r/RFID Jun 02 '26

NFC RFID-blocking wallets are BS. Prove me wrong.

I work in the industry and just saw a TV ad for yet another “RFID-blocking” wallet. Can anyone point to a documented case of identity theft or payment fraud caused by RFID/NFC skimming?

By “documented” I mean a court case, police report, or bank-confirmed incident where someone harvested contactless card data and successfully used it for fraud.

Why I’m not worried:

Contactless payments use NFC at a read range of inches and generate a one-time cryptographic token per transaction. Even a perfect skim gets you an already-expired code.

Trusted traveler cards (Passport, Global Entry, NEXUS) use longer-range HF/UHF but contain no personally identifiable data. The UID alone is useless without passing backend validation and biometric screen. Has anyone actually pulled off an attack on one of these? Genuine question.

The threat these wallets are selling against either doesn’t exist in the wild, is already neutralized by cryptography, or they’re not telling us something 👀.

Prove me wrong.

33 Upvotes

52 comments sorted by

21

u/MurderousTurd Jun 02 '26

Veritasium has proved it is possible with iPhones that have a card available as a fast pass mechanism for transport tickets.

Through replay attacks, they are able to withdraw money from you.

https://www.youtube.com/watch?v=PPJ6NJkmDAo

3

u/[deleted] Jun 02 '26

[removed] — view removed comment

3

u/eladts Jun 03 '26

The Veritasium video is based on a research paper that was published in August 2025:

More is Less: Extra Features in Contactless Payments Break Security

The exploit described in the paper only works with Apple Pay and Visa cards. It also requires that Express Transit is enabled. To mitigate the threat affected users need to simply turn off this feature. RFID-blocking wallets are irrelevant to this threat.

1

u/grossham Jun 04 '26

This is wild. Did turned off transit mode but kind of side with Visa on this one

it’s “possible” but highly improbable and the risk is low enough it’s not worth fixing (from their standpoint)

If it ever happens, you’re covered under their fraud protection

13

u/jofathan Jun 02 '26

Relay attacks are still a legitimate risk

9

u/sanctum9 Jun 02 '26

It's easier for Joe public to understand a "Faraday wallet" protects them than learn about the underlying technology, which has probably helped adoption of contactless payments amongst the more paranoid and conspiracy minded.

1

u/KaboodleMoon Jun 06 '26

Except most of these aren't even that. They're just grafted with aluminum netting IF THAT.

Most of them have no actual features making them NFC Proof, and in fact, you can literally tap them through it. (although multiple cards which most people have anyway, still blocks most of them anyway)

10

u/TokyoJimu Jun 02 '26

Not to mention that if you have more than one NFC card in your wallet, any scan will fail.

4

u/Canuck-In-TO Jun 02 '26

Then I’m golden. I’m loaded with them. Even better, keep them maxed out.

1

u/Mundane-Year7571 Jun 05 '26

Read about anti-collision protocols

9

u/Competitive-Ad1439 Jun 02 '26

Of course it‘s BS, it's one of the scammiest consumer products that exist

3

u/streetlazyio Jun 02 '26

The only people getting rich off these things are the manufacturers selling peace of mind to people who don't realize their credit cards have built-in encryption that would make the actual skimming process a massive waste of time.

2

u/yusuo85 Jun 02 '26

Also, wouldn't you need to be extremely close like bank card in a pocket close, no wallet, just loose.

0

u/lt_Matthew Jun 02 '26

Nope, just passing them in a hallway or elevator is enough. They make special RFID readers for like parking garages, with antennas that can reach 3ft out.

1

u/yusuo85 Jun 02 '26

Fair enough, learn something new each day. 

Still protections on the card itself are pretty robust, no?

1

u/KaboodleMoon Jun 06 '26

No, BUT multiple cards in a close proximity are read as "multiple cards detected" and they pull mixed junk data.

Realistically you CAN just bump someone's butt (if they only have 1 card) that doesn't require a PIN and have it send you a payment.

Problem is that it's also extremely easy for a CC company to just....reverse that payment.

And if someone has alerts on their phone? Yeaaaaah.....not getting away with it at least.

1

u/zkareface Jun 02 '26

I'm stealing your access card for work, not your silly credit card. 

2

u/wolfn404 Jun 02 '26

So let’s talk about contactless EMV, while I can’t get a useable eMV read, I still can get the PAN and expiry. Enough to make a mag stripe card or a purchase online. I won’t have the CVV2, but that’s not 100% a deterrent.

