Home / Resources / Article
RFID Article

Can RFID Tags Be Cloned? The TID Is Not the Fingerprint Your Audit Thinks It Is

Yes, RFID tags can be cloned, and the part of the tag most people rely on to prove they cannot is the part that just got weaker.

Yes, RFID tags can be cloned, and the part of the tag most people rely on to prove they cannot is the part that just got weaker. If you run a property audit, a hospital equipment inventory, or an industrial asset count on passive UHF RFID, you have probably been told that the TID is the chip’s permanent factory serial number, so a matching EPC and TID pair proves the tag is genuine and the asset is real. The company that makes more RAIN RFID silicon than anyone else said something different in November 2025, in a press release, in its own words.

This piece is about what the TID actually guarantees in 2026, why “EPC and TID both matched, so the audit passed” is a weaker control than it reads, and what an asset owner should do about it in practical order of cost. It is not a product pitch. Most of the useful answer costs nothing and is a change in how you interpret a report.

What the TID actually is

Passive UHF RFID tags built to the EPC Gen2 air interface carry several separate memory banks. The EPC bank holds the Electronic Product Code, which identifies the item the tag is stuck to. The user memory bank holds whatever you decide to put there. The TID bank, short for tag identifier, holds a number that identifies the chip itself rather than the asset.

The TID is written during chip manufacturing. It carries a designer identifier and a model number, and on most modern parts it also carries a serialized portion unique to that individual die. That is genuinely useful, and nothing in this article changes the useful parts. The EPC is field-writable by design, since you have to be able to encode a tag with your own asset number. The TID, on a normal part, is not.

That asymmetry is where the security story came from. If the EPC can be copied but the TID cannot, then reading both and checking them as a pair gives you something the EPC alone does not: evidence that this is the same physical chip you commissioned, not a blank tag someone encoded with a copied number.

What the top-ranking pages say

Search for what a TID is and the answers are unanimous and absolute.

One widely ranking explainer calls the TID “a unique, factory-programmed serial number that is permanently embedded into the silicon chip,” describes it as the tag’s “immutable birth certificate,” states that it “cannot be altered or reprogrammed by users,” and concludes that “due to its unalterable nature, the TID can be used for authentication and anti-counterfeiting measures.”

Another calls the TID “the unique ‘fingerprint’ of each RFID chip,” describes it as “a unique, unalterable serial number permanently encoded into each RFID chip during manufacturing,” and says that because it “is immutable, it can verify the authenticity of RFID chips, effectively preventing counterfeit products.” It goes on to call this “tamper-proof nature” one of the core values of the TID.

RFID Journal’s standing answer, written by founder Mark Roberti, is four words long on the point that matters: “It cannot be altered.”

None of these pages are dishonest. They were correct as a description of ordinary commercial parts, and they are still correct about ordinary commercial parts. What they are missing is that “ordinary commercial parts” is now a qualifier rather than a description of everything on the market.

What the chip vendor said

On November 12, 2025, Impinj announced a new Gen2X capability called Endpoint IC Verification. The release describes it as something that “inhibits fraudulent tags and items by allowing RAIN readers and printers to verify, during normal inventory and with no speed penalty, whether a tag contains an authentic Impinj endpoint IC.”

Then it says what that replaces:

“This new verification effectively replaces EPC-TID verification, eliminating a critical vulnerability from illicit endpoint ICs, available on the market today, that have changeable TIDs.”

Read that as an asset owner rather than as a retailer. The largest supplier of RAIN RFID silicon has characterized EPC-TID verification as carrying a critical vulnerability, and has characterized the parts that create it as available on the market today. That is not a researcher’s proof of concept at a security conference. That is a vendor describing its own market as a reason to buy a replacement control.

Be precise about the limits of that evidence, because the strength of this argument is that we are reporting what the chip vendor said rather than asserting it ourselves. Impinj has a commercial interest in the replacement it is selling, and no named, purchasable part with a writable TID bank turned up in publicly reachable vendor documentation while researching this article, which is what you would expect for a part whose purpose is impersonation. What exists is a dated, on-the-record statement by the party best positioned to know, pointing in the opposite direction from every explainer page ranking for the question.

