
Portable NFC/RFID security tool for emulating and cloning contactless smartcards, reading tags, sniffing RF traffic, and recovering Mifare access keys.
This is NOT the official repository of ChameleonMini, a freely programmable portable tool for NFC security analysis that can emulate and clone contactless cards, read RFID tags, and sniff/log RF data. This repository brings support for the Chameleon Tiny.
Our Project is based on the open-source project ChameleonMini RevG by Kasper & Oswald. They also have their own Webshop.
Show HTML OutputMini or Tiny:
OFF positionDFU modeSettings tab, Send the Upgrade command while the Chameleon is connected
DFU modeDFU modeFurther information:
Mini:
OFF state, press and hold the black (Rev E) or yellow (Rev G) button near the USB while inserting it into the USB port
DFU modeupgrade and hit Enter
DFU modeDFU modeTiny:
upgrade and hit Enter
DFU modeDFU modeDFU modeDFU modeChameleonFirmwareUpgrade.bat file AS ADMIN to automatically start the firmware upgradeON
Connect to automatically connect the ChameleonDevice Information column, press BLE CMD Version 5 timesOTA upgrade page, click Auto UpgradeTools:
Connect to the Chameleon Mini or Tiny using the APP
ON on your phone and the APP will automatically connectMF_DETECTION_1K or MF_DETECTION_4K in the Card Slot modeDetection mode turned ONUID Card Number column
Clear button below to clear the last detection recordCrack buttonHistory button. The APP will automatically list the keys separately and save them for other software to useDump columnScanner in the plus sign in the upper right cornerAllow AccessDump file interface, which can be uploaded or edited at willDump column below, and click Upload below to upload to the card slot corresponding to the ChameleonUID Changeable (GEN1a) in the APP or directly send the command UIDMODE = 1 to turn it ON
UIDMODE = 0 to turn it OFFON, the card simulated by Chameleon will become a GEN1a card
SAK Mode button in the APP or directly send the command SAKMODE = 1 to turn it ON
SAKMODE = 0 to turn it OFFSAK Mode is turned ON, the card will feedback the real SAK value when it is foundSAK Mode is not turned on, the SAK is a fixed value of 08, and 0 blocks of data are ignored
OFF, press any button once to turn ON the Bluetooth power, and at the same time, display the current power with a white LEDON state, click any button to turn OFF the Bluetooth power, the power LED goes out, and the system sleepsON state, double click any button
OFF state, triple click any button times to turn ON the ChameleonOFF state, press the A button once to turn ON the Chameleon power| Option | Type | Length of UID | Memory Size |
|---|
| MF_classic_1K 4B/7B | M1 S50 | 4 Byte / 7 Byte | 1024 byte |
| MF_classic_4K 4B/7B | M1 S70 | 4 Byte / 7 Byte | 4096 byte |
| MF_classic_mini_4B | M1 mini S20 | 4 Byte / 7 Byte | 320 byte |
| MF_ultralight_C | M0 ultralight | 7 Byte | 192 byte |
| MF_ultralight_EV1_80B | M0 ultralight | 7 Byte | 80 byte |
| MF_ultralight_EV1_164B | M0 ultralight | 7 Byte | 164 byte |
| Vicinity | - | 8 Byte | 8192 byte |
| SL2S2002 | - | 8 Byte | 8192 byte |
| TITAGITSTANDARD | - | 8 Byte | 44 byte |
| EM4233 | - | 8 Byte | 208 byte |
| Option | Ability | Cracking Type | APP Supported |
|---|
| MF_DETECTION_1K | Detecting reader to obtain keys | MFKEY32V2 | List results directly |
| MF_DETECTION_4K | Detecting reader to obtain keys | MFKEY32V2 | List results directly |
| ISO14443A_READER | Reader Mode | - | Display UID |
| ISO14443A_SNIFF | Sniffing | - | Not supported |
| ISO15693_SNIFF | Sniffing | - | Supported |
| Option names | Description |
|---|
| NONE | Set this button to have no function |
| UID_RANDOM | Randomly generated UID number in the current card slot after pressing |
| UID_LEFT_INCREMENT | After pressing, the highest byte of the UID number plus one (hexadecimal) |
| UID_RIGHT_INCREMENT | After pressing the lowest byte of the UID number plus one (hexadecimal) |
| UID_LEFT_DECREMENT | After pressing, the highest byte of the UID number is reduced by one (hexadecimal) |
| UID_RIGHT_DECREMENT | After pressing, the lowest byte of the UID number is reduced by one (hexadecimal) |
| CYCLE_SETTINGS | Card slot number sequence will increase after pressing |
| CYCLE_SETTINGS_DEC | Card slot number sequence decreases after pressing |
| STORE_MEM | Immediately after pressing, the current card data in the temporary buffer is overwritten into the memory |
| RECALL_MEM | Immediately after pressing, the current card data in the memory is overwritten into the temporary buffer (Can be used to quickly restore card data) |
| TOGGLE_FIELD | Click once to turn off the antenna and click again to turn on the antenna function |
| STORE_LOG | Write the log data in the temporary cache to the memory, which can be saved even when power is off |
| CLEAR_LOG | Clear log data immediately after pressing |
