An NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.
About this app
This is a low-level tool for reading, writing and analyzing MIFARE Classic RFID tags. It is designed for users who have at least basic familiarity with the MIFARE Classic technology. It provides several features to interact with (and only with) MIFARE Classic RFID-Tags.
• Read MIFARE Classic tags
• Save, edit and share the tag data you read
• Write to MIFARE Classic tags (block-wise)
• Clone MIFARE Classic tags
(Write dump of a tag to another tag; write 'dump-wise')
• Key management based on dictionary-attack
(Write the keys you know in a file (dictionary).
MCT will try to authenticate with these keys against all sectors and read as much as possible.)
• Format a tag back to the factory/delivery state
• Write the manufacturer block of special MIFARE Classic tags
• Use external NFC readers like ACR 122U
• Create, edit, save and share key files (dictionaries)
• Decode & Encode MIFARE Classic Value Blocks
• Decode & Encode MIFARE Classic Access Conditions
• Display generic tag information
• Display the tag data as highlighted hex
• Display the tag data as 7-Bit US-ASCII
• Display the MIFARE Classic Access Conditions as a table
• Display MIFARE Classic Value Blocks as integer
• Calcualate the BCC
• Quick UID clone feature
• Import/export/convert files
• In-App (offline) help and information
• It's open source ;)
More information can be found at the README.
It should work on most NFC-enabled devices but there are exceptions. Have a look at the list of devices which are known to be incompatible to MIFARE Classic.
MIFARE® is a registered trademark of NXP Semiconductors.
Licensed under GPL-3.0-only, by IKARUS Projects.
What's New in v4.3.1
Imported from the F-Droid repository index.
- * Target Android SDK 35.
- * Fixed one possible crash.
Version history
Jan 26, 2026 · 3.8 MB · Android API 19–35 · code 70
Imported from the F-Droid repository index.
- * Target Android SDK 35.
- * Fixed one possible crash.
SHA-256 1e230b26d97d119c7f8034af082fbe6cc41b99a955b6d699d951c59c456a086c
Jan 23, 2026 · 3.8 MB · Android API 19–34 · code 69
Imported from the F-Droid repository index.
- * Added feature to write to Value Blocks if only
- decrement/transfer/restore permissions are available
- (Thanks @IamMusavaRibica).
- * Use keys from dump when writing a dump first (speed-up).
- * Add key file with common keys for hotel cards
- (Thanks to @WillCaruana).
SHA-256 cfb13d8d5b42169aa902c7055c2e93212a9a826950bfb596621a774eeb671b48
Sep 6, 2024 · 3.8 MB · Android API 19–34 · code 68
Imported from the F-Droid repository index.
- * Make "cancel" during key map creation more responsive
- (Thanks to Alan Le Corre).
- * Added more well known keys to the extended key file.
- (extended-std.keys file will be updated automatically.)
- * Fixed several crashes.
- * Some minor code cleanup.
SHA-256 62b492a457c2c9088d6f6415f7a7af9c475e17907bff55a7cd83a87855c9d559
Will it run on your device?
78%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be de.syss.MifareClassicTool is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 4.3.0 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall MIFARE Classic Tool first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of MIFARE Classic Tool, and a listing is removed when the evidence for it stops holding up.
Get MIFARE Classic Tool
Every source we list for de.syss.MifareClassicTool is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
1e230b26d97d119c7f8034af082fbe6cc41b99a955b6d699d951c59c456a086c
Signing certificate
37d940651520f32f66eeb60f1dc8d30afa00951304f9936d9ddd2ee1623512f8
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.