Executive brief
A vulnerability exists in the cashless payment wristbands used at events like Resurrection Fest 2025, which rely on insecure NFC chip technology. An attacker with physical access to a wristband can clone its credentials, allowing them to impersonate the original user and spend their digital balance. This can lead to direct financial losses for attendees and significant revenue leakage or reputational damage for event organizers.
Technical details
The vulnerability is classified as CWE-326 (Inadequate Encryption Strength) due to the use of the MIFARE Classic family (specifically the FM11RF08S variant) which employs a weak proprietary authentication algorithm. An attacker with physical proximity to a target wristband can utilize a 'Backdoored Nested Attack' to retrieve the static encrypted nonces and extract the access keys. Once the keys are obtained, the attacker can read the entire memory contents and clone the identity and balance onto a compatible rewritable NFC card. Because the flaw is inherent to the hardware's cryptographic implementation, the recommended mitigation is migrating to more secure hardware such as MIFARE DESFire EV2 or EV3.
Affected products
- CasfID Servicios Tecnológicos S.L.U. NFC Wristbands (FM11RF08S variant) Version used at Resurrection Fest 2025
Timeline
- 2026-07-28: disclosed: Coordinated disclosure by INCIBE-CERT
- 2026-07-28: advisory: NVD publication date