Coin RFID Keyfobs
RFID Coin Keyfob
Vending & Laundry Token
Quick answer
RFID coin keyfobs are compact round credentials (Ø 25 / 30 mm × 3-4 mm, pocket + keyring carry) engineered for cashless micropayment in laundry rooms, unattended vending, self-serve car washes, pay-per-use lockers and arcades. The specification envelope couples MIFARE DESFire EV2 / EV3 AES-128 stored-value files (NXP AN12343 Transaction MAC + NIST FIPS 197 cipher) to Nayax / USA Technologies / Setomatic / CSC ServiceWorks cashless controllers, with ISO/IEC 14443-3/-4 air-interface, IEC 60529 IP67 sealed housing, BSI TR-02102-1 cipher-suite alignment and a documented Classic → DESFire migration posture that closes the CRYPTO-1 counterfeit-coin exposure path.
- Ø 25 / 30 mm × 3-4 mm coin form — pocket-friendly, keyring-compatible, slots into legacy coin-acceptor adapters for retrofitted coin-operated machines.
- DESFire EV2 / EV3 AES-128 stored-value file (NXP AN12343) on Common Criteria EAL5+ silicon — mutual authentication + Transaction MAC defeats CRYPTO-1-style counterfeit-balance attacks that cost the US vending industry ~$1 billion / year (NAMA reporting).
- Cashless operator payback in 7-11 months for a typical 12-site laundry operator — coin-collection labour, coin-processing bank fees, theft shrinkage and per-machine analytics together recover the keyfob + controller capital within the first year.
At a glance
Use these short answers to decide whether this page matches the project before moving into the detail.
Form factor
Ø 25 mm or Ø 30 mm coin, 3-4 mm thick Keyring hole (2.5 mm) for carry-on-keychain, or plain edge for pocket-carry / coin-slot retrofit
Chip options
NTAG213 / NTAG216 (tap-to-URL / basic token, no encryption) MIFARE Classic 1K (legacy compatibility only — CRYPTO-1 documented, NOT recommended for new stored-value depl...
Next step
Ready to move forward? Start your inquiry to get specific answers for this project.
Request quote and samples- Air interface
-
- ISO/IEC 14443-3:2018 Type A anticollision at 13.56 MHz
- ISO/IEC 14443-4:2018 T=CL framing with Transaction MAC on EV2/EV3
- NFC Forum Type 4 Tag — NDEF access profile
- Cryptographic posture
-
- AES-128 mutual authentication per NIST FIPS 197 on DESFire variants
- Transaction MAC + commit counter per NXP AN12343 — anti-replay on every value-file update
- BSI TR-02102-1 cipher-suite alignment for operator / PSP audit closure
- Cashless-controller compatibility
-
- Nayax VPOS Touch / Nayax Onyx (laundry + vending)
- USA Technologies ePort G10-S / ePort Engage (vending + micromarket)
- Setomatic SpyderWash 3, CSC ServiceWorks Tide, Dexter DexterLive (commercial laundry)
- Stored-value architecture
-
- Server-side balance — chip holds only a signed credential ID, balance lives in operator backend (recommended for connected readers)
- On-chip DESFire value file — AES-128-protected balance on the chip itself (for offline / intermittent-network readers)
- Hybrid model — low-value settles on-chip, high-value / admin routes to backend (the real-world default)
- Housing & durability
-
- ABS injection-moulded or two-part epoxy dome over inlay — no seam, no adhesive layer
- IEC 60529 IP67 sealed — handles pocket moisture, laundry-room spray, car-wash overspray
- 10,000+ tap cycles + -20 to +80 °C operating range (commercial-washer-adjacent)
- Operator deployment targets
-
- Apartment / HOA laundry rooms replacing quarter-operated washers and dryers
- Unattended vending, micromarket, car wash, arcade, family entertainment centre
- Gym / pool / coworking-space locker rental with per-minute or per-cycle billing
- Fraud-prevention posture (CRYPTO-1 migration)
-
