Flipper Zero explained: What to know about the viral hacker tool (2024)

Feature

The hacking tool blew up on TikTok. Unlike other TikTok trends, it is a powerful tool that can be used by serious pen testers and a learning device for new hackers.

Wireless signals are everywhere. Phones, Wi-Fi networks and bank cards are just a few technologies that use wireless signals to communicate. Hacking them typically requires some cybersecurity knowledge, but Flipper Zero makes it a cinch.

Flipper Zero is a toy-like portable hacking tool. The multi-tool is marketed to "geeks," red team hackers and pen testers to expose vulnerabilities in the world around them, like a cybersecurity X-ray. The tool is open source and completed a successful Kickstarter in 2020.

The tool gained popularity on TikTok when it appeared in a flurry of videos from hackers and script kiddies playing pranks in public. In the videos, hackers turn off the electronic menus at fast food restaurants, remotely open the charging ports of strangers' Teslas and even change the gas prices on gas station displays. The hackers simply point the device at the target system like a remote control, press a button or two, and the target screen turns off, the display numbers change or the charging port opens.

These videos make Flipper Zero out to be a skeleton key for IoT, but this is an exaggeration. Most of the videos were likely staged, requiring significant preparation to pull off.

The gadget is still a powerful and intuitive tool to investigate cybersecurity in the physical world. Although it can't manipulate every wireless device in its path, it can read the signals wireless devices emit. With this capability, it can reveal a significant amount of information about a spectrum of electronic devices, even if it can't really change gas prices at the click of a button. For example, it can do the following:

  • Read a stranger's car tire pressure sensor data.
  • Read the body temperature of a dog with an animal microchip embedded in it.
  • Detect the signals an iPhone sends out for facial recognition and the frequency of those emissions.
  • Read and record the signal from a garage door opener.
  • Clone a building entry card.

How does Flipper Zero work?

Flipper Zero contains a few different antennas. These help it capture, store, clone and emulate wireless signals. It can interact with several signal types:

  • Near field communication (NFC). Bank cards and building access cards use NFC signals.
  • 125kHz RFID. Older proximity cards and animal microchips use this frequency.
  • Infrared. Many remotes use infrared signals.
  • Sub-1 GHz. Garage door remotes and remote keyless systems use Sub-1 GHz frequencies to communicate.

To read a wireless signal, the user holds Flipper Zero up to source of the signal, selects the program that corresponds to the signal type, and selects "Read." Flipper Zero then saves the signal type to memory. The user can access the saved signal and emulate it. Flipper Zero doesn't allow users to save and emulate NFC bank cards, but it can read them.

Part of Flipper Zero's appeal is its versatility. Three simple hacks showcase Flipper Zero's capabilities via radio signal communication and other means. It can unlock a car that uses a radio fob, control a TV that uses infrared and create a two-factor authentication token for websites.

Flipper Zero also features the following:

  • 18 general purpose input/output connectors that connect it to other hardware devices.
  • A USB 2.0 port, type C, to connect with computers.
  • iButton 1-Wire support. iButtons are often used in asset control and tracking.
  • Removable storage in the form of an SD card.
  • An LCD display screen and five-button control pad.
  • The FreeRTOS embedded operating system for microcontrollers.
Flipper Zero explained: What to know about the viral hacker tool (2)

Is Flipper Zero a serious security threat?

Flipper Zero has potential to be a security threat in the wrong hands. However, it is not inherently dangerous. To engineer a security attack would take a fair amount of planning and intent. Flipper Zero is better suited to light pen testing activities and general reconnaissance to gain awareness of the digital environment. For novice hackers, pen testing is the act of intentionally finding vulnerabilities in a computer system to fix the vulnerabilities and make the system stronger.

Flipper Zero is a learning tool primarily, designed to make cybersecurity information more accessible and change the way users think of the digital devices around them. Much of the technology and techniques Flipper Zero uses have been around for years. Flipper Zero just makes them slightly more accessible and user friendly.

Is it legal?

