
RFID Skimming Is Getting Easier. The Threat Has Changed.
Skimming attacks require no contact, leave no trace, and are increasingly easy to execute. A hardware backdoor disclosed in August 2024 means a category of access card that organisations trusted as secure can now be cloned in minutes using standard equipment. The risk has changed. The carry habit hasn't.
Contactless payment cards, e-passports, and access credentials all transmit data wirelessly. That convenience has a cost: any reader within range, a device small enough to conceal in a pocket and available online for under $30, can capture that data without touching your wallet, your bag, or you.
You won’t feel it. There’s no alert. No declined transaction to notice. The card stays in your wallet and continues working normally. The only thing that changes is that someone else now has a copy of what’s on it.
This has been a known risk for years. What changed in August 2024 is the scale of exposure.
The MIFARE Backdoor
Security researchers at Quarkslab disclosed a hardware backdoor in a widely deployed generation of RFID cards manufactured by Shanghai Fudan Microelectronics: the FM11RF08 and FM11RF08S series. These cards are embedded in hotel key systems, access control infrastructure, and transit networks globally. They have been marketed and sold as secure.
The backdoor allows the cards to be cloned in minutes, using standard equipment, by anyone with the right reader. The cards cannot be patched: the vulnerability is in the hardware itself.
The practical result: a category of card that organisations have relied on as secure is not. And the tools required to exploit it remain cheap, compact, and widely available.
That exchange happens whether or not you initiated it.
How Skimming Works in Practice
RFID operates at 125kHz and 13.56MHz. NFC (used for contactless payments and e-passports) operates at 13.56MHz. Both communicate at short range, but short range is not zero range. In a coffee queue, a packed train, an airport terminal: the physical proximity that makes contactless payment convenient is the same proximity that makes passive interception possible.
A reader doesn’t need to ask your permission. It doesn’t need to touch the card. It transmits a signal; your card responds. That exchange happens whether or not you initiated it.
Access credential harvesting works on the same principle. An attacker with a concealed reader near a building entrance or co-working space can capture the credential data from cards carried by anyone who walks past. No interaction, no confrontation, no trace.
The Signal Flare
The OffGrid Signal Flare is a passive RFID and NFC blocking card. Credit card dimensions: it slides into any wallet slot and sits alongside your existing cards. No batteries, no activation, no setup.
The mechanism is signal interference. The Signal Flare disrupts the RF field around adjacent cards, preventing a reader from completing the exchange required to capture data. Your contactless cards stay in your wallet. You don’t need to remove them, sleeve them individually, or change how you carry them.
It blocks RFID at 125kHz and 13.56MHz, and NFC at 13.56MHz, covering contactless payment cards, e-passports, transit cards, and access credentials. Sold as a 2-pack: one for your everyday wallet, one for a travel wallet or backup carry.
OffGrid is a product line from EDEC Digital Forensics, a company that has built Faraday and signal isolation technology for law enforcement and defence applications since 2009. The Signal Flare is consumer-facing, but it comes from a manufacturer that builds to operational standards for professional buyers. That lineage is worth knowing.