- MIFARE Classic 1K CRYPTO-1 publicly broken since Garcia et al. 2008 — cloneable with Proxmark3 + mfoc/mfcuk
- Industry loss: 2-4 % of gross revenue in NAMA-reported coin-operated machine theft and shrinkage
- DESFire EV3 upcharge ~$0.25 / coin recovers on the first prevented counterfeit incident
- Custom print / personalisation
-
- Logo, denomination value, serial number, color on one or both faces
- Multi-value denominations by colour ($5 blue / $10 green / $20 gold) for visual stock
- Factory pre-encoding of AES-128 keys + initial value-file load + signed UID list
- Logistics
-
- MOQ 500 pcs stock / 1,000 pcs custom-printed
- Lead time 10-15 business days stock / 15-20 pre-encoded + printed
- Per-order UID ↔ starting-balance CSV + signed key-ceremony evidence
Commercial terms
- MOQ
- Varies by SKU — stock items from 100 pcs; custom production typically 200-1,000 pcs
- Lead time
- Production 2-3 weeks after artwork and encoding sign-off; reorders on a 3-4 week cycle
- Samples
- Free samples and RF test report with every order; courier at customer cost
- Payment
- 50% T/T deposit, 50% before shipment; Net 30/60 for established accounts; LC for large orders
- Shipping
- FOB Shenzhen / Yantian; DHL, FedEx or EMS air freight; sea LCL / FCL for volume
- Response
- Itemized quote within one business day, Mon-Fri (UTC+8)
RFID coin keyfob at a glance
Metal coin vs RFID coin keyfob — the operator economics
The comparison is not 'is RFID cheaper per transaction' — it is 'what happens to coin-collection labour, bank-processing fees, theft shrinkage and per-machine revenue visibility once coins leave the site'. The four lines below compound in the operator's favour once RFID is in place.
Metal coin / token status quo
- Coin collection 2-4 times / month / site — ~$75 loaded cost / visit on labour + vehicle + security escort
- Bank coin-roll processing fees $0.08-0.15 / roll + 0.5-1 % counting-machine error shrinkage
- Theft loss 2-4 % of gross revenue — pry attacks, slug fraud, coin-on-a-string (NAMA industry reporting)
- Zero per-machine analytics — no peak-time data, no demand forecasting, no customer-frequency visibility
- Lost coin = lost value, no remote recovery possible
- Machine-uptime diagnostics absent — coin-jam events discovered only at next collection visit
RFID coin keyfob (DESFire EV3 AES-128)
- Coin collection labour drops to near zero — online recharge kiosk / app replaces physical visits
- Bank processing fees disappear — card-processor fee only on recharge events (~2.9 % on the recharge, not on every coin)
- Theft exposure closes — AES-128 + Transaction MAC + commit counter on EV3 makes counterfeit balances computationally infeasible
- Per-machine, per-tap, per-user analytics in the controller backend — peak-hour pricing, preventive service scheduling
- Lost coin remotely deactivated + balance transferred to a replacement — zero value lost
- Machine uptime + jam telemetry surfaces in the controller dashboard — service dispatched before revenue is lost
Quantified payback for a 12-site laundry operator
Coin-to-RFID rollout timeline for a multi-site operator
The typical operator does not migrate all 12 sites overnight — they stage through a pilot-site, then roll building-by-building. Proud Tek's preset (DESFire EV3 on 30 mm ABS coin, Nayax VPOS Touch controller) follows the pattern below.
- Week 0-2 · Pilot site — 1 building, dual-acceptance period
One building receives cashless controllers installed alongside the existing coin acceptor. Both payment methods operate in parallel — users can still insert quarters, or tap a coin keyfob. Tenants receive 100-200 pre-loaded coin keyfobs at a leasing-office kiosk with on-site recharge. Controller backend captures baseline telemetry.
