Do You Actually Need an RFID-Blocking Wallet?
In this article
For your bank card, almost certainly not. The crime an RFID wallet is sold to prevent does not appear in Europe's official payment fraud statistics at all. When journalists asked the card networks and the banking trade bodies to name one verified case, none of them could.
There is a card in most people's wallets that can genuinely be copied by someone standing near them. It is not the bank card, and nobody is selling wallets to protect it.
Key Takeaways
- RFID blocking is marketed against "electronic pickpocketing" of contactless bank cards. That category does not exist in the EU's official payment fraud reporting.
- In the joint EBA and ECB payment fraud report covering 2024, the words "skimming" and "RFID" do not appear once across 49 pages.
- Card fraud is overwhelmingly a lost, stolen or copied-number problem. In 2024, lost or stolen cards accounted for 42% of the value of in-person card fraud in the EU and EEA.
- A contactless card is a poor target because it generates a one-time code per transaction. A captured reading cannot be replayed.
- Office, building and transit passes are the real proximity risk. Researchers showed a MIFARE Classic card can be cloned with only a few minutes of nearby access.
- We do not put RFID shielding in our wallets. That is a reason to check the sources below rather than take our word for it.
What RFID Blocking Is Sold Against
The pitch is consistent across the category. A criminal walks past you with a concealed reader, powers up the chip in your contactless card through your clothing, captures enough data to make a purchase, and moves on. You notice nothing. A metallic layer in the wallet lining blocks the signal and stops it.
The physics of the first half is real. A contactless card has no battery; it draws power from a reader's field and responds. Point a strong enough reader at it and it will answer.
Whether the answer is worth anything is the part the marketing skips.
How Often Does This Actually Happen?
Nobody can give you a number, and that absence is the most useful piece of evidence available.
The European Banking Authority and the European Central Bank publish a joint report on payment fraud across the EU and EEA. The 2025 edition covers 2024 and runs to 49 pages. It breaks card fraud into named categories: lost or stolen card, counterfeit card, card not received, card details theft, modification of a payment order, manipulation of the payer, and other.
Across all 49 pages, "skimming" appears zero times and "RFID" appears zero times. Contactless is discussed only as a reason banks may skip a PIN prompt, never as a threat. The regulators tracking every euro of card fraud in Europe do not have a line item for this.
Someone did put the question directly to the industry. Security author Roger Grimes, writing for CSO Online in 2017, contacted Visa, Mastercard, the Secure Technology Alliance and UK Finance. He reported that he could not locate public evidence of a single real-world RFID contactless crime.
UK Finance's Maeve Dunne answered him bluntly. Waving a card reader about in the street or on a train cannot take a payment from passers-by, she said. She added that no verified report of it happening in the UK had ever reached them.
That article is from 2017 and is old enough to deserve scepticism on its own. Put it beside the 2024 figures and nothing has moved in between: demonstrations at security conferences, no pattern of prosecutions.
To be precise about what this does and does not prