Blank NFC Cards Explained: MIFARE Classic vs NTAG vs DESFire
Blank NFC cards compared: NTAG213/215/216, MIFARE Ultralight, Classic 1K and DESFire EV3. Memory, security, phone support and which to pick for each project.
A blank NFC card is a contactless card with empty, rewritable memory. Which one to buy depends on the project: an NTAG213/215/216 for anything a phone should read, a MIFARE Classic 1K to learn how legacy badges work, and a DESFire EV3 when you need real security. This guide untangles the jargon, compares the chips in one table and matches each to a project you can build on your own equipment.
NFC, RFID, MIFARE: what the terms mean
These words get used interchangeably, but they mean different things.
- RFID (Radio Frequency Identification) is the broad family: a battery-less chip and antenna that answer a reader. There is low frequency (125 / 134 kHz, used by older building fobs and pet microchips) and high frequency (13.56 MHz).
- NFC (Near Field Communication) is a subset of 13.56 MHz RFID, standardised to work at a few centimetres and to be read by phones. The NFC Forum, an industry body, defines tag "types" and a shared data format, NDEF (the format that lets a phone open a URL or a contact card when you tap a tag).
- MIFARE is a brand of NXP Semiconductors, the Dutch chipmaker that dominates contactless chips. It covers very different families: Classic, Ultralight, DESFire and Plus.
- NTAG is another NXP range, designed specifically for consumer NFC.
The key point: all these cards run at 13.56 MHz, but they don't all speak the same protocol. That is why your phone reads one card and ignores another.
Chip comparison: memory, security, phone support
| Chip | User memory | Security | NFC Forum type | Readable by a phone | Typical use |
|---|---|---|---|---|---|
| NTAG213 | 144 bytes | Optional 32-bit password, originality signature | Type 2 | Yes, Android and iPhone | URLs, home automation, business cards |
| NTAG215 | 504 bytes | Same | Type 2 | Yes | Longer data, gaming figures |
| NTAG216 | 888 bytes | Same | Type 2 | Yes | Full contact card (vCard) |
| MIFARE Ultralight EV1 | 48 or 128 bytes | 32-bit password | Type 2 | Yes | Disposable tickets |
| MIFARE Ultralight C | 144 bytes | 3DES authentication | Type 2 | Yes | Tickets with some security |
| MIFARE Classic 1K | 1,024 bytes total (16 sectors), about 752 usable | Crypto1, broken and not recommended | No | Partly: not on iPhone, not on every Android | Learning, legacy badges |
| MIFARE Classic 4K | 4,096 bytes total (40 sectors) | Crypto1 | No | Partly | Same, more room |
| MIFARE DESFire EV3 | Several KB (the DESFire family comes in 2, 4 and 8 KB) | AES-128, Common Criteria EAL5+ certified | Type 4 (when formatted for NDEF) | Yes for NDEF reading | Access control, transport, closed-loop payment |
A few notes on reading the table.
NTAGs are the simplest. They follow NFC Forum Type 2, carry a 7-byte unique ID and an ECC originality signature (a cryptographic signature from NXP proving the chip is genuine). The 32-bit password protects against accidental or casual rewrites, not against a determined attacker.
MIFARE Classic is a special case. It has been in millions of badges and transport cards, but its proprietary cipher, Crypto1, was publicly broken in the late 2000s. NXP now lists MIFARE Classic EV1 1K as "Not Recommended for New Designs" and advises against relying on Crypto1 for security-critical uses. It remains a great teaching tool: its sectors, blocks and keys are the best way to understand how badges were designed, and why they were replaced.
DESFire EV3 is today's reference for serious access control. It uses AES-128, a standard and robust cipher, and is Common Criteria EAL5+ certified, an independent security evaluation. Its memory is organised into applications and files, each with its own keys. It costs more and takes more work to set up.
Which card for which project?
Home automation and shortcuts
A tag on the bedside table that turns off the lights, another by the door that runs a "leaving home" scene. Use NTAG213: 144 bytes is plenty, since the phone often just reads the ID or a short URL. On Android, automation apps can trigger an action on tap; on iPhone, the Shortcuts app's Automation tab does the same. Home Assistant can also use NFC tags as triggers.
NFC business card
An NTAG216 holds a full contact card. Simpler and more flexible: write a URL on an NTAG213 that points to a page with your details. You can then update the page without rewriting the card.