- Month 1-3 · Pilot telemetry review + key-ceremony for production issuance
Pilot-site data validates the pricing model (per-cycle vs per-minute billing) and the service-interval trigger. AES-128 master key ceremony runs inside an HSM for production-scale issuance; signed key-derivation log archived as audit evidence. Keyfob order sized to full operator footprint (~2,000 pcs for a 12-site / 1,500-tenant operator).
- Month 3-9 · Rolling site conversion — 2-3 sites per month
Sites convert at ~2-3 per month; each site switches from dual-acceptance to cashless-primary (coin slot disabled, but mechanically left in place for rollback insurance). Tenant adoption runs via leasing-office distribution + online-recharge portal. Coin-collection route progressively shrinks as sites go cashless.
- Month 9-12 · Coin-route retirement + shrinkage-elimination posture
Last coin-operated site converts. Coin-collection vehicle and armored-transport contract are cancelled — the $86k / yr labour line closes. Controller dashboard replaces coin-counting-machine reconciliation; theft-shrinkage line closes because counterfeit-balance attacks against AES-128 DESFire EV3 are computationally out of reach.
- Month 12+ · Steady-state cashless operation + analytics-driven pricing
Field experience covers cashless-laundry, unattended-vending, self-serve-carwash, pay-per-use-locker and arcade-micropayment RFID-coin-keyfob estates, with each vertical contributing its own audit-cycle, replacement-cadence and supplier-governance pattern. per-machine telemetry drives peak-hour pricing, loyalty / volume discount tiers surface in the controller backend, lost-coin replacement is a one-click deactivate-and-reissue operation, and the operator's annual audit closes against the signed UID ↔ account CSV + DESFire Transaction MAC logs without touching physical coin.
RFID coin keyfob — the full specification envelope
Operators comparing quotes want the spec sheet, not adjectives. Here is the coin in one table — dimensions, chip menu, cryptography, sealing and the commercial terms — so procurement can drop it straight into a bill of materials. It sits in the wider RFID keyfob range; if you want the same silicon without the key-ring lug, the coin tag is the adhesive-disc sibling.
| Parameter | Specification | Standard / note |
|---|---|---|
| Coin diameter | Ø 25 mm or Ø 30 mm disc | Pocket-friendly, keyring-compatible |
| Thickness | 3-4 mm | Slots into legacy coin-acceptor adapters |
| Keyring lug | 2.5 mm hole (optional) | Plain edge for pocket-carry or coin-slot retrofit |
| Operating frequency | 13.56 MHz HF | Near-field tap, not long-range |
| Air interface | ISO/IEC 14443-3 / -4 Type A | T=CL framing with Transaction MAC on EV2 / EV3 |
| NFC profile | NFC Forum Type 4 Tag (NDEF) | Tap-to-URL path on NTAG213 / NTAG216 |
| Chip menu | NTAG213 / NTAG216, MIFARE Classic 1K (legacy), MIFARE DESFire EV2 / EV3 | DESFire EV3 is the greenfield default |
| Cryptography | AES-128 mutual authentication on DESFire EV2 / EV3 | NIST FIPS 197 cipher |
| Anti-replay | Transaction MAC + commit counter | NXP AN12343, per value-file update |
| Stored-value model | Server-side balance, on-chip DESFire value file, or hybrid | Backend for connected readers; on-chip for offline |
| Housing | ABS injection-moulded or two-part epoxy dome | Seamless — no seam, no adhesive layer |
| Sealing | IP67 (IEC 60529) | Pocket moisture, laundry spray, car-wash overspray |
| Operating temperature | -20 to +80 °C | Commercial-washer-adjacent duty |
| Tap endurance | 10,000+ tap cycles | Coin outlives the keyring it rides on |
| Cashless controllers | Nayax, USA Technologies, Setomatic, CSC ServiceWorks, Dexter | Retrofit modules installed alongside the coin slot |
| Compliance | RoHS 3 (EU 2015/863), REACH | Declared per shipment of ABS / epoxy housings |
| MOQ | 500 pcs stock / 1,000 pcs custom-printed | Per-order UID ↔ starting-balance CSV |
| Lead time | 10-15 business days stock / 15-20 pre-encoded + printed | Signed key-ceremony evidence included |
Anatomy of a stored-value coin
A coin keyfob is a disc with a secret: a copper coil and a secure die potted under a moulded skin. The buyer-facing decisions are the skin — ABS for colour and price, or a two-part epoxy dome for a seamless, outdoor-adjacent seal — and the security tier of the die underneath. It is the same construction logic as the ABS keyfob, rounded into a pocket coin.
