Can legacy iCLASS 2K cards really be cloned?
Yes, legacy HID iCLASS 2K and 16K cards can be cloned. The security of legacy iCLASS depends on a proprietary HID cipher that academic researchers fully reverse-engineered and published in 2012. Once the cipher and the keys behind it are in the public record, the encryption that was supposed to stop copying no longer does — the card can be read and reproduced by someone with the right equipment and knowledge.
This is not a theoretical footnote. The break covers both the 2K and 16K memory versions, because they share the same cipher and 64-bit key structure. For a deep technical account of the Picopass chip and the full disclosure history, see our companion explainer on legacy HID iCLASS (Picopass 2K/16K). This page focuses on what that break means for your decision.
How hard is it to clone a legacy iCLASS card?
Cloning a legacy iCLASS card is not as trivial as copying a 125 kHz proximity card, but the barrier is far lower than most owners assume. Because the keys are public, the hard research work is already done — an attacker no longer has to break anything, only apply what was published. The 2012 researchers reported recovering the iCLASS Elite master key "from only 15 authentication attempts," a process that "can be fully executed within 5 seconds on an ordinary laptop."
The standard legacy iCLASS population was even more exposed: researchers found that iCLASS Standard cards "worldwide share the same master key." In practical terms, the difficulty of cloning legacy iCLASS today is a function of access to a card and off-the-shelf tools, not of cracking cryptography. That is the definition of a credential that is no longer clone-resistant.
Does that mean my building is at risk right now?
Legacy iCLASS being cloneable does not mean every building is being attacked — it means the technical protection you are relying on is gone. Whether that translates into real risk depends on the site: a low-traffic interior door is a very different exposure from a perimeter entrance, a data centre, a pharmacy, or a cash room. The honest framing is that legacy iCLASS should now be treated like an unencrypted credential for threat-modelling purposes, because its cipher offers no assurance.
The reasonable response is proportionate, not panic. High-value and perimeter openings warrant prompt upgrade; lower-risk internal doors can be scheduled into a phased migration. What is not defensible is assuming legacy iCLASS still provides meaningful clone resistance — the public record says it does not.
Should I re-card, or upgrade readers and credentials?
The key decision for a legacy iCLASS site is whether to simply re-issue more legacy cards or to upgrade the technology. Re-issuing legacy iCLASS cards changes the numbers on the cards but not the broken cipher underneath, so it does not restore clone resistance. Upgrading the readers and credentials to iCLASS SE or Seos does, by replacing the proprietary cipher with AES-128.
| Option | What it fixes | Trade-off |
|---|---|---|
| Re-issue legacy iCLASS cards | New card numbers only | Cipher still broken — no clone resistance gained |
| Upgrade to iCLASS SE (SIO) | AES-128, site / diversified keys | New credentials; readers must support SE |
| Upgrade to Seos | AES-128, mobile-ready, highest tier | New credentials; best long-term end-state |
What does an upgrade to iCLASS SE or Seos involve?
Upgrading from legacy iCLASS to iCLASS SE or Seos is a phased project, not a single cutover. The usual path is to install multiCLASS SE or HID Signo readers, which read legacy iCLASS, iCLASS SE, and 125 kHz proximity at the same door. That lets every existing credential keep working while you re-issue users onto AES-128 iCLASS SE or Seos cards in batches, so no one is locked out during the transition.
Once all readers are upgraded and users are re-badged, legacy iCLASS can be switched off. Because iCLASS SE and Seos store identity in an encrypted, signed Secure Identity Object with no published break, the end-state genuinely closes the cloning exposure that the 2012 disclosure opened — which is why HID positions SE and Seos as the migration destination.
Where legacy proximity fits, and can I buy a compatible legacy iCLASS card?
No — Security ID Systems does not supply cloned or aftermarket legacy iCLASS cards, even though the cipher is public. If a site genuinely still needs legacy iCLASS credentials during a transition, the legitimate source is HID or your integrator. Our recommendation for legacy iCLASS is to upgrade, not to add more of a broken technology.
During an upgrade, most sites keep some doors, gates, or parking on 125 kHz proximity for a while. Those open proximity formats we do encode as fully compatible credentials that read identically on your existing readers — a practical way to cover the openings that are not yet cut over to secure 13.56 MHz.
Compatible formats we do supply
We do not supply cloned legacy iCLASS cards — but the 125 kHz proximity formats most sites still run during an upgrade are ones we encode as fully compatible credentials that read identically on your existing readers.
Sources & references
HID Global and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.