Bricked xEM implant

Just installed the xEM implant into my right hand. Attempting to clone a HID card, and it appears that the implant is bricked. I have a proxmark3 rdev4, and have had no trouble cloning Mifare and HID cards up to this point. Any help would be appreciated as I donā€™t want to have to cut this out of my hand and install another one.

Thanks,
-Jason

1 Like

What happened? Is the Proxmark not recognizing it, or is a reader not recognizing it?

Proxmark canā€™t identify a modulation scheme, a lf search returns a nice sine wave on the graph, but no data

Did you manage to get it working again? My xEM (implanted) is showing a waveform on pm3 with the new proxLF antenna but the modulation cannot be recognised.

Fixed it with a lf t55xx write b 0 d 00088040 p AA55BBBB t :smiley:

Then I was able to write HID config. Finished up with the following two, which now let me get the t55 infoā€¦

lf t55xx write b 1 d E0150A48 1
lf t55xx write b 2 d 2D782308 1

3 Likes

Lol, completely missed this comment! I deleted my last response as it must have been wrong in some way. I mustā€™ve used that command in addition to the million steps I tookā€¦ glad you found the fast way!

1 Like

Iā€™m curious where I can find out more about the flags that are used in this command. is ā€œp AA55BBBBā€ a password being set?

The reason Iā€™m asking is I have an xEM implant and I tried to use the ELECHOUSE Proxmark 3 RDV2 with the less-than-optimal LF coil that came with it. Iā€™m waiting for a proper coil in the mail that is tuned for these glass chips, but in the meantime I wanted to do more research into figuring out how to un-brick my glass chip and bring it back to the factory defaults it shipped with. I made the mistake of issuing a wipe command and then I applied the block 1 and block 2 command you posted above. Itā€™s still locks up my proxmark whenever I try a ā€œlf searchā€ command or any basic command to read what is written on the chip.

I guess Iā€™m just asking for some help or some links to educate myself better. Iā€™ve tried the ā€œQuirks of Cloningā€ forum post, but Iā€™m still getting the same issue.

http://www.proxmark.org/forum/viewtopic.php?id=6482

Have a read through this too. The p value was password set by white cheap Chinese cloner I now believe, though I donā€™t recall performing an intentional write with the cloner. You shouldnt need to use that switch.

Have a read of the data sheet too for the em chip, that will hopefully fill any gaps left after youā€™ve read the thread I pasted above. Let us know how you get on. I tried just about everything to get mine active again over several evenings, dont give up :slight_smile:

2 Likes

Turns out I hadnā€™t bricked it. I used the ā€œlf t55xx readā€ command after doing ā€œhw tuneā€ and I didnā€™t realize I could get an analogue output on the oscilloscope while I moved the antennae around until I got the cleanest read possible with the worst possible antennae for the xEM. Once I had about an 85% success rate, I sent the clone command and it took.

I just wanted to thank you for telling me to keep at it. I was too eager and didnā€™t do my research. In the end, it forced me to read up on several websites until I had a better understanding of everything. Including your link. Iā€™m kinda glad I got myself in this situation.

2 Likes