Your own escape game or treasure hunt
NTAGs are ideal: each card carries a clue, a URL or an ID that your app or phone recognises. You can lock the tags once the game is ready so players can't overwrite them by mistake. It's the idea behind our upcoming NFC Escape Tag puzzle (planned for Christmas 2027, on the waitlist).
Learning how badges work
Get a few MIFARE Classic 1K cards and, if you can, a DESFire EV3. With a suitable reader, a research tool like the Proxmark3 Easy or a simple reader app, you'll see the difference between a card that identifies itself with a number and one that authenticates with an AES key. All of it on your own cards, which is exactly why blank cards are useful.
Quick summary
| Project | Recommended chip |
|---|---|
| Home-automation tag, link to a page | NTAG213 |
| Business card with a full vCard | NTAG216 |
| Escape game, treasure hunt | NTAG213 or NTAG215 |
| Understanding legacy badges | MIFARE Classic 1K |
| Studying modern access control | DESFire EV3 |
"Magic" cards: what they are for in a lab
When shopping for blanks you'll come across "magic cards", sometimes labelled Gen1a, Gen2 or CUID. They are MIFARE Classic-compatible cards, not made by NXP, whose identifier (UID) can be rewritten. On a genuine card, the UID is programmed at the factory and never changes.
Why do they exist? Because many older systems simply read a card's UID to decide whether to open a door. A UID is not a secret: it is sent in the clear to every reader. In a lab, on a system you run, a magic card lets you test one simple question: "does my reader trust the ID alone?" If it does, the system needs to move to cryptographic authentication, typically DESFire EV3 with proper key management.
That is the defensive use of these cards, and the only one we recommend. Reproducing the badge of a building, an employer or anyone else without permission is a criminal offence in France (unauthorised access to a system, Code pénal article 323-1) and in most other countries. For the legal picture around RFID tools in France, read what the law actually says about the Flipper Zero and similar tools. If you're weighing up research hardware, our Proxmark3 Easy vs RDV4 comparison will help.
How to tell a genuine NXP chip
Plenty of "MIFARE-compatible" cards come from other manufacturers. They aren't necessarily bad, but they may behave differently and don't come with NXP's guarantees. A few ways to check what you're buying:
- The NXP TagInfo app, free on Android and iOS, identifies the chip's manufacturer and exact part. On chips that support it (NTAG21x, Ultralight EV1, DESFire EV2/EV3), it checks the originality signature: an ECC signature that NXP computes from the UID and that cannot be forged without NXP's private key.
- Price. A genuine DESFire EV3 costs considerably more than an NTAG. A "DESFire" sold at NTAG prices deserves a closer look.
- Wording. "MIFARE compatible" or "1K chip" is not "NXP MIFARE Classic EV1". A reputable seller names the exact part.
- Traceability. Buy from a reseller who can tell you where the cards come from and who answers if a card isn't what was promised.
For a personal project, a non-NXP chip may be fine. For learning, prefer genuine chips: you study the real chip's behaviour, not a clone's quirks.
Our blank NFC cards
If you want a pack to start your home-automation tags, business cards or your own escape game, our blank NFC cards (pack of 15, €14.90) use genuine NXP chips and are rewritable. They'll be back soon: sign up on the product page to be notified when they're available.
Frequently asked questions
Which blank NFC card works best with a phone?
An NTAG213, NTAG215 or NTAG216. These chips follow the NFC Forum Type 2 specification and can be read and written by practically every NFC phone, Android and iPhone alike. Pick the size based on what you store: 144 bytes is plenty for a URL or a home-automation trigger.
Why can't my iPhone read my MIFARE Classic card?
MIFARE Classic uses a proprietary protocol (Crypto1) that is not part of the NFC Forum standards. iPhones and some Android phones don't support it. For anything a phone needs to read, use an NTAG.
Is MIFARE Classic still secure?
Not for anything that matters. NXP lists MIFARE Classic EV1 1K as "Not Recommended for New Designs" and advises against relying on its Crypto1 cipher for security-critical uses. It is still handy for learning and for projects with no security stakes.
What is a "magic" card?
A MIFARE-compatible card whose identifier (UID), normally fixed at the factory, can be changed. In a lab, it lets you check that a system you run doesn't rely on the UID alone. Using one to reproduce someone else's badge without permission is illegal.