| CLONE | Read the UID card number immediately after pressing, continue searching, and simulate immediately after reading the card |
| CLONE_MFU | Clones a Mifare Ultralight card that is in the range of the antenna to the current slot, which is then accordingly configured to emulate it |
| - | Rev.G Official by KAOS | Rev.E Old Rdv2.0 by ProxGrind | Rev.G by ProxGrind | Rev.G Tiny by ProxGrind |
|---|
| Simulation | Good performance, has blind area | Poor compatibility | Perfect performance | no blind area |
| As a reader | 1-2cm for white tag | 0cm for keyfob | × | 5-6cm for white tag |
| Read current | 170mA | × | 65mA | 60mA |
| BLE nrf52832 | × | × | √ | × |
| Li-ion battery | √ | × | √ | √ |
| Battery indicator | × | × | √ | × |
| Low power sleep | × | × | √ | √ |
| RF field wakeup | × | √ | √ | √ |
| Button wakeup | × | √ | √ | √ |
| Auto power off | × | √ | √ | √ |
| Official firmware compatible | √ | √ | √ | √ |
| Replaceable Antenna | × | × | √ | × |
| MFKEY32 crack | × | √ | √ | √ |
| 8 LED for slot | × | √ | √ | √ |
| Android APP | × | × | √ | √ |
| Firmware anti lost | × | × | √ | × |
| Rev.G Official By KAOS | Rev.E old RDV2.0 By PROXGRIND | Rev.G new RDV2.0 By PROXGRIND | M1 white tag |
|---|
| 122U r/w full data | 1-2 sector only | Smooth | Smooth | Smooth |
| 122U Range | 61mm | 41mm | 73mm | 71mm |
| PM3 r/w full data | 1-2 sector only | Smooth | Smooth | Smooth |
| PM3 Range | 57mm | 74mm | 88mm | 89mm |
| Phone NFC r/w full data | No | Smooth | Smooth | Smooth |
| Phone NFC Range | 25mm | 18mm | 33mm | 32mm |
| Magic back door | By default | No | Dual mode | No |
| SAK ATQA Support | No | No | Modifiable | No |
| Command | Effect Range | Description |
|---|
| UIDMODE? | All slot | Returns the configuration of the all slot |
| UIDMODE=? | All slot | Returns a list of all supported configurations |
| UIDMODE=[0;1] | All slot | Activates(1),deactivates(0),the magic card mode(It will has Chinese magic card back door) |
| SAKMODE? | Current slot | Returns the configuration of the current slot |
| SAKMODE=? | Current slot | Returns a list of all supported configurations |
| SAKMODE=[0;1] | Current slot | Activates(1),deactivates(0),the real SAK ATQA mode (the SAK ATQA will be mapped from block 0) |
| CONFIG=MF_DETECTION_1K | Current slot | Set current slot to detection 1K mode. |
| CONFIG=MF_DETECTION_4K | Current slot | Set current slot to detection 4K mode. |
| DETECTION=0 | Device | Clears the detection log memory |
| DETECTION? | Device | Wait for an XModem connection and then downloads the binary detection log data. |
| Card Type | Encoding Type | Whether the hardware supports | Does the software support | Whether the application layer supports | Note |
|---|
| Non13.56MHz | No | No | No | ||
| Mifare Ultralight | ISO14443A/106 kbit/s | Support | Support | Support | |
| Mifare Ultralight Ev1 | ISO14443A/106 kbit/s | Support | Support | Support | |
| MifareClassic1K/4K 4B/7B | ISO14443A/106 kbit/s | Support | Support | Support | |
| Mifare DESFire | ISO14443A High Rate | Supports low rates, or possibly higher rates | Only supported Low rate | No | |
| Mifare DESFire EV1 | ISO14443A High rate | Supports low rates, or possibly higher rates | Only supported Low rate | No | Backward compatible |
| Mifare DESFire EV2 | ISO14443A High rate | Supports low rates, or possibly higher rates | Only supported | Low rate | No |
| Mifare PLUS | ISO14443A High rate | Supports low rates, or possibly higher rates | Only supported Low rate | No | |
| Sniff Mode NTAG | ISO14443A 106 kbit/s | Support | Support | No | |
| LEGIC prime | LEGICprime/ ISO14443A/ ISO15693 | Possible but not supported | Possible but not supported | No | |
| HID iCLASS | 125kHz/ISO15693/ISO14443B | Possible but not supported | Possible but not supported | No | |
| Epass | ISO14443A/B | Supported / Supported | Low rate only / not supported | No | |
| TiTagIT Standard | ISO15693 | Support | Support | Support | |
| EM4233 | ISO15693 | Support | Support | Support |
| Encoding type | Whether the hardware supports | Does the software support | Whether the application layer supports | Note |
|---|
| Non-13.56MHz | Not Supported | Not Supported | Not Supported | |
| ISO 14443 A 106 kbit/s | Reader -> card Direction sniffing | Maybe support the other direction | Currently only supported Reader -> card Direction sniffing | |
| ISO 15693 | Support | Support | Support | Single subcarrier only |
| Card type | Encoding type | Whether the hardware stand by | Whether the software stand by | Whether the application layer supports | Note |
|---|
| Non13.56MHz | Not Supported | Not Supported | Not Supported | ||
| Mifare Ultralight | ISO14443A 106 kbit/s | Support | Support | SupportCommand: dump_mfu | |
| MifareClassic1K/4K 4B/7B | ISO14443A 106 kbit/s | Support | Support | Not Supported | No card reading instruction, encryption function has been implemented |