What Is a Clone RFID Sticker and How Does It Work in Modern Security Systems?
Jul 27, 2026
Leave a message

A duplicator beeps and the screen says write successful. The sticker goes onto the back of a phone. At the door, the reader does nothing: no beep, no LED, no log entry. The customer is standing there with a product that tested fine ten minutes ago.
This is the most common support ticket we get from buyers who resell duplication, and in nearly every case the copier did exactly what it was supposed to. So the useful question about a clone RFID sticker is not whether the write worked. It is what else had to be true for that write to survive the trip from the bench to the door.

The Thin Carrier Nobody Reads the Datasheet On
Strip away the marketing and a rewritable RFID sticker 125kHz product is one thing: a writable chip and its antenna laminated into an adhesive-backed disc, usually 25, 30, or 40 mm across and around 0.9 mm thick, with a working range of roughly 1–10 cm. The low-frequency versions carry a T5577 or EM4305 chip rated for more than 100,000 write cycles and over ten years of data retention. Those numbers appear on every listing, and they are real.
What the listings never separate is the difference between a blank writable sticker and a finished copy. A blank T5577 clone RFID sticker leaves the factory with no card number in it. Present it to a door lock and nothing happens, because there is no credential data to offer yet. It has to be written first with a 125 kHz writer. This is one of the things we most often find when a customer sends returned stickers back to us for inspection.
So the physical spec on the label tells you almost nothing about whether a batch will work in the field. Everything that decides that sits in how the chip behaves, and in what the sticker's shape does to the field it depends on.

Two Frequencies, Two Completely Different Meanings of "Writing"
The word clone hides the fact that there are two unrelated technical paths underneath it, and confusing them is where sourcing goes wrong first.
Low-frequency 125 kHz credentials, meaning the EM4100/TK4100 family common in legacy access control, are duplicated by writing a new ID into a T5577 or EM4305 chip so that it presents the original's identity. High-frequency 13.56 MHz credentials based on MIFARE Classic work differently. The unique identifier lives in block 0, which on a standard chip is read-only, so a UID changeable RFID sticker is required before duplication is possible at all. The command sets these two families answer to are documented in detail by the open-source research community that maintains the Proxmark tooling (RfidResearchGroup), and the HF air interface itself is defined in ISO/IEC 14443.
For a buyer the translation is short: the frequency has to match the reader before any other question matters.
That sentence is true and it is also where most people stop, which is why so many batches still fail after the frequency checks out. Matching the frequency only gets the sticker into the conversation. Whether the reader accepts what it hears next depends on the chip's response characteristics, and that is a separate filter, applied by hardware you do not control. If the target system runs on 13.56 MHz, the UID-format and reader-behaviour questions are worth working through on their own before any sample is cut (MIFARE-class sourcing notes).
The Chip Generation Problem Most Suppliers Won't Raise
Here is the variable that decides whether a cloneable RFID sticker order runs quietly or turns into a permanent support queue, and it rarely appears on a spec sheet at all: the "magic" generation of the HF chip.
Mixing magic-chip generations inside one shipment is the fastest way to break a duplication operation's tooling.
Gen1a chips require a special backdoor wake-up command before block 0 can be rewritten. Gen2 chips are direct-write and accept an ordinary write command with no special sequence. One-time-write classes such as FUID stop answering the backdoor command after the first block 0 edit, which locks the copy permanently. Send a customer 5,000 pieces where 3,000 are Gen1a and 2,000 are Gen2, and if their programming station only issues the backdoor sequence, the Gen2 portion is scrap on arrival: not defective, just unprogrammable with the equipment they own. That is a five-figure write-off caused by a line on a purchase order that nobody filled in.