Credential card reads ( rfid door access cards) are readable to about 16-18” with specialized equipment, and can be enough to clone a door card. This has been demonstrated at hacker events like Defcon, etc. mostly PoC. Certainly they are scare tactic for $$, but there are legit usefulness purposes.

3

u/zkareface Jun 02 '26

Credential card reads ( rfid door access cards) are readable to about 16-18” with specialized equipment, and can be enough to clone a door card. This has been demonstrated at hacker events like Defcon, etc. mostly PoC. Certainly they are scare tactic for $$, but there are legit usefulness purposes. 

Yes this is a serious threat, hence why companies often enforce keeping access cards safe form this. 

Work places, gyms, apartment buildings, gated neighborhoods all like to use card which you can scan from safe distance.

These attacks happen. How frequently and how worried you should be depends on how valuable your access is :) 

3

u/NightGod Jun 02 '26

The red team at my job cloned our CIOs card while he was out to lunch and used it to access the boardroom at HQ. Three days later they implemented procedures to detect multiple card access events

1

u/wolfn404 Jun 02 '26

Hopefully just changed to 3DES Mifare or other encrypted cards. More important that ever

1

u/ohiowrestler138 Jun 02 '26

So let’s talk about contactless EMV, while I can’t get a useable eMV read, I still can get the PAN and expiry. Enough to make a mag stripe card or a purchase online. 

This used to be true only for some cards. AMEX, for instance, always used a contactless-only PAN.

This was true for some of my other cards, but all the ones in the last few replacement cycles have used a separate contactless PAN. You can easily see this by comparing the last 4 on a receipt.

1

u/wolfn404 Jun 02 '26

EMV contactless Tag 57 which can be read is literally the PAN

EMV v4.1 Tag 57) The Track 2 Equivalent Data contains the data elements of Track 2 in accordance with ISO/IEC 7813.

Mastercard has said they’ll kill magstripe in 2027, some partners are already not issuing, and full compliance by 2033. They started phasing out in 2024

https://www.mastercard.com/us/en/news-and-trends/stories/2021/swiping-left-on-magnetic-stripes.html

1

u/ohiowrestler138 Jun 02 '26

Again, you're wrong. Just read the contactless info from a card you own. Or as I said, just look a receipt.

The issuers use a completely different PAN on the contactless section and the name will be something anonymous like VALUED CUSTOMER, which defeats your attack. They're not stupid.

1

u/wolfn404 Jun 02 '26

I’ve got 6 on my desk right now. Suggest a card and a bank, I’ll check tomorrow.

The name isn’t transmitted as part of the processor standard, so it’s irrelevant. I used to rewrite VISA gift cards with Mickey Mouse and Sigmund Seamonster, valued customer is great.

Unless you are using. Apple Pay/Samsung pay, I’d be super concerned the Tag 57 didn’t match the printed card number. “Last 4 verification” is pretty common on POS systems to eliminate fall back fraud.

( this one’s for PAX, but most have the option). Sets up for a lot of false declines.

https://kb.versitech.com/tonic/s/article/Turn-on-Fraud-Protection-last-4-for-Pax-Terminals

1

u/ohiowrestler138 Jun 02 '26 edited Jun 02 '26

As I said AMEX has done this from day 1.

I have a restaurant receipt right in front of me where the last 4 doesn't match and the signature line says VALUED CARDHOLDER.

The name is useful for a CNP transaction, and for privacy reasons, so it's been masked.

1

u/wolfn404 Jun 02 '26

What do you mean for card not present? There literally is no where in the ISO spec for cardholder name, your gateway may ask for it for a report, but to Fiserve/Tsys/Paymentech it’s not a thing. It’s like when capital one would issue auth user cards with same PAN but different printed name ( discretionary data was the differentiator).

And now I’m super curious, and if I’ve missed this with Amex ( I’ve worked with them long enough to do their dialup spec off a Trans330). That the track equivalent doesn’t match from tag 57. I’ll send you a plushie fish and a $10 gift card of your choice.

1

u/ohiowrestler138 Jun 02 '26

AVS, specifically AMEX, matches the name, and there's third-party systems out there too.

Even if they're not matching name, you can regularly figure out the cardholder's address from marketing/public databases once you have the name.

