NFC THIEF
NFC THIEF
RELAY · CAPTURE · REPLAY · CLONE
NFC

STEAL ANY CARD WITH NFCTHIEF

Two phones. One flow. Bypass POS & ATM with real-time NFC relay. Capture, replay, clone, and control — all from your dashboard.

What's New

v2.1 — Field Device, Track2 NFC and relay improvements

NEW · HARDWARE

NFC THIEF Field Device

Custom cap-style field device — NFC cap, motion & ambient sensors, BLE relay link. Design your footprint in the live customizer.

NEW · TRACK2

Track2 NFC

Paste Track 2 data and emulate contactless MSD on one phone — isolated from relay, no server required. Visa, MC, Maestro, Amex, Discover, JCB, UnionPay.

RELAY

Expanded HCE AIDs

Wider payment scheme list on Tag — more POS terminals select the app during relay.

RELAY

Live APDU latency

Real round-trip per APDU. FAST / OK / SLOW badge, session averages, POS time estimate.

SAFETY

Isolated modes

Track2 and Relay cannot run together — relay hot path unchanged when Track2 is off.

PANEL

PIN bypass engine

7-method command-aware bypass: no-PIN, signature, combined, ATM-specific, CIP chip reader mode.

How It Works

Four steps to relay any NFC payment card through your server

01
🖥

Run the Server

Start the relay server from the web panel on your PC or VPS. It listens on a port — TCP with optional TLS.

02
📱

Reader Phone

Set Host & Port in the app, select Relay mode (Reader or External), connect to the server.

03
📡

Tag Phone

Same Host, Port, and Session. Switch to Tag mode. Pairs with the Reader phone in that session.

04
💳

Tap & Profit

Tap Tag phone at POS/ATM. Data flows through your server. CVM bypass — no PIN needed. Dashboard logs everything.

Payment Flow

💳 CARD
📱 NFC READ
🖥 EMV → SERVER
📱 TAG EMULATES
🔓 CVM BYPASS
90 00

What You Get

A complete, reliable solution for NFC research and testing

📡

Relay

Reader + Tag over network. Two phones, one server. Classic NFC tap or external USB CCID reader. Terminal sees a real card.

💿

External Reader

Connect compatible CCID readers (ACS ACR1552U, ACR122U, Rocketek USB-C). Read card by chip or contactless — same relay.

NFC THIEF Field Device

Custom cap-style hardware: 5 cm NFC read, BLE relay link, motion & ambient telemetry, up to 24 h battery. Design your footprint in the customizer.

🔓

CVM Bypass

Multiple bypass methods. No PIN, signature, combined options, ATM-specific. Terminal may not ask for PIN at POS or ATM.

📥

Capture & Replay

Record NFC sessions, save cards, clone and replay. Export sessions from the app for analysis.

📊

Dashboard

Start/stop relay, connected phones, real-time charts, live log. Filter by SYSTEM, EMV, READER, CVM. Devices, cards, blacklist.

📱

Devices

App login attempts tracked. Device info, Android version, IP, location, time. Mark unauthorized — block with message.

💳

Cards

Scanned cards with BIN-derived info. Add via POST /api/cards. Export JSON from the panel. Full card history.

🛡

Security

Rate limit on login/setup, anti brute-force, security headers. GET /api/version and /api/health for monitoring.

NFC THIEF Field Device

Compact custom field device — NFC cap, motion & ambient sensors, relay integrated

NFC THIEF· FIELD DEVICE LIVE
NFC cap
Standby
Motion
Idle
Ambient
21°C · 45% RH
Relay
Off
Battery
98% · ~21 h
Session
4.5×4.5 cm
Min. footprint
7 mm
Profile
24 h
Battery
5 cm
NFC reach

Phone NFC Reader

Quick tap with any Android phone — card or mobile wallet over the phone antenna. Same relay + Tag flow. ~35–45 ms RTT on a regional node.

RELAY → READER

Design your unit · live preview

85 × 54 × 12 mm
7 mm profile TOP · width × height SIDE · width × depth

Reference unit — final devices built to order above the 4.5×4.5 cm minimum. Save your spec JSON and send it with your order on Telegram.

Track2NFC

Pay contactless with Track 2 data — no relay needed, one phone

TRACK 2 DUMP
B510000000000000^NAME/NAME^2801000000000000000000000000000000
Separator: D or ; or =
Visa MSD enabled
APP SET AS DEFAULT NFC PAYMENT → TAP AT POS
1

Add Track 2

Paste Track 2 line from dump into the app. Use D, ; or = as separator. Add optional nickname.

2

Select Card

Tap a card in the list to set as active. "In use" badge = this card is your contactless payment card.