Flipper Zero reported on its social media channels that U.S. Customs and Border Patrol seized a shipment of Flipper Zeros in September 2022. Despite this event, the device is legal. It simply has the potential to be used illegally.

Flipper Zero shouldn't be used to tamper with devices or systems that the user doesn't have permission to access.

The device's firmware prevents users from transmitting frequencies that are banned in the country where they are using it.

Flipper Zero is banned on Amazon because it was tagged as a card-skimming device. There is a third-party Flipper locator application that lets people monitor Flipper restocks by country and vendor.

Alternatives to Flipper Zero

Flipper Zero is just one hacking gadget. While Flipper Zero can perform a range of actions, there are many products and software that can also perform one or several of those same functions:

  • The USB Rubber Ducky. The USB Rubber Ducky can perform BadUSB attacks and run ducky scripts.
  • ChameleonMini. The ChameleonMini is a portable tool for NFC security analysis.
  • Smartphones. Smartphones can read and store NFC codes.
  • Raspberry Pi. Raspberry Pi can be set up as an NFC signal reader.
  • The Wi-Fi Pineapple. Both Flipper Zero and the Wi-Fi Pineapple can be used for pen testing wireless networks.
  • John the Ripper. This tool does password-cracking attacks, like Flipper Zero does with its BadUSB function.

Cost of Flipper Zero

The gadget was originally sold for $169 by the manufacturer. However, the device is often sold out and only available through third-party vendors, increasing the price. There are also many scammers that claim to be selling Flipper Zero when they aren't. It's best to only buy Flipper Zero through a reputable distributor.

Flipper Zero generally works on devices and systems that were vulnerable to begin with. Learn how to fix five of the most common cybersecurity vulnerabilities to prevent data loss and hacking.

Next Steps

11 TikTok alternatives to check out

What is the Rabbit R1, and what can it offer the enterprise?

Related Resources

Dig Deeper on Authentication and access control

  • How to manage 4 common mobile payment issuesBy: MichaelGoad
  • Top 5 mobile payment systems to considerBy: GaryOlsen
  • What fees come with accepting Apple Pay for businesses?By: GaryOlsen
  • 7 useful hardware pen testing toolsBy: RobShapland
Flipper Zero explained: What to know about the viral hacker tool (2024)

FAQs

What do you need to know about Flipper Zero? ›

Flipper Zero can act as a BadUSB device, which means that when connected to a port it is seen as a Human Interface Device (HID), such as a keyboard. A BadUSB device can change system settings, open backdoors, retrieve data, initiate reverse shells, or do anything that can be achieved with physical access.

What do criminals use Flipper Zero for? ›

The Flipper Zero is a portable multi-functional device developed for interaction with access control systems. The device is able to read, copy, and emulate RFID and NFC tags, radio remotes, iButton, and digital access keys, along with a GPIO interface.

What bad things can a Flipper Zero do? ›

Crash smartphones

You can use a Flipper Zero to crash nearby Androids by flooding them with Bluetooth messages. It's not exactly easy—you need to load a developer build of third-party firmware in order to run the “crash my enemy's phone” app—but it's possible.

Why is the Flipper Zero banned? ›

In February 2024 the Canadian government announced plans to ban the sale of the Flipper Zero, mainly because of its reported use to steal cars.

Can you do illegal things with Flipper Zero? ›

Disclaimer: Like many devices dedicated to hacking, the Flipper Zero itself is perfectly legal and complies with all regulations. It serves as an amazing tool for learning and experimenting with all kinds of devices. Yet, it has the ability to be used for illegal purposes.

What does a Wi-Fi board do on Flipper Zero? ›

Wi-Fi-enabled Developer Board brings debugging and firmware update capabilities to your Flipper Zero.

What cool things can a Flipper Zero do? ›

10 Actually Useful Things the Flipper Zero Can Do
  • 1) Scan pet RFID microchips. ...
  • 2) Start a Pomodoro timer. ...
  • 3) Copy a garage door key. ...
  • 4) Control your television. ...
  • 5) Create an NFC business card. ...
  • 6) Get into your digital accounts. ...
  • 7) Set up a metronome. ...
  • 8) Go through a slideshow.
Feb 13, 2024

Can the Flipper Zero turn off phones? ›

Apple silently fixed an exploit that let Flipper Zero devices mass-bombard nearby iPhones with popup notifications, so much so they would essentially disable users' phones requiring a restart. Flipper Zero is a small multi-tool able to mimic NFC, RFID, or other radio signals.