The second piece of evidence matters more than it looks, because it is a contradiction rather than a confirmation. Nedap, which sells UHF RFID into vehicle access control where cloning is an active and well understood attack, publishes a tag security page stating that “the TID value is programmed and locked by the chip manufacturer and cannot be cross-copied into another tag,” noting that “the EPC number cannot be changed, but can be copied into a new empty unprogrammed tag,” and recommending that readers validate EPC and TID together as a pair. A serious security-facing vendor is recommending the exact control Impinj describes as carrying a critical vulnerability. Both pages are live. That gap is the reason this article exists.

Why this is an asset-integrity problem, not a counterfeit-handbag problem

Tag cloning almost always gets written up as a brand protection story. Fake goods, gray market diversion, luxury authentication. If you run a hospital, a public agency, a defense facility, or an industrial plant, that framing is why you skipped every previous article on the subject, and you were right to, because it was not about you.

Here is the version that is about you.

You conduct a periodic physical inventory. A technician walks the floor with a handheld reader, or a fixed reader at a doorway logs what passes. The system compares what it read against what it expected. The report comes back clean. Signed, filed, and defensible, because you have a read event with a timestamp and a tag identifier.

The control you just relied on is a number that a tag reported about itself over the air. Nothing in that transaction proved the asset was present. It proved that something in radio range answered with the expected number.

That is true even without any cloning at all. It is the reason a tagged asset can pass an audit while sitting in a scrapper’s truck, if the tag came off first. Cloning is the deliberate version of the same weakness, and the reason it matters more in asset accountability than in retail is the value of a single successful event. A retailer losing one item to a cloned tag loses one item. A property accountability program that produces a clean count on a missing capital asset loses the thing the entire program exists to produce.

Federal and state property programs require periodic physical inventory with documented reconciliation. Hospital equipment management programs have to produce a current, accurate device inventory on demand during a survey. Industrial and defense sites control high-value tooling against counts that feed insurance, depreciation, and export compliance. In every one of those, the audit output is a legal or accreditation artifact. A clean result on a missing asset is worse than a failed count, because a failed count starts an investigation and a clean count ends one.

What the TID still does well

None of this makes the TID useless, and treating it as useless would be its own error.

The TID is still an excellent operational identifier. It distinguishes one physical tag from another when your EPCs are duplicated, mis-encoded, or reused. It tells you the chip model, which is how you explain why one population of tags reads at twelve feet and another reads at four. It survives EPC rewrites, which makes it the right key for tracking tag-level failure rates across a deployment. It makes casual copying meaningfully harder, because encoding a blank tag with a copied EPC is trivial while sourcing a part that will report an arbitrary TID is not.

The change is one of category, not of value. The TID is a strong identifier and a weak authenticator. Identifiers tell you which thing is claiming to be present. Authenticators prove the claim. Treating a strong identifier as an authenticator is the actual error, and it survives regardless of whether a changeable-TID part ever shows up on your site, because an attribute the tag itself reports cannot verify the tag, for the same reason a name badge cannot verify its own wearer.

Why this became a 2026 buying decision

This could have stayed a chip-vendor firmware note. It did not, because the capability is moving into the hardware people are specifying this year.

On January 9, 2026, at NRF, Zebra announced the TC501 and TC701 ultra-rugged handhelds. The release states that “by leveraging UHF RFID and Impinj Gen2x extensions, the new TC501 and TC701 provide advanced visibility and security of critical data, especially in challenging enterprise environments.”

The same Impinj release that described the TID vulnerability also stated that Gen2X Fast Reinventory “is in limited availability today, with general availability to follow in mid-2026,” and described a separate Gen2X Tag Selection capability that “allows readers to better specify which tags should respond during inventory and which should remain quiet.”

So the timing is specific. If you are refreshing handhelds or fixed readers in 2026, the question of whether your reader fleet can do chip-level verification is a question you can actually ask a vendor now, and the answer will differ between models you are already comparing on price and ruggedness. Two years ago there was nothing to ask for. That is what changed.