- Moulded disc: ABS injection-moulded or a two-part epoxy dome over the inlay — no seam and no adhesive layer for water to creep into.
- HF coil antenna: a copper coil tuned to 13.56 MHz harvests the reader's energy — there is no battery inside the coin.
- Secure die: MIFARE DESFire EV2 / EV3 carrying the AES-128 stored-value file, or a plain NTAG213 / NTAG216 for tap-to-URL tokens.
- Seal and lug: IP67 potting to IEC 60529 rated for laundry and car-wash overspray, finished with an optional 2.5 mm keyring hole.
Three chips, three security tiers — which belongs in a coin
The coin's body is the easy part; the chip inside is the decision that survives an audit. Three tiers cover every coin programme: a plain tap-token, a legacy chip you should not build new value on, and the AES-128 stored-value default. If the coin holds money, the MIFARE DESFire keyfob chemistry is the one that closes the counterfeit-coin path.
- Tap token — NTAG213 / NTAG216: opens a URL or carries a basic ID with no encryption. Fine for a loyalty tap, wrong for stored value.
- Legacy — MIFARE Classic 1K: the CRYPTO-1 cipher was publicly broken in 2008 (Garcia et al.) and clones in seconds. Keep it only for drop-in compatibility with an existing Classic estate.
- Greenfield — MIFARE DESFire EV2 / EV3: AES-128 mutual authentication plus a Transaction MAC per NXP AN12343 puts a counterfeit balance computationally out of reach.
- The upgrade math: the DESFire EV3 upcharge is about $0.25 per coin — recovered the first time a counterfeit coin is refused at the reader.
Useful next pages
Use these linked product, guide and comparison pages to keep the next click specific and practical.
Related RFID keyfob and token products
Other RFID credential form factors for cashless and access applications.
FAQ
Can RFID coin keyfobs retrofit existing coin-operated machines?
Yes. Most major cashless payment controller manufacturers (Nayax, USA Technologies, Setomatic) offer retrofit modules that install alongside existing coin mechanisms. The RFID reader module accepts coin keyfob taps while the coin slot remains operational during the transition period. Full conversion typically takes 15-30 minutes per machine.
How secure is the stored-value system against cloning or balance fraud?
MIFARE DESFire EV2/EV3 chips use AES-128 encryption and mutual authentication between the chip and reader. Each transaction is cryptographically signed, preventing cloning, replay attacks and balance manipulation. The chip's unique hardware ID (UID) is factory-locked and cannot be duplicated. This is the same security level used in major public transit payment systems worldwide.
What happens if a user loses their coin keyfob?
Since the prepaid balance is stored in the operator's server-side database (linked to the coin's unique chip ID), a lost coin can be remotely deactivated and the remaining balance transferred to a replacement coin. The lost coin becomes inoperable at all readers. This is a significant advantage over metal coins or tokens, where loss means permanent loss of value.
Should I specify MIFARE Classic or DESFire EV3 for a new laundry or vending rollout?
Specify DESFire EV3. MIFARE Classic 1K uses the CRYPTO-1 cipher, which was publicly broken in 2008 (Garcia et al.) and can be cracked in seconds with a Proxmark3 and open-source tools — enabling counterfeit coins with inflated balances. DESFire EV3 uses AES-128 mutual authentication and has no known cryptographic breaks. The per-coin cost difference is approximately $0.25, which is recovered the first time a counterfeit incident is prevented. NXP and the German BSI both recommend migration.
How do I handle offline vending machines with intermittent connectivity?