3

Set Default App

In NFC settings, set NFC THIEF as default payment app. Otherwise terminal may not use it.

4

Tap to Pay

Hold phone to POS. Works where terminals accept Visa MSD (magnetic stripe data). No relay needed.

Dashboard

Full visibility into every session, payment, and device

nfc-thief.com/dashboard — admin
24
Active Sessions
$1,847
Today's Volume
156
Cards Recorded
89
Devices Tracked
[14:32:01] EMV Payment — BIN: 4532** → $47.50 CVM: bypass (no PIN) — Session #1847
[14:31:45] CVM ATM bypass — 8E method — Terminal: POS-8821
[14:31:22] DEV New device — Android 14 — IP: 192.168.x.x — Location: EU
[14:30:58] EMV Payment — BIN: 5412** → $123.00 CVM: signature — Session #1846
[14:30:12] RELAY Session #1845 ended — Duration: 4m 32s — Cards: 2
[14:29:55] CARD New card captured — BIN: 4916** — Stored to panel

Relay Speed in Milliseconds

Real round-trip per APDU — POS → relay → reader → card → back to POS

42 ms
FAST
41
AVG rolling session average
36
MIN best hop
58
MAX worst hop
12
APDUs this transaction
Quality badge: FAST avg < 50 ms (target ~1 s POS) · OK 50–120 ms · SLOW > 120 ms — check WiFi / relay region Field units add ~15–45 ms vs phone NFC

Pricing

Unlock the full power of NFC detection. No free tier — paid plans only.

Monthly
Flex
$2,000
per month · billed monthly
  • Full client panel access
  • Android app & QR provisioning
  • Relay region assignment
  • Devices, cards, APDU & payments modules
  • Track2NFC + NFC THIEF Field Device support
  • Email / Telegram onboarding
Get monthly

Pay via Telegram (BTC) — access code and panel credentials delivered on activation.

Tenant Isolation & Access Control

2FA

Login Gate

Panel protected by account credentials — no shared superadmin access. Tokens expire and can be revoked.

ISO

Isolated Workspace

Each customer gets a dedicated workspace — cards, devices and logs never cross accounts.

BLK

Device Block

Track every device by IP + Android version + model. Mark unauthorized, block with a message.

LOG

Audit Trail

Full session, APDU and login history with timestamps — export for review.

Trusted by Operator Teams

4.9 / 5  ·  ★★★★★  ·  verified client reviews

★★★★★

"Switched to the Frankfurt relay in March — ping stays around 35 ms at peak. Live APDU caught a bad session before it hit production."

R**** S. · Europe Central
★★★★★

"New phone takes ~90 seconds: scan QR, remote config pulls, done. Blocked two cloned UUIDs last week from the devices page."

A**** R. · Europe West
★★★★☆

"Virginia node assigned same day we paid. CSV export has BIN and scheme columns — bookkeeping stopped needing custom reports."

J**** D. · US East
★★★★★

"The field device posts motion within a second of pickup. Battery estimate in the panel is approximate but fine for night-shift planning."

S**** V. · Middle East
★★★★★

"Dashboard START/STOP works on mobile data — old stack couldn't do that reliably. Bypass stats match relay-side logs."

D**** M. · US West
★★★★★

"Runs two Android readers on one tenant. Never saw another client's cards in our list — isolation holds up."

L**** F. · South America

Questions

What is NFC THIEF?

A complete NFC relay stack: Android app, relay server and a full web operator panel. Run live NFC/APDU sessions, manage devices, view EMV analytics and bypass POS/ATM CVM.

How do my phones connect to the relay?

Download the APK, install on both devices, set the same host, port and session — one as Reader, one as Tag. Sessions appear live in your dashboard.

Is my data isolated from other clients?

Yes. Each customer gets a separate workspace with their own cards, devices and logs — traffic never crosses accounts.

What can I control from the dashboard?

START/STOP relay, live sessions, connected devices, card list with BIN enrichment, live APDU log, exports, device blacklist and remote block with message.

How is the NFC THIEF Field Device different from a phone?

It's a hands-free cap: place it over the tap zone and it reads contactlessly within 5 cm, streams APDUs + motion/ambient telemetry over BLE to the same relay session. No one is holding a phone at the terminal.

How long does a POS payment take?

With a nearby relay and stable connection, each APDU round-trips in tens of ms — a full EMV flow typically completes in 1–3 seconds.

How do I pay?

Subscribe on Telegram — BTC payment, access code and panel credentials delivered to your account.

Can I export my data?

Card and session exports are available from the panel, plus the public card list for relay-tagged captures.

Get Access

Message us on Telegram for details, pricing and your access code