One caution on that. Endpoint IC Verification as described verifies whether a tag contains an authentic Impinj endpoint IC. That is a supply chain and silicon authenticity control, and it is a real one. It is not the same thing as proving that a specific tag is the specific tag you commissioned onto a specific asset, and it is tied to one manufacturer’s silicon. Understand which problem you are buying a solution to before you spec around it.

The remedy ladder, cheapest first

Most of the value here is free. Work down this list in order and stop when the remaining risk matches the value of the assets.

Change how you read your own reports. Stop describing an RFID inventory result as verification or as proof of presence. It is a read event. Write it that way in the procedure, in the report header, and in whatever you hand an auditor. This costs nothing, takes an afternoon, and removes the single most dangerous assumption in the program.

Control the tag supply chain. Buy tags through a documented channel, record which chip models are deployed where, and keep the commissioning record. If you know the TID prefixes that should exist in your population, a TID that is well formed but belongs to a model you never bought is a signal you can actually alert on. This is procurement discipline rather than technology.

Lock what the standard lets you lock. Gen2 supports access passwords and memory locking, including permanent locking of banks you do not intend to rewrite. This does not address a part with a writable TID, and Nedap is candid that the 32-bit password is not strong cryptography, but it raises the cost of opportunistic tampering and you have already paid for the capability.

Make the physical audit disagree with the radio on purpose. Sample. Pull a percentage of the population each cycle and lay eyes on the asset, choosing the sample deliberately rather than randomly: highest value, highest mobility, longest time since anyone physically touched it. The point of sampling is not statistical coverage. It is to create a path by which a divergence between the radio and reality can be discovered at all. A program where every count is radio only has no such path, and a cloned or orphaned tag will pass forever.

Add a second, independent signal for assets that justify it. A control that depends on one self-reported number is weaker than one that requires two independent things to agree. That can be a barcode or serial plate verified on a sampled subset, a photo captured at inventory, a weight or power draw the asset produces, or a second identification technology. What matters is independence. Two numbers stored on the same tag are one signal, not two.

Buy cryptographic tag authentication where the asset value carries it. This is the real answer to the underlying problem and it has existed as a standard for years. Gen2v2 supports tag authentication using crypto suites defined in the ISO/IEC 29167 family. The mechanism, as Voyantic describes it, is that “a reader asks a tag to encrypt a message using its stored secret key. If the reader is able to decrypt the tag response, the tag is genuine.” NXP’s UCODE DNA uses the AES crypto suite defined in ISO/IEC 29167-10. That is authentication rather than identification, because the secret never crosses the air. It costs more per tag, needs readers that implement the Authenticate command, and requires key management you will have to actually run. For a hundred thousand cases of consumables it is unjustifiable. For a few hundred pieces of capital equipment where a clean count on a missing asset is a reportable event, the arithmetic looks different.

Ask about chip-level verification in the reader. The Endpoint IC Verification and Gen2X path described above, arriving through the reader and handheld refresh cycle rather than through the tag. Scope it for what it is.

Five questions worth asking a vendor

If you take one practical thing from this article, take these. They are short, they are answerable, and the quality of the answer tells you a great deal.

  1. Does your system treat a TID match as authentication, and can you show me where that is documented?
  2. What exactly does my inventory report assert? Presence of the asset, or receipt of a radio response?
  3. If a tag were removed from an asset and read elsewhere in range, what in the system would catch it?
  4. Do the readers and handhelds you are quoting support tag authentication under Gen2v2, or chip-level verification, and at what additional cost per reader and per tag?
  5. What is the sampling and physical verification procedure you recommend alongside the RFID count, and is it in the statement of work?

A vendor who answers question 1 with “the TID cannot be changed, so yes” is working from the explainer pages rather than from the chip vendor’s 2025 statement. That is worth knowing before you sign.

Where InfinID stands on this

Directly, because the alternative is a marketing claim: we do not ship an anti-clone or tag authentication feature.