| Chip class | Block 0 write method | Re-writable after first copy | Typical buyer fit |
|---|---|---|---|
| Gen1a magic | Backdoor wake-up command | Yes, repeatedly | Operators with Proxmark-class tooling |
| Gen2 magic | Direct write, standard command | Yes, repeatedly | Mixed tool fleets, Android-based workflows |
| FUID / one-time | Backdoor, first edit only | No, locks after first write | Services that must prevent re-cloning downstream |
There is a second, slower failure mode worth knowing about. Early magic chips had a flaw in how they handled the brief field pause inside the ISO 14443-2 bit period. A genuine card would halt where some magic cards would carry on, and readers were subsequently updated with filters that fingerprint exactly that behaviour, which eventually pushed those chips out of production. For a reseller the consequence arrives late: a cloneable RFID sticker batch that passes every test today can be silently rejected by a firmware-updated reader eighteen months later, long after the invoice cleared.
No supplier can promise a reader manufacturer's future firmware behaviour, and anyone who does is guessing. What you can do is contractual rather than technical, and it comes down to four things. Fix the exact chip part number in the PO instead of accepting "MIFARE-compatible". Require lot numbers printed or recorded per carton, so a problem batch can be isolated instead of recalling a year of output. Retain sealed samples from each lot on both sides. And agree in advance who re-tests and who absorbs the cost if a customer's reader firmware changes mid-contract. None of that is exotic. It is standard practice in any regulated component supply, and it is what separates a traceable incident from an argument. The chip families behind these decisions are the same ones we build duplication-grade fobs and stickers around, which is why the part number belongs on the order rather than in the sales conversation.
A smaller trap sits inside the write step itself. The byte following the UID is a BCC checksum, the XOR of the four UID bytes, and writing an invalid value soft-bricks the chip. On a high-volume line that lands directly in the scrap rate, which is one more reason batch consistency is a manufacturing question rather than a matter of luck.
Why the Same Clone RFID Sticker Reads on Cardboard and Dies on a Phone
Industry habit says a sticker is a sticker and the only variables are diameter and adhesive. The most confusing failure in this product category says otherwise. Peel a working sticker off a box, put it on the back of a handset or onto a steel door plate, and the range collapses or disappears. The chip is fine. The physics changed.
At 125 kHz the sticker is not radiating in any meaningful sense. It is a magnetic coupling coil, and everything depends on flux passing through it cleanly. Metal nearby absorbs that energy through eddy currents and shifts the coil's inductance, pulling its resonant point away from where the reader is listening. High-Q tags suffer most from that shift, because a narrower transfer function means a small detune costs a large amount of received power. Orientation matters for the same reason: coupling is best when the sticker's coil sits parallel to the reader coil and falls off sharply toward 90 degrees (EDN). A phone is a harder case than plain sheet metal, because on top of the battery shield it stacks an NFC antenna and, increasingly, a wireless-charging coil into the same few square centimetres. Technicians who mount these under phone cases describe the antenna layer itself as roughly 0.4 mm, but the assembled stack, with foam spacer, reaching around 3 mm before it reads reliably, and the real work being the search for a clean position on the phone body (Elektroda). In practice the centre of the battery pack is close to hopeless, and the workable spots sit toward the edge of the housing, clear of the charging coil footprint.

The fix is a ferrite isolation layer between sticker and metal, which restores usable range by keeping flux out of the conductive surface. But an anti metal RFID sticker access control deployment still needs a decision rather than a checkbox, and the boundary is roughly this. If the target read distance is short, meaning a wall reader the user taps directly, repositioning alone often recovers enough range without any ferrite at all. If the sticker has to work across a full battery module or a steel door plate, ferrite is not optional and thickness matters. Component suppliers such as Laird publish standard sheet thicknesses of 0.05, 0.1 and 0.2 mm for this class of application, with 0.3 mm available on request, and the thin end of that range tends to under-perform at 125 kHz where the flux volume is larger. Air gap alone is the worst of both worlds: it adds bulk long before it adds range.
