Skip to contentHacker gift guide · Christmas 2026

Blank NFC Cards Explained: MIFARE Classic vs NTAG vs DESFire

Blank NFC cards compared: NTAG213/215/216, MIFARE Ultralight, Classic 1K and DESFire EV3. Memory, security, phone support and which to pick for each project.

Published on 8 min read

A blank NFC card is a contactless card with empty, rewritable memory. Which one to buy depends on the project: an NTAG213/215/216 for anything a phone should read, a MIFARE Classic 1K to learn how legacy badges work, and a DESFire EV3 when you need real security. This guide untangles the jargon, compares the chips in one table and matches each to a project you can build on your own equipment.

NFC, RFID, MIFARE: what the terms mean

These words get used interchangeably, but they mean different things.

  • RFID (Radio Frequency Identification) is the broad family: a battery-less chip and antenna that answer a reader. There is low frequency (125 / 134 kHz, used by older building fobs and pet microchips) and high frequency (13.56 MHz).
  • NFC (Near Field Communication) is a subset of 13.56 MHz RFID, standardised to work at a few centimetres and to be read by phones. The NFC Forum, an industry body, defines tag "types" and a shared data format, NDEF (the format that lets a phone open a URL or a contact card when you tap a tag).
  • MIFARE is a brand of NXP Semiconductors, the Dutch chipmaker that dominates contactless chips. It covers very different families: Classic, Ultralight, DESFire and Plus.
  • NTAG is another NXP range, designed specifically for consumer NFC.

The key point: all these cards run at 13.56 MHz, but they don't all speak the same protocol. That is why your phone reads one card and ignores another.

Chip comparison: memory, security, phone support

ChipUser memorySecurityNFC Forum typeReadable by a phoneTypical use
NTAG213144 bytesOptional 32-bit password, originality signatureType 2Yes, Android and iPhoneURLs, home automation, business cards
NTAG215504 bytesSameType 2YesLonger data, gaming figures
NTAG216888 bytesSameType 2YesFull contact card (vCard)
MIFARE Ultralight EV148 or 128 bytes32-bit passwordType 2YesDisposable tickets
MIFARE Ultralight C144 bytes3DES authenticationType 2YesTickets with some security
MIFARE Classic 1K1,024 bytes total (16 sectors), about 752 usableCrypto1, broken and not recommendedNoPartly: not on iPhone, not on every AndroidLearning, legacy badges
MIFARE Classic 4K4,096 bytes total (40 sectors)Crypto1NoPartlySame, more room
MIFARE DESFire EV3Several KB (the DESFire family comes in 2, 4 and 8 KB)AES-128, Common Criteria EAL5+ certifiedType 4 (when formatted for NDEF)Yes for NDEF readingAccess control, transport, closed-loop payment

A few notes on reading the table.

NTAGs are the simplest. They follow NFC Forum Type 2, carry a 7-byte unique ID and an ECC originality signature (a cryptographic signature from NXP proving the chip is genuine). The 32-bit password protects against accidental or casual rewrites, not against a determined attacker.

MIFARE Classic is a special case. It has been in millions of badges and transport cards, but its proprietary cipher, Crypto1, was publicly broken in the late 2000s. NXP now lists MIFARE Classic EV1 1K as "Not Recommended for New Designs" and advises against relying on Crypto1 for security-critical uses. It remains a great teaching tool: its sectors, blocks and keys are the best way to understand how badges were designed, and why they were replaced.

DESFire EV3 is today's reference for serious access control. It uses AES-128, a standard and robust cipher, and is Common Criteria EAL5+ certified, an independent security evaluation. Its memory is organised into applications and files, each with its own keys. It costs more and takes more work to set up.

Which card for which project?

Home automation and shortcuts

A tag on the bedside table that turns off the lights, another by the door that runs a "leaving home" scene. Use NTAG213: 144 bytes is plenty, since the phone often just reads the ID or a short URL. On Android, automation apps can trigger an action on tap; on iPhone, the Shortcuts app's Automation tab does the same. Home Assistant can also use NFC tags as triggers.

NFC business card

An NTAG216 holds a full contact card. Simpler and more flexible: write a URL on an NTAG213 that points to a page with your details. You can then update the page without rewriting the card.

