Legacy iCLASS — clone risk & upgrade decision

Can HID iCLASS Legacy 2K Cards Be Cloned? Should You Upgrade?

Yes — legacy HID iCLASS 2K and 16K cards can be cloned, because the proprietary cipher protecting them was reverse-engineered and published by researchers in 2012. Whether you should act depends on your exposure, but for most sites the right move is migrating readers and credentials to iCLASS SE or Seos, which use unbroken AES-128 cryptography.

Last updated 2026-07-29

Can legacy iCLASS 2K cards really be cloned?

Yes, legacy HID iCLASS 2K and 16K cards can be cloned. The security of legacy iCLASS depends on a proprietary HID cipher that academic researchers fully reverse-engineered and published in 2012. Once the cipher and the keys behind it are in the public record, the encryption that was supposed to stop copying no longer does — the card can be read and reproduced by someone with the right equipment and knowledge.

This is not a theoretical footnote. The break covers both the 2K and 16K memory versions, because they share the same cipher and 64-bit key structure. For a deep technical account of the Picopass chip and the full disclosure history, see our companion explainer on legacy HID iCLASS (Picopass 2K/16K). This page focuses on what that break means for your decision.

How hard is it to clone a legacy iCLASS card?

Cloning a legacy iCLASS card is not as trivial as copying a 125 kHz proximity card, but the barrier is far lower than most owners assume. Because the keys are public, the hard research work is already done — an attacker no longer has to break anything, only apply what was published. The 2012 researchers reported recovering the iCLASS Elite master key "from only 15 authentication attempts," a process that "can be fully executed within 5 seconds on an ordinary laptop."

The standard legacy iCLASS population was even more exposed: researchers found that iCLASS Standard cards "worldwide share the same master key." In practical terms, the difficulty of cloning legacy iCLASS today is a function of access to a card and off-the-shelf tools, not of cracking cryptography. That is the definition of a credential that is no longer clone-resistant.

Does that mean my building is at risk right now?

Legacy iCLASS being cloneable does not mean every building is being attacked — it means the technical protection you are relying on is gone. Whether that translates into real risk depends on the site: a low-traffic interior door is a very different exposure from a perimeter entrance, a data centre, a pharmacy, or a cash room. The honest framing is that legacy iCLASS should now be treated like an unencrypted credential for threat-modelling purposes, because its cipher offers no assurance.

The reasonable response is proportionate, not panic. High-value and perimeter openings warrant prompt upgrade; lower-risk internal doors can be scheduled into a phased migration. What is not defensible is assuming legacy iCLASS still provides meaningful clone resistance — the public record says it does not.

Should I re-card, or upgrade readers and credentials?

The key decision for a legacy iCLASS site is whether to simply re-issue more legacy cards or to upgrade the technology. Re-issuing legacy iCLASS cards changes the numbers on the cards but not the broken cipher underneath, so it does not restore clone resistance. Upgrading the readers and credentials to iCLASS SE or Seos does, by replacing the proprietary cipher with AES-128.

OptionWhat it fixesTrade-off
Re-issue legacy iCLASS cardsNew card numbers onlyCipher still broken — no clone resistance gained
Upgrade to iCLASS SE (SIO)AES-128, site / diversified keysNew credentials; readers must support SE
Upgrade to SeosAES-128, mobile-ready, highest tierNew credentials; best long-term end-state

What does an upgrade to iCLASS SE or Seos involve?

Upgrading from legacy iCLASS to iCLASS SE or Seos is a phased project, not a single cutover. The usual path is to install multiCLASS SE or HID Signo readers, which read legacy iCLASS, iCLASS SE, and 125 kHz proximity at the same door. That lets every existing credential keep working while you re-issue users onto AES-128 iCLASS SE or Seos cards in batches, so no one is locked out during the transition.

Once all readers are upgraded and users are re-badged, legacy iCLASS can be switched off. Because iCLASS SE and Seos store identity in an encrypted, signed Secure Identity Object with no published break, the end-state genuinely closes the cloning exposure that the 2012 disclosure opened — which is why HID positions SE and Seos as the migration destination.

Where legacy proximity fits, and can I buy a compatible legacy iCLASS card?

No — Security ID Systems does not supply cloned or aftermarket legacy iCLASS cards, even though the cipher is public. If a site genuinely still needs legacy iCLASS credentials during a transition, the legitimate source is HID or your integrator. Our recommendation for legacy iCLASS is to upgrade, not to add more of a broken technology.

During an upgrade, most sites keep some doors, gates, or parking on 125 kHz proximity for a while. Those open proximity formats we do encode as fully compatible credentials that read identically on your existing readers — a practical way to cover the openings that are not yet cut over to secure 13.56 MHz.

Compatible formats we do supply

We do not supply cloned legacy iCLASS cards — but the 125 kHz proximity formats most sites still run during an upgrade are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

HID Global and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID iCLASS legacy 2K/16K — common questions

Can HID iCLASS 2K cards be cloned?

Yes. Legacy iCLASS 2K and 16K cards rely on a proprietary cipher that researchers reverse-engineered and published in 2012. With the cipher and keys public, the cards can be read and reproduced, so legacy iCLASS is no longer clone-resistant. The secure fix is upgrading to iCLASS SE or Seos, which use AES-128.

Is it hard to clone an iCLASS card?

Not as hard as it should be. Because the keys were published in 2012, the cryptography no longer has to be broken — only applied. Researchers reported recovering the iCLASS Elite master key in about 15 authentication attempts in roughly 5 seconds on a laptop, and Standard iCLASS cards shared one global master key.

Should I upgrade my iCLASS system?

For most sites, yes — at least for perimeter and high-value doors. Re-issuing legacy iCLASS cards does not fix the broken cipher, so it adds no clone resistance. Upgrading readers and credentials to iCLASS SE or Seos replaces the proprietary cipher with unbroken AES-128, which is the only step that actually closes the exposure.

Can I keep my readers when upgrading from legacy iCLASS?

Often you upgrade the readers as part of the project. multiCLASS SE and HID Signo readers read legacy iCLASS, iCLASS SE, and 125 kHz proximity at the same door, so they can be installed first and read existing cards while you re-issue users onto AES-128 credentials in phases, avoiding a single disruptive cutover.

Does Security ID Systems supply cloned iCLASS 2K cards?

No. Security ID Systems does not supply cloned, copied, or aftermarket iCLASS credentials. If a site genuinely still needs legacy iCLASS cards during a transition, the legitimate source is HID or your integrator. Our recommendation for legacy iCLASS is to upgrade to iCLASS SE or Seos rather than add more legacy cards.