Skip to content

proxmark3

Client and firmware tooling for the Proxmark3 RFID and NFC research device

What it does

Drives the Proxmark3, a research device for low-frequency (125 kHz) and high-frequency (13.56 MHz) RFID and NFC. It reads, writes, emulates and analyses a very wide range of card technologies, and it flashes the device's own firmware.

Why you would want it

It is the most capable open RFID research tool there is, and it is the only one in this profile that covers 125 kHz at all -- everything else here is 13.56 MHz over libnfc. If you want to study the access-control cards that are actually deployed in buildings, this is the hardware that reaches them.

Before it will work

Proxmark3 hardware, membership of dialout and plugdev, and firmware matching the client version. On Debian 13 and Parrot the client must be built from source, which needs a backend this project has not written yet. See catalog/hardware/devices/proxmark3.yaml -- its USB identifier is confirmed by capture (2d2d:504d, 2026-08-26); what it cannot solve is telling two identical units apart, since the board supplies no serial.

How it installs

  • apt: proxmark3 — on kali
  • Measured 2026-08-26 in kalilinux/kali-rolling: proxmark3 4.21611-0kali1, which corresponds to upstream's v4.21611 tag.
  • git (make) — https://github.com/RfidResearchGroup/proxmark3 at v4.21611
  • build dependencies: build-essential, pkg-config, libreadline-dev, libpcsclite-dev, libssl-dev, libbz2-dev, liblz4-dev, libbluetooth-dev, libpython3-dev, libqt5svg5-dev, qtbase5-dev, gcc-arm-none-eabi, libnewlib-dev
  • Pinned to the same release Kali packages so a client built here and a client installed there are the same version. This needs the source-from-git backend, which is NOT WRITTEN -- see the engine status in README.md. The manifest is data and is correct today; nothing can act on it yet.

Binaries this produces:

  • client/proxmark3
  • pm3

Known problems

Client and firmware are version-locked and a mismatch produces confusing behaviour rather than a clear error. Several incompatible hardware generations share the name -- the original design, RDV4 and RDV5 -- and they differ in USB identifier and in what the firmware supports. Packaged only on Kali; the other three targets need a source build, and the ARM cross-compiler in the build dependencies is required even to build the client, because the client ships the firmware images it flashes.

Keeping it current

  • probe: github tags (RfidResearchGroup/proxmark3)
  • strategy: rebuild

Source: catalog/packages/proxmark3.yaml