Which is why the deliverable here is a measurement rather than a claim. Absolute centimetre figures travel badly between projects, because in an inductively coupled system the ceiling is set by the reader: a useful rule of thumb is that maximum range lands at roughly one to two times the reader antenna's diameter. What does travel is the ratio. The table below is the acceptance envelope we work to on sticker builds, expressed against each batch's own bare-surface baseline:
| Mounting condition | Construction | Expected result vs baseline | Verdict |
|---|---|---|---|
| Bare non-metal surface | Standard 0.9 mm sticker | 100% by definition. On a 25–30 mm coin sticker against a typical wall reader this sits at the low end of the published 1–10 cm band | Reference for the batch |
| Steel plate, direct contact | Standard 0.9 mm sticker | Near zero, usually no read at all | Do not quote this build |
| Steel plate | Sticker + 0.2–0.3 mm ferrite | 60–80% | Accept at ≥60% |
| Phone back, over the battery | Standard 0.9 mm sticker | Near zero | Do not quote this build |
| Phone back, edge, clear of the charging coil | Sticker + 0.2–0.3 mm ferrite | 40–70%, varies by handset | Accept at ≥50% across three handset models |
Run this once against your own reader and write the model and antenna diameter beside the numbers. That single sheet answers most of what a customer will ask in the first month of a rollout. And if the phone-mount constraint turns out not to be essential, a keyfob housing sidesteps the entire problem, which is worth weighing before committing to a sticker form factor at all (fob selection for access control projects).

Where Cloning Legitimately Stops
There is a hard edge to this category, and being straight about it is part of being a credible supplier. Encrypted credentials such as DESFire EV3, SEOS, and the modern MIFARE generations are engineered specifically to resist duplication, and many current readers reject copies outright. Only legacy, unencrypted formats are practically duplicable. The wider market is moving that way deliberately: access-control readers are shifting away from low-frequency, easily copied proximity cards toward encrypted smart credentials and multi-factor authentication at the door (360iResearch). A duplicate RFID sticker for access control has a shrinking addressable base, and pretending otherwise does no buyer any favours.
"Compatible" is also not a synonym for "sound". When researchers examined the FM11RF08S, a chip sold widely as a MIFARE Classic-compatible replacement, they found a hardware backdoor reachable through a card-only attack, capable of exposing the user-defined keys (Quarkslab, via CyberInsider).
So what should a buyer do with that? Three things, all verifiable from your side of the table. Ask for the chip part number and the die vendor by name rather than the family, because "MIFARE-compatible 1K" describes a dozen chips with different security histories. Ask whether the supplier bonds its own chips or buys finished inlays, because a factory that runs its own chip-bonding line receives IC lots directly and can tell you where a batch came from, while a trading house reselling inlays usually cannot. And ask what happens when a die vendor is publicly compromised mid-contract: who qualifies the replacement, and on whose schedule. A supplier who has thought about that will answer in a sentence. One who hasn't will change the subject to price. The same logic governs how credential security gets specified in hospitality projects, where the security assumptions behind hotel key cards tend to be audited more closely than in residential work.
Authorization, Not Capability
Whether a copy is legal has almost nothing to do with whether it is technically possible. Access credentials are frequently treated as controlled property rather than personal items, and that status appears in apartment leases, condo bylaws, and HOA policies. The sanctioned route to an extra credential is usually the building's own issuance process, where the new copy is enrolled and the old one can be revoked and audited (Nimbio). Choosing to copy a key fob to a clone RFID sticker outside that process solves an inconvenience and creates an accounting gap, because management may not know the extra credential exists.
We supply businesses operating inside that authorized frame: locksmiths, credential-duplication services, systems integrators, and property operators reissuing credentials to their own tenants. We do not supply anything designed to defeat a security system, and stating that plainly is a feature rather than a disclaimer.
It also happens to describe our best customers. Buyers who already know which credentials they are authorized to reproduce, and who can document it, are the ones who ask the sourcing questions in the next section, because their risk is not legal exposure. It is a batch that does not perform.
