NYC’s Inauguration Banned Flipper Zero. What Does the Gadget Actually Do?

Illustration of a hooded cat holding a yellow device beneath wireless symbols.

New York City’s 2026 inauguration had a prohibited-items list with a particularly odd guest: the Flipper Zero. The pocket-sized gadget with a dolphin mascot appeared alongside Raspberry Pi computers, drones, umbrellas, and weapons or explosives.

A dolphin sharing a security checklist with explosives is excellent material for the internet. It is less useful as a technical assessment. The Flipper Zero is neither a universal hacking wand nor an entirely harmless toy. What it can do depends on the system in front of it.

What New York actually prohibited

The city’s official inauguration checklist explicitly names both Flipper Zero and Raspberry Pi. This was an event restriction, not a citywide prohibition on owning either device.

The document gives no device-specific explanation. It also excludes chairs, blankets and large bags. Sharing a list does not mean the organizers considered every item equally dangerous; nobody needs a bomb squad for a folding chair.

It is fair to ask why these particular computers were singled out. It goes further than the available evidence to declare that the organizers had no security rationale at all. The list tells us the rule, not the reasoning behind it.

What the little dolphin can actually do

The Flipper Zero hardware combines several interfaces in one handheld device: sub-GHz radio, infrared, low-frequency RFID, NFC, iButton contacts, Bluetooth and expansion pins. That makes it useful for exploring access-control systems and everyday electronics.

At home, the appealing version of this is quite ordinary: experimenting with your own tags, organizing infrared remote commands or learning which technology an access token uses. There is a satisfying moment when an apparently mysterious plastic fob becomes a recognizable protocol. The dolphin gets an adventure; you get an electronics lesson.

Advertisement

Flipper’s NFC documentation describes reading, saving and emulating supported cards. “Supported” does considerable work there. Reading a card identifier is not necessarily the same as reading all its protected contents, and possessing that identifier does not guarantee that a reader will accept an imitation.

A hotel card, office badge and transit pass may look similar while using very different authentication systems. “It copies key cards” is a starting point for a question about the particular card, rather than a promise about every door.

Bank cards and cars are not television remotes

A TV can accept the same infrared command repeatedly. Secure payment systems are designed to do something more demanding. EMVCo’s explanation of payment security describes transaction-specific cryptographic codes used to authenticate payments.

That is why reading some information from a contactless bank card does not produce a functioning clone capable of authorizing arbitrary new EMV transactions. It is not a guarantee that payment fraud cannot happen; it explains why the viral “tap a stranger’s wallet and copy their bank card” story skips the important part.

Cars deserve similar care. A simple recording-and-replay trick against a fixed-code remote does not automatically work against a correctly implemented rolling-code system, where accepted messages change.

However, “rolling code” is not a magical certificate of invulnerability. In an August 2025 response to car-hacking claims, Flipper’s founder discussed old KeeLoq weaknesses and leaked manufacturer keys. He distinguished attacks on some remote-locking systems from starting an engine, and emphasized that purpose-built relay equipment is a different category of hardware.

The manufacturer has an obvious interest in defending its product. The useful distinction remains: demonstrating one action on one vehicle does not prove that the device can steal any car, while a car’s recent model year alone does not prove every component is secure.

The Wi-Fi claim needs an asterisk

The standard handheld has no built-in Wi-Fi radio. That limits what it can do on its own, but the expansion connector exists for a reason. Flipper also documents a separate Wi-Fi Developer Board.

Accessories and firmware can change the setup. A video using added hardware is not demonstrating the capabilities of the bare device, and installing unofficial software does not automatically make every possible use lawful or safe.

This is where both the panic and the fan-club defense become unhelpful. “It hacks everything” and “it could never cause trouble” are equally poor substitutes for asking what equipment, software and target system are involved.

Canada’s debate came in 2024

The Canadian government’s February 8, 2024 auto-theft announcement proposed examining ways to prohibit devices it associated with copying vehicle-entry signals, explicitly naming Flipper Zero.

A subsequent radiocommunication consultation considered restrictions and their effects on legitimate uses. That is a more complicated policy discussion than “Canada banned the dolphin in 2023.” An announcement, a consultation and an enacted prohibition are different things.

The useful security lesson

A tool that makes weak access systems easier to examine can be valuable to researchers and misused by somebody else. Public documentation does not eliminate misuse, and misuse does not erase legitimate applications.

For a building operator, the productive question is whether the access system authenticates a credential securely, and how lost credentials are revoked. For a hobbyist, it is whether the experiment concerns equipment they own or are authorized to test. Neither answer depends on how adorable the screen animation is.

The inauguration ban makes a memorable headline. The more interesting story is the gap between the devices we carry, the protocols they use and the confidence we place in them. The dolphin can stay cute while we take that seriously.

Advertisement
Share this story

Leave a Reply

Your email address will not be published. Required fields are marked *