iOS app · Chameleon Ultra

Mifare Chameleon Tool

iOS companion for Chameleon Ultra: read, write, and manage MIFARE Classic tags with a workflow inspired by Mifare Classic Tool (MCT). Dumps, keys, tools, and slots — all from your phone.

Download on the App Store Requires iOS 18.6+

Hardware requirement

The iPhone does not read NFC on its own. Tag operations (read, write, sniff, value block on tag) require a Chameleon Ultra connected over Bluetooth. Hold the MIFARE tag on the Chameleon reader while the app sends commands.

Without a device you can still use offline mode: edit dumps (.bin, .mct), compare files, manage key files (.keys), and many tools (Access Bits, Value Block on dumps, etc.).

How it works

On launch, connect your Chameleon Ultra (or continue without a device). From the main menu you reach the core features.

  1. Connect Chameleon Ultra

    Open the app and pair the device over Bluetooth. When connected, the icon menu is ready; otherwise you can enter offline mode to work on files only.

  2. Prepare keys

    Import or create .keys files (one key per line, 12 hex digits). They are used to authenticate when reading and writing tag sectors.

  3. Read the tag

    Pick a key file, tap Read tag, and place the MIFARE tag on the Chameleon. The app tries keys until the full dump is read; then you can view sectors, edit, and export dumps or keys.

  4. Edit and write

    Edit dumps in hex (sectors, blocks, Access Bits). To write to a tag, load a dump (.bin or .mct), select sectors, and use Write to tag. For Gen1A/Gen2 magic tags you can also update the UID.

  5. Advanced tools

    From Tools: Access Bits, Value Block, Chameleon slots, dump compare, MF1 key recovery, device firmware updates, and more — aligned with the Chameleon / MCT ecosystem.

iPhone
MCT app
Chameleon
Ultra
Tag
MIFARE Classic

What you can do

Overview of the main app functions, with the quick path to run each one.

Connect Chameleon Ultra

Turn on Chameleon, tap Connect Chameleon Ultra, and select the device. You can also use the app offline and connect later.

Details
This prepares the Bluetooth link between phone and device. The iPhone does not read NFC by itself: place the tag on Chameleon while the app sends commands.

Read MIFARE tags

Open Read tag, pick a .keys file, place the tag on Chameleon, and start reading the dump.

Details
The app tries available keys on tag sectors, builds a MIFARE Classic dump, then lets you view, save, export, or edit the data immediately.

Write MIFARE tags

Open Write tag, load keys and a .bin/.mct dump, select sectors, and keep the tag still while writing.

Details
Write a full dump or selected sectors. For Gen1A/Gen2 magic tags, you can also enable UID writing and let the app guide the final verification.

MIFARE dump editor

Open Edit dump, import a file, edit bytes/sectors/blocks, copy or paste rows, and save as .bin or .mct.

Details
Works offline too. Edit single bytes, work by sector, copy whole blocks, open Access Bits from the trailer, and save files compatible with MCT workflows.

Key library

Open Key files to create, import, edit, and export .keys, .txt, or .dic files.

Details
Manage MIFARE key dictionaries: one key per line, 12 hex characters. Create personal sets, import from Files, edit, share, and reuse them for reading, writing, and recovery.

Tag identification

Open Tools > Tag Detect, place the tag, and read UID, type, ATQA, SAK, and PRNG hints when available.

Details
Use it before reading, writing, or attacking a tag. It shows useful technical data such as UID length, ATQA, SAK, MIFARE Classic support, and PRNG type when detected.

MIFARE Classic key recovery

From Tag Detect or Tools, start recovery: dictionary, darkside, nested, static nested, or hardnested depending on the tag.

Details
The pipeline tries known keys first, then chooses the best route for the tag. Found keys are grouped by sector and can be saved as a clean .keys file.

Advanced acquisitions

In Tools, use darkside, static encrypted nested, and sector key checks; keep the tag on the antenna until finished.

Details
Collects data with Chameleon Ultra GUI-style firmware commands, including darkside, static encrypted nested acquire, and multi-sector key checks for technical workflows.

mfkey32 recovery

Open Tools > mfkey32, enable sniffing on a Classic 1K slot, authenticate with an external reader, then recover the key from captured nonces.

Details
Chameleon records reader/tag authentication traffic. The app reads UID, NT, NR, and AR values, validates candidates, and filters false keys when nonce support is not consistent.

mfkey64 recovery

Open Tools > mfkey64, enter or import the required authentication data, and start key calculation.

Details
For cases where you already have the authentication data required for mfkey64. Enter the values, check formatting, and let the app calculate the key.

Encrypted static nonces

Open the dedicated attack from Tag Detect or Tools, set the known key, acquire nonces, and verify candidate keys.

Details
Designed for tags that behave like static encrypted nested targets. Acquire data from Chameleon, use dedicated filters/solvers, and verify which candidates really authenticate.

Emulator slot manager

Open Tools > Chameleon slots to manage all 8 slots: active slot, dumps, nicknames, HF/LF, reset, and emulator preferences.

Details
Each slot can hold a different configuration. Load dumps, read slot data, rename slots, choose the active slot, disable HF/LF, or reinitialize only the selected slot.

LF tag emulation

In slot configuration, enable LF, choose EM410X/HID/Viking/ioProx/PAC, scan the external tag, and save the UID to the slot.

Details
Prepare a slot for low-frequency tags. Choose the right format, read the UID from a supported external LF tag, and store it in the slot for emulation.

Dump compare

Open Tools > Compare dumps, load dump A and B, and review byte-by-byte highlighted differences.

Details
Useful for seeing what changed between two dumps or after an edit. Rows show blocks side by side and highlight different bytes.

Access Bits decoder

Open Tools > Access Bits or tap trailer bytes in the dump editor; decode bytes 6-8 and apply safe presets.

Details
Turns trailer access conditions into readable permissions for data blocks and keys. Start from existing bytes, use presets, and apply the result to the current trailer.

Value Block tools

Analyze or create value blocks from dumps. Increment/decrement/transfer/restore require a connected Chameleon.

Details
Decode and build MIFARE value blocks. Offline you can prepare the bytes; with Chameleon connected you can execute supported value operations on a tag.

Magic tag UID change

Open Tools > Change UID, detect Gen1A or Gen2, enter the new hex UID, and write it to the magic tag.

Details
For compatible magic tags, detect the type, enter the new UID, write it, and read back to confirm. The app handles details such as BCC when needed.

Data converter

Open Tools > Converter, choose the conversion, set endianness when needed, and copy the result.

Details
Quickly convert numbers and payloads between decimal, binary, and hexadecimal. Useful for interpreting UIDs, blocks, values, and log data.

Chameleon firmware

Open Tools > Firmware version to read the device version and update Chameleon with Normal/Dev channels and DFU ZIP packages.

Details
Shows device information, helps choose channel/package, and guides DFU ZIP updates. Keep phone and Chameleon close during the update.

App preferences

Open Info > Settings for language, theme, color, privacy, and global actions such as clearing all slots.

Details
Customize language, theme, and colors, read privacy/app information, and run maintenance actions such as clearing and turning off all Chameleon slots.

App UI in English, Italian, French, German, and Spanish.

Ready to get started?

Download MCT from the App Store and connect your Chameleon Ultra.

Download on the App Store