What to Actually Specify, and What to Do When the Answer Is Vague
Most sourcing problems in this category are preventable at the purchase-order stage. Six things need pinning down that generic listings leave floating, and any serious OEM cloneable RFID sticker supplier should answer all six without hedging: the exact chip part number and its die source; the magic generation, stated explicitly as one-time-write versus rewritable; diameter and total thickness including any ferrite layer; adhesive grade and the substrate it is rated for; the outgoing test items, meaning frequency, read distance and data integrity, with the coverage rate; and lot traceability.
The list is the easy half. The half that actually protects a cloneable RFID sticker wholesale order is knowing what a weak answer means and what to do about it.
If the supplier gives a chip family instead of a part number, that usually means they buy finished inlays and do not control the die. Workable for low-risk volume, but stop asking them compatibility questions they cannot answer, and budget for your own incoming inspection. If they cannot state the magic generation, assume the batch is mixed and either reject it or price in a sorting step. If outgoing testing is described as "sampling" without a rate, ask for the rate and the AQL; a supplier who tests 100% will say so immediately, because it costs them money and they want credit for it. If they cannot provide lot numbers, you have no way to isolate a bad batch later, which is the single most expensive thing on this list to discover after the fact. And if the thickness quoted excludes the ferrite layer, re-measure the sample yourself, because that discrepancy is what turns a phone-mount project into a return.
On our side those questions have concrete answers because the process is controlled end to end: copper-wire antenna winding held to roughly ±0.1 mm, in-house chip bonding at a daily capacity in the hundreds of thousands, and 100% outgoing inspection rather than sampling. That ±0.1 mm is a frequency spec in disguise. Coil geometry sets inductance, inductance sets where the tag resonates, and a resonant point that wanders unit to unit means some pieces in a batch sit closer to the edge of the reader's tolerance window than others. Those are the pieces that read intermittently at the door while the rest of the shipment behaves, and they are also the reason validating a sample against the target reader before committing to volume is worth the two weeks it costs. If your project needs a form factor, thickness, or ferrite build that is not in a standard catalogue, that is a tooling and process question we handle in-house rather than a sourcing exercise.
A Note From One Long-Running Account
One of our longest relationships is with a French company at the top of the building-access-credential duplication market. Over five years they have taken roughly 500,000 copy fobs a year from us, and the decision that made it work was not price.
They specified a one-time-write FUID chip instead of an endlessly rewritable magic chip. The reason was commercial. Once a credential leaves their counter, they wanted it to be impossible for the end customer, or anyone downstream, to rewrite it into something else and have that traced back to their brand. We also cut new tooling so their fobs carry their own logo, which closed off the other half of the same problem: copy shops passing off generic housings as their product. Five years and roughly 2.5 million units later, the chip-generation question has never come back as a support issue, because it was answered once, in writing, before the first order was placed.
That is the whole argument for treating a clone RFID sticker as a specification rather than a commodity. If you want to work through the same trade-offs for your own volume, covering chip generation, thickness, ferrite build and test coverage, our engineers will do it against a real sample and spec sheet before you commit to tooling.
FAQ
What chip is used in a clone RFID sticker?
Most 125 kHz cloneable stickers use T5577 or EM4305, written to emulate common EM4100/TK4100 ID formats. The 13.56 MHz versions use a MIFARE Classic-compatible chip with a writable block 0. The two are not interchangeable, because the frequency must match the reader.
Why does a clone RFID sticker stop working on a phone or metal surface?
Metal absorbs the coil's energy and detunes it, cutting range sharply or blocking it entirely, and a phone's NFC antenna, battery and wireless-charging coil compound the effect. Stickers for these surfaces need a ferrite isolation layer, and the mounting position still has to be tested.
Can every access fob be copied to a sticker?
No. Encrypted credentials such as DESFire EV3 and SEOS are designed to resist duplication, and many modern readers reject copies. Only legacy, unencrypted formats are practically duplicable, and even then only with the system owner's authorization.
What should a buyer specify when ordering a T5577 RFID sticker in bulk?
Chip part number and die source, magic generation (one-time-write versus rewritable), diameter and total thickness, whether a ferrite layer is included, adhesive grade, outgoing test items with coverage rate, and lot traceability.
Send Inquiry