Your own escape game or treasure hunt

NTAGs are ideal: each card carries a clue, a URL or an ID that your app or phone recognises. You can lock the tags once the game is ready so players can't overwrite them by mistake. It's the idea behind our upcoming NFC Escape Tag puzzle (planned for Christmas 2027, on the waitlist).

Learning how badges work

Get a few MIFARE Classic 1K cards and, if you can, a DESFire EV3. With a suitable reader, a research tool like the Proxmark3 Easy or a simple reader app, you'll see the difference between a card that identifies itself with a number and one that authenticates with an AES key. All of it on your own cards, which is exactly why blank cards are useful.

Quick summary

ProjectRecommended chip
Home-automation tag, link to a pageNTAG213
Business card with a full vCardNTAG216
Escape game, treasure huntNTAG213 or NTAG215
Understanding legacy badgesMIFARE Classic 1K
Studying modern access controlDESFire EV3

"Magic" cards: what they are for in a lab

When shopping for blanks you'll come across "magic cards", sometimes labelled Gen1a, Gen2 or CUID. They are MIFARE Classic-compatible cards, not made by NXP, whose identifier (UID) can be rewritten. On a genuine card, the UID is programmed at the factory and never changes.

Why do they exist? Because many older systems simply read a card's UID to decide whether to open a door. A UID is not a secret: it is sent in the clear to every reader. In a lab, on a system you run, a magic card lets you test one simple question: "does my reader trust the ID alone?" If it does, the system needs to move to cryptographic authentication, typically DESFire EV3 with proper key management.

That is the defensive use of these cards, and the only one we recommend. Reproducing the badge of a building, an employer or anyone else without permission is a criminal offence in France (unauthorised access to a system, Code pénal article 323-1) and in most other countries. For the legal picture around RFID tools in France, read what the law actually says about the Flipper Zero and similar tools. If you're weighing up research hardware, our Proxmark3 Easy vs RDV4 comparison will help.

How to tell a genuine NXP chip

Plenty of "MIFARE-compatible" cards come from other manufacturers. They aren't necessarily bad, but they may behave differently and don't come with NXP's guarantees. A few ways to check what you're buying:

  1. The NXP TagInfo app, free on Android and iOS, identifies the chip's manufacturer and exact part. On chips that support it (NTAG21x, Ultralight EV1, DESFire EV2/EV3), it checks the originality signature: an ECC signature that NXP computes from the UID and that cannot be forged without NXP's private key.
  2. Price. A genuine DESFire EV3 costs considerably more than an NTAG. A "DESFire" sold at NTAG prices deserves a closer look.
  3. Wording. "MIFARE compatible" or "1K chip" is not "NXP MIFARE Classic EV1". A reputable seller names the exact part.
  4. Traceability. Buy from a reseller who can tell you where the cards come from and who answers if a card isn't what was promised.

For a personal project, a non-NXP chip may be fine. For learning, prefer genuine chips: you study the real chip's behaviour, not a clone's quirks.

Our blank NFC cards

If you want a pack to start your home-automation tags, business cards or your own escape game, our blank NFC cards (pack of 15, €14.90) use genuine NXP chips and are rewritable. They'll be back soon: sign up on the product page to be notified when they're available.

Frequently asked questions

Which blank NFC card works best with a phone?

An NTAG213, NTAG215 or NTAG216. These chips follow the NFC Forum Type 2 specification and can be read and written by practically every NFC phone, Android and iPhone alike. Pick the size based on what you store: 144 bytes is plenty for a URL or a home-automation trigger.

Why can't my iPhone read my MIFARE Classic card?

MIFARE Classic uses a proprietary protocol (Crypto1) that is not part of the NFC Forum standards. iPhones and some Android phones don't support it. For anything a phone needs to read, use an NTAG.

Is MIFARE Classic still secure?

Not for anything that matters. NXP lists MIFARE Classic EV1 1K as "Not Recommended for New Designs" and advises against relying on its Crypto1 cipher for security-critical uses. It is still handy for learning and for projects with no security stakes.

What is a "magic" card?

A MIFARE-compatible card whose identifier (UID), normally fixed at the factory, can be changed. In a lab, it lets you check that a system you run doesn't rely on the UID alone. Using one to reproduce someone else's badge without permission is illegal.

Related articles

Proxmark3 Easy vs RDV4: hardware differences, antennas, flash size, build quality and euro prices, plus which model suits which kind of user.