iOS app · Chameleon Ultra
Mifare Chameleon Tool
iOS companion for Chameleon Ultra: read, write, and manage MIFARE Classic tags with a workflow inspired by Mifare Classic Tool (MCT). Dumps, keys, tools, and slots — all from your phone.
Hardware requirement
The iPhone does not read NFC on its own. Tag operations (read, write, sniff, value block on tag) require a Chameleon Ultra connected over Bluetooth. Hold the MIFARE tag on the Chameleon reader while the app sends commands.
Without a device you can still use offline mode: edit dumps (.bin, .mct), compare files, manage key files (.keys), and many tools (Access Bits, Value Block on dumps, etc.).
How it works
On launch, connect your Chameleon Ultra (or continue without a device). From the main menu you reach the core features.
-
Connect Chameleon Ultra
Open the app and pair the device over Bluetooth. When connected, the icon menu is ready; otherwise you can enter offline mode to work on files only.
-
Prepare keys
Import or create
.keysfiles (one key per line, 12 hex digits). They are used to authenticate when reading and writing tag sectors. -
Read the tag
Pick a key file, tap Read tag, and place the MIFARE tag on the Chameleon. The app tries keys until the full dump is read; then you can view sectors, edit, and export dumps or keys.
-
Edit and write
Edit dumps in hex (sectors, blocks, Access Bits). To write to a tag, load a dump (
.binor.mct), select sectors, and use Write to tag. For Gen1A/Gen2 magic tags you can also update the UID. -
Advanced tools
From Tools: Access Bits, Value Block, Chameleon slots, dump compare, MF1 key recovery, device firmware updates, and more — aligned with the Chameleon / MCT ecosystem.
MCT app
Ultra
MIFARE Classic
What you can do
Overview of the main app functions, with the quick path to run each one.
Read MIFARE tags
Open Read tag, pick a .keys file, place the tag on Chameleon, and start reading the dump.
Details
.keys file, place the tag on Chameleon, and start reading the dump.
Write MIFARE tags
Open Write tag, load keys and a .bin/.mct dump, select sectors, and keep the tag still while writing.
Details
.bin/.mct dump, select sectors, and keep the tag still while writing.
MIFARE dump editor
Open Edit dump, import a file, edit bytes/sectors/blocks, copy or paste rows, and save as .bin or .mct.
Details
.bin or .mct.
Key library
Open Key files to create, import, edit, and export .keys, .txt, or .dic files.
Details
.keys, .txt, or .dic files.
Tag identification
Open Tools > Tag Detect, place the tag, and read UID, type, ATQA, SAK, and PRNG hints when available.
Details
MIFARE Classic key recovery
From Tag Detect or Tools, start recovery: dictionary, darkside, nested, static nested, or hardnested depending on the tag.
Details
.keys file.
Advanced acquisitions
In Tools, use darkside, static encrypted nested, and sector key checks; keep the tag on the antenna until finished.
Details
mfkey32 recovery
Open Tools > mfkey32, enable sniffing on a Classic 1K slot, authenticate with an external reader, then recover the key from captured nonces.
Details
mfkey64 recovery
Open Tools > mfkey64, enter or import the required authentication data, and start key calculation.
Details
Encrypted static nonces
Open the dedicated attack from Tag Detect or Tools, set the known key, acquire nonces, and verify candidate keys.
Details
Emulator slot manager
Open Tools > Chameleon slots to manage all 8 slots: active slot, dumps, nicknames, HF/LF, reset, and emulator preferences.
Details
LF tag emulation
In slot configuration, enable LF, choose EM410X/HID/Viking/ioProx/PAC, scan the external tag, and save the UID to the slot.
Details
Dump compare
Open Tools > Compare dumps, load dump A and B, and review byte-by-byte highlighted differences.
Details
Access Bits decoder
Open Tools > Access Bits or tap trailer bytes in the dump editor; decode bytes 6-8 and apply safe presets.
Details
Value Block tools
Analyze or create value blocks from dumps. Increment/decrement/transfer/restore require a connected Chameleon.
Details
Magic tag UID change
Open Tools > Change UID, detect Gen1A or Gen2, enter the new hex UID, and write it to the magic tag.
Details
Data converter
Open Tools > Converter, choose the conversion, set endianness when needed, and copy the result.
Details
Chameleon firmware
Open Tools > Firmware version to read the device version and update Chameleon with Normal/Dev channels and DFU ZIP packages.
Details
App preferences
Open Info > Settings for language, theme, color, privacy, and global actions such as clearing all slots.
Details
App UI in English, Italian, French, German, and Spanish.
Ready to get started?
Download MCT from the App Store and connect your Chameleon Ultra.
Download on the App Store