Can a Flipper Zero open a car? ›

The Flipper Zero will never be able to capture car fobs rolling codes and recover the seed unless a severe vulnerability is found. The Flipper might be able to emulate a NEW key fob but it would have to be learned by the car as a new fob.

What can Flipper Zero do with Bluetooth? ›

Bluetooth. The Bluetooth LE connectivity feature allows you to pair the device with your phone with the help of Flipper Mobile App. You can also connect your Flipper Zero to a smartphone or computer as a remote. After using the Unpair All Devices option, all previously connected devices will need to be paired again.

Can the Flipper Zero read credit cards? ›

You have to physically attach the credit card to the Flipper Zero for it to read the information. If you get access to the card, the Flipper Zero only reads the card number and sometimes the expiration date depending on the type of card it is. The CVC code or personal information is required.

Can I buy a Flipper Zero in the United States? ›

Flipper Zero is in stock for ! There are no import limitations, and you don't need additional documents for customs.

Can the Flipper Zero be used as a jammer? ›

Select a frequency you would be jamming, and then send this signal. This will keep running for about 30 seconds. Any receivers within the jamming range of the Flipper Zero (pretty darn close) that operate on the frequency being jammed should now not be effective to the genuine transmitter (legitimate remote, etc.).

What is the Flipper Zero used for crime? ›

The Flipper Zero Device

Conceptually, the device could not only obtain valuable personal information from NFC signals, such as a person's banking information, it could also be used to initiate vehicle theft. A Flipper Zero user may be able to intercept, record, and possibly mimic the signal of a vehicle's key fob.

What things can the Flipper Zero do? ›

It can access control systems, manipulate radio protocols, and interact with infrared gadgets found in bank cards, public Wi-Fi networks, and mobile phones. If you own a Flipper Zero, we strongly advise staying on the right side of the law and using it primarily for learning purposes or as a security evaluation tool.

How far away does Flipper Zero work? ›

Flipper Zero has a built-in sub-1 GHz module based on a CC1101 transceiver and a radio antenna (the maximum range is 50 meters). Both the CC1101 chip and the antenna are designed to operate at frequencies in the 300-348 MHz, 387-464 MHz, and 779-928 MHz bands.

Top Articles
How Much of Your Net Worth Should Be Tied Up in a Home?
Imperium Insecticide | Envu Environmental Science US
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Xenia Canary Dragon Age Origins
Momokun Leaked Controversy - Champion Magazine - Online Magazine
Maine Coon Craigslist
‘An affront to the memories of British sailors’: the lies that sank Hollywood’s sub thriller U-571
Tyreek Hill admits some regrets but calls for officer who restrained him to be fired | CNN
Haverhill, MA Obituaries | Driscoll Funeral Home and Cremation Service
Rogers Breece Obituaries
Ems Isd Skyward Family Access
Elektrische Arbeit W (Kilowattstunden kWh Strompreis Berechnen Berechnung)
Omni Id Portal Waconia
Kellifans.com
Banned in NYC: Airbnb One Year Later
Four-Legged Friday: Meet Tuscaloosa's Adoptable All-Stars Cub & Pickle
Model Center Jasmin
Ice Dodo Unblocked 76
Is Slatt Offensive
Labcorp Locations Near Me
Storm Prediction Center Convective Outlook
Experience the Convenience of Po Box 790010 St Louis Mo
Fungal Symbiote Terraria
modelo julia - PLAYBOARD
Poker News Views Gossip
Abby's Caribbean Cafe
Joanna Gaines Reveals Who Bought the 'Fixer Upper' Lake House and Her Favorite Features of the Milestone Project
Tri-State Dog Racing Results
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Stellaris Resolution
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6343

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.