Use DESFire EV2/EV3 value files for on-chip balance storage with AES-128 protection. The controller debits the value file during a transaction without needing to reach the backend. When connectivity is restored, the controller uploads the transaction log and reconciles against the backend record. Nayax VPOS Touch, USA Technologies ePort G10-S and Setomatic SpyderWash 3 all support this hybrid online/offline model. Do not attempt offline storage on MIFARE Classic — a cloned coin with a forged balance will not be detected until the reconciliation window, by which point the counterfeit coin may have been used at dozens of machines.
What is the MOQ and lead time, and can you pre-encode and brand the coins?
Stock coins are MOQ 500 pcs; custom-printed coins are MOQ 1,000 pcs. Lead time is 10-15 business days from stock, or 15-20 business days when the order is pre-encoded and printed. We print your logo, denomination value, serial number and colour on one or both faces, and multi-value denominations can be colour-coded ($5 blue / $10 green / $20 gold) for visual stock control. Factory pre-encoding covers the AES-128 keys, the initial value-file load and a signed UID list, delivered with a per-order UID ↔ starting-balance CSV and key-ceremony evidence.
Will the coins survive a laundry room or car wash, and are they REACH / RoHS compliant?
Yes. The housing is IP67 sealed to IEC 60529 — moulded ABS or a two-part epoxy dome with no seam or adhesive layer — so pocket moisture, laundry-room spray and car-wash overspray are within spec. The operating range is -20 to +80 °C (commercial-washer-adjacent) and the coin is rated for 10,000+ tap cycles, which outlasts the keyring it rides on. Housings ship with a RoHS 3 (EU 2015/863) and REACH declaration per shipment; an SVHC disclosure is available on request.
Sources & references
Primary standards, OEM datasheets and regulatory documents cited by this article. All URLs were verified on the access date shown below.
- ISO/IEC 14443-3:2018 — Identification cards, Proximity cards, Part 3: Initialization and anticollision
Air-interface standard for MIFARE DESFire EV2/EV3 coin keyfob operation.
- ISO/IEC 14443-4:2018 — Identification cards, Proximity cards, Part 4: Transmission protocol
- NXP AN12343 — Transaction MAC and Secure Unique NFC (SUN) on MIFARE DESFire EV3
Reference for AES-128 value file, mutual authentication and tamper-evident transaction counter on EV3.
- NXP — MIFARE Classic / CRYPTO-1 security status and migration guidance
Vendor rationale for avoiding CRYPTO-1 MIFARE Classic in stored-value coin programs.
- Garcia et al. (2008) — Dismantling MIFARE Classic
- NIST FIPS 197 — Advanced Encryption Standard (AES)
Federal specification for the AES-128 block cipher underpinning DESFire EV3 authentication.
- BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths
German federal cipher-suite recommendations explicitly favour AES-128 over CRYPTO-1; cited in the Classic→DESFire migration guidance.
- NAMA — State of the Convenience Services Industry (annual report)
Industry data source for coin-operated machine theft and shrinkage rates (2-4 % of gross revenue).
- IEC 60529:2013 — Degrees of protection provided by enclosures (IP Code)
IP67 rating for sealed coin keyfob housing — laundry / car-wash / unattended-vending duty.
- Commission Delegated Directive (EU) 2015/863 — RoHS 3 amendment
Restriction of hazardous substances — compliance declared per shipment of ABS / epoxy housings.
- Regulation (EC) No 1907/2006 — REACH
Chemical substance registration and SVHC disclosure framework applicable to the coin housing.
- NXP NTAG213 / NTAG216 — NFC Forum Type 2 Tag datasheet
Vendor datasheet for the NTAG213 / NTAG216 tap-to-URL token option offered on the coin — no cryptographic authentication at the air interface.
Proud Tek is a Shenzhen-based RFID & NFC manufacturer supplying hotel chains, transit operators, event venues and retail brands worldwide. Every order includes free samples, RF testing and dedicated project support.
Get a Quick Quote
Tell us about your project and we'll respond within one business day. Fields marked (asterisk) are required.