AssetWorx records what the readers report. Our passive UHF deployments are built on EPC Gen2 in the 902 to 928 MHz US band, using LLRP for fixed readers such as the Zebra FX9600, Zebra FXR90, and Impinj Speedway R420, and handheld capture with a Zebra RFD40 sled paired to a TC22R, with typical read ranges of five to twenty feet depending on tag, antenna, and environment. That is an inventory and visibility platform. It is not a tag authenticity verification platform, and if a cloned tag reported a valid EPC and TID in our system, our system would record a read event like any other.

We are publishing this because the framing is the part most asset owners are missing, and because the remedy that helps the most people costs nothing: stop describing a radio response as proof of presence. If we ship something in this area later, that will be its own announcement with its own specifics.

FAQ

Can RFID tags be cloned? Yes. A standard Gen2 EPC is transmitted in the clear and can be copied onto a blank tag, which Nedap describes plainly. The harder question is whether the TID can also be matched, which historically it could not. Impinj stated in November 2025 that illicit endpoint ICs with changeable TIDs are available on the market today.

Can the TID on an RFID tag be changed? On normal commercial parts, no. It is written at manufacture and is not user writable. Impinj’s November 12, 2025 statement is that parts with changeable TIDs exist in the market, which is a different claim from saying ordinary tags can be rewritten. Both are true at once, and that is why the topic is confusing.

Is checking the EPC and TID together still worth doing? Yes, as a data quality and operational control. It catches mis-encoding, duplicate EPCs, and casual copying onto blank tags. Just do not describe it in a procedure as authentication or as proof the asset is present.

What is Impinj Endpoint IC Verification? A Gen2X capability announced November 12, 2025 that lets RAIN readers and printers verify during normal inventory, with no speed penalty, whether a tag contains an authentic Impinj endpoint IC. Impinj describes it as effectively replacing EPC-TID verification.

Does a cloned tag mean my whole RFID inventory is unreliable? No. One specific inference is unreliable, the inference from a read event to asset presence. The count, the location history, and the labor savings are all still real. What you lose is the right to call the result proof, and the fix is sampling plus honest language rather than abandoning the technology.

Is active RFID immune to this? Different technology, different failure modes, and outside the scope of this article. This piece is about passive UHF specifically, because the TID is a passive UHF Gen2 construct.

How would I know if this had already happened to me? Under a radio-only inventory program, you very likely would not. The first detection path most organizations have is a physical encounter: someone goes to use the asset and it is not there, long after the audit said it was. That gap is the thing sampling is for.

Sources

  • Impinj, Impinj Expands Gen2X to Unlock New Enterprise RAIN RFID Use Cases, November 12, 2025. Source of the Endpoint IC Verification, changeable-TID, Tag Selection, and mid-2026 general availability quotes. Fetched and verified 2026-09-13. Link
  • Zebra Technologies, Zebra Technologies Empowers Retail Frontline Operations with Advanced AI-Powered Solutions, January 9, 2026. Source of the TC501 and TC701 Gen2X quote. Fetched and verified 2026-09-13. Link
  • Nedap Identification Systems, UHF RFID tag security for automatic vehicle identification. Source of the TID cross-copy statement, the EPC copy statement, and the EPC-plus-TID recommendation. Fetched and verified 2026-09-13. Link
  • Jukka Voutilainen, Voyantic, What Gen2v2 Security Offers for RAIN RFID Applications, February 12, 2016. Source of the tag authentication mechanism description and the ISO/IEC 29167 crypto suite reference. Fetched and verified 2026-09-13. Link
  • Mark Roberti, RFID Journal, What Is a TID? Source of the “It cannot be altered” quote. Fetched and verified 2026-09-13. Link
  • RFID Label, TID vs EPC: Decoding the Critical Roles of RFID Tag Serial Numbers in Asset Identification. Source of the “immutable birth certificate” and “cannot be altered or reprogrammed by users” quotes. Fetched and verified 2026-09-13. Link
  • RFID Card, What Is TID Number: A Simple Guide to This Critical RFID Identifier. Source of the “fingerprint” and “tamper-proof nature” quotes. Fetched and verified 2026-09-13. Link
  • InfinID Knowledge Base, Products/Passive RFID/Passive RFID Overview.md. Source of all InfinID hardware and frequency references. Internal.