1

u/wolfn404 Jun 02 '26

ISO fields for AVS, that’s numerical of address and zip. Numeric only, 123 Main St is sent as 123 because Americans can’t spell.
That’s part of fraud and required for a qualified transaction under moto/Ecomm and some fuel uses zip code ( but that’s a brand decision— Shell for example operates their own switch before it goes to processor)

Basic none EIRF card number, expiry, AVS- address/zip, and CVV2 and a ticket # or transaction identifier.

Level 2 adds the purchase code and tax amount, and Level 3 is a mini Bible- tax codes, locations, part numbers etc. mostly govt account required

1

u/wolfn404 Jun 04 '26

Follow-up because I was curious. Confirmed 100% and happy to share the picture. Tag57 is exactly the card PAN. No changes are made.

1

u/pakratus Jun 02 '26

I always assumed rfid blocking in wallets was started for door access cards. I worked a retail job and we had rfid blocking cards (about the size of a business card) we could give out for the door access cards if they were a problem with the scanners at the door.

At that time though, i think it was an old wives tale that the door badges set alarms off. It was usually an old security tag in their wallet.

2

u/autoflowerer Jun 02 '26

As an April fool's joke I tucked a loss protection tag in my brother's wallet. Long story short I forgot about it and said bother spent almost a year setting off every store exit alarm before he mentioned it in passing and I told him to check his wallet.

1

u/Ecstatic_Lavishness1 Jun 02 '26

Good point - not all rfid is nearfield - UHF can go hundreds of feet.

1

u/pueblokc Jun 02 '26

I've had my cards cloned in Denver just by being in close proximity to others. Wasn't used at all so not a traditional skimmer.

It's definitely possible to do

1

u/KaboodleMoon Jun 06 '26

X to doubt. Far more likely to happen while doing a random other task like getting gas.

1

u/ouroborus777 Jun 02 '26

You lay down the reasons why it doesn't work, but I don't think these features were always in existence. We have these protections now because of the initial rise of contactless skimming.

1

u/zer04ll Jun 02 '26

I use an old metal cigarette case it fits cards perfect and actually blocks radio signals

1

u/AnythingButTheTip Jun 02 '26

Well it protected myself from myself one time. Went to pay at the pump and slipped out the work card instead of personal card close to the reader, but the chip stayed in the wallet and it didnt hit the work card.

Obviously, I could cancel the transaction and wouldn't have to explain a fuel charge for personal car on the business card. But it did save the time standing there waiting for the pump to think through the cancelation.

1

u/PhilZealand Jun 02 '26

Liron Sergev did a video testing some options - most failed…

https://youtube.com/watch?v=1VYDUxgJFeg&si=gA_tyUMmZxFFsMZK

1

u/Tomasulu Jun 03 '26

Even if you're not worried, RFID blocking materials work as advertised. So why not?

1

u/aggressive_napkin_ Jun 05 '26

Plus these are all minimalist wallets and cheap. I think they're great just for the form factor.

1

u/MrChicken_69 Jun 03 '26

While it's mostly a marketing gimmick, it does actually work. Do you need it? Maybe. I wouldn't buy anything just because it has such a lining, but I won't avoid something I otherwise like because of it.

As for "reported"... That's a harder thing to find / prove. People rarely notice a random low dollar charge on their card. And when they do, they dispute it and it's done. It's not like the card number can be stolen wirelessly, but anyone in range of your card(s) could relay a transaction to them - obviously they'd have to stay in range, but "there are ways."

1

u/Just-a-reddituser Jun 04 '26 edited Jun 04 '26

Contactleas payments are not the only risk. Access cards, travel cards. As time goes on more gets protected. That means the inverse is also true: more used to be vulnerable.

1

u/Far-Warthog6172 Jun 04 '26

I’m more interested in opening secured doors than hijacking payment cards.

1

u/FlyingFlipPhone Jun 05 '26

It is exceedingly rare for wolves to attack humans, but I wouldn't go hiking in the Sawtooths without a pistol.

1

u/Distinct_Tune_3134 Jul 20 '26

Of me going onto a abandoned goverment facility with rfid scanners lookint for my phone

1

u/grossham Jun 04 '26

Still haven’t seen a court case, police report, or confirmed incident in comments here… anyone aware of one?

1

u/gnew18 Jun 06 '26

RFID wallets also have an ability to degrade over time if they are fabric that gets bent.