cards with your reader model and a photo of your existing card. We will tell you what you have, whether it is clonable, whether we can supply compatible credentials for it, and — if it is a secured AES platform — exactly why we cannot, and who can.
Every credential we supply is backed by our lifetime parts and workmanship guarantee. And every answer we give you about security is the truth, including the times the truth is “this card cannot be cloned, and that is a good thing for you.”
Frequently asked questions
Which access cards genuinely cannot be cloned?
Credentials that use cryptographic mutual authentication: MIFARE DESFire EV1/EV2/EV3 (AES), MIFARE Plus running in security level 3 (AES), and HID iCLASS SE and Seos (AES with Secure Identity Objects). On these cards the credential data is encrypted and the reader and card must prove their identities to each other before any data is exchanged, so the transmission cannot simply be captured and replayed. There is no commercially available tool that clones these as of this writing.
Are MIFARE cards clonable?
It depends entirely on which MIFARE product. MIFARE Classic (the original 1K and 4K cards using the proprietary Crypto-1 cipher) is broken and clonable — practical attacks recover the keys in seconds to minutes. MIFARE Plus in security level 3 and MIFARE DESFire EV1/EV2/EV3 use AES and are not practically clonable. So 'is MIFARE secure?' has no single answer; the chip generation is everything.
Is DESFire secure?
Yes. MIFARE DESFire EV1, EV2, and EV3 use AES-128 encryption with mutual authentication between card and reader, and the secure element is independently certified (DESFire EV2/EV3 carry Common Criteria EAL5+ certification). DESFire is one of the most widely deployed clone-resistant credential platforms in the world and has no publicly known practical cloning attack.
Can Seos be cloned?
No. HID Seos uses AES-128 mutual authentication and stores the credential inside a digitally signed Secure Identity Object (SIO) that is cryptographically bound to the specific chip. Even a full capture of the card's transmission cannot be replayed or transplanted to another chip. There is no public cloning attack against Seos, and it cannot be re-encoded by third parties because programming requires HID's issuance infrastructure.
What is the single factor that decides whether a card can be cloned?
Cryptographic mutual authentication, not frequency. People assume 13.56 MHz 'smart' cards are secure and 125 kHz 'prox' cards are not, but that is wrong. MIFARE Classic is a 13.56 MHz card and is broken. What actually matters is whether the card encrypts its data and forces the reader to authenticate before the card responds. Cards that do this cannot be cloned; cards that broadcast their data in the clear can.