Advertorial · Independent Editorial Review · Contains Affiliate Links
Live offer: Cardian 3-pack 54% OFF $109.99 now $51.10 Claim deal
TopRate Safety Lab

How RFID Skimming Actually Works (And What It Cannot Do)

By Jack Green · 7 min read

Every contactless bank card, transit pass and biometric passport in your pocket contains a small antenna and a chip that has no battery of its own. When a reader comes close enough, the reader's own field powers the chip, the chip answers, and a transaction begins. That is the entire mechanism, and it is also the entire vulnerability: the card cannot tell the difference between the terminal at your coffee shop and a reader hidden inside a backpack.

The physics that decide the real risk

Contactless payment cards operate at 13.56 MHz, and the field that powers them falls away sharply with distance. At the counter, a legitimate terminal wants you within a couple of centimetres. A determined attacker with a larger antenna and more power can stretch that, but not to the across-the-room distances that viral videos imply. The realistic threat is proximity: a crowded subway car, a packed airport queue, a bar where someone stands closer than they need to.

That is exactly why a blocking card matters more than it sounds like it should. You cannot control who stands next to you, and you cannot see a reader hidden in a bag. What you can control is whether your card answers at all.

Shielding versus jamming

There are two approaches on the market, and the marketing rarely distinguishes them. Shielding puts a conductive layer between the reader and your card, weakening the field that reaches it. It works, but its effectiveness depends on geometry — where the shield sits relative to the card the reader is targeting.

Jamming is the more aggressive approach. The card contains its own antenna and chip, which harvest energy from the incoming field and transmit noise back on the same frequency. The reader hears interference instead of a card number. Because the jamming card responds to the field itself, it does not care as much about the exact stacking order in your wallet, which is why the better products in this category use it.

What a blocking card cannot protect you from

It is worth being blunt, because the category attracts overclaiming. A blocking card does nothing about a compromised online merchant, a phishing email, a card handed to a waiter, a magnetic-stripe skimmer bolted to a petrol pump, or a data breach at your bank. It addresses one narrow attack: a wireless read of the chip while the card sits in your wallet.

Narrow does not mean unimportant. It means you should size your spending to the problem: a card, not a subscription, and certainly not a device that needs charging.

How to verify a card is actually working

The honest manufacturers in this category tell you to test at a self-checkout machine, and you should. Put the blocking card in the wallet next to your payment card, close the wallet, and present the whole wallet to the terminal. If the payment fails, the card is doing its job. Then open the wallet, present the payment card on its own, and confirm it still works normally. Repeat with each wallet you own, because slot geometry changes results.

Passports, hotel keys and transit cards

Biometric passports use a different frequency and carry their own basic access protection, but they still respond wirelessly, and a blocking card in the same document holder gives you a second layer. Hotel keys and building fobs frequently sit at 125 kHz, which most payment-focused blocking cards are not designed for — if building access cloning is your concern, that is a different product category.

The bottom line

The threat is real, the range is short, and the fix is cheap. Buy one card per wallet you actually carry, test it once at a self-checkout machine, and then stop thinking about it. Anything that asks for a subscription or a charging cable to solve this problem is solving a problem you do not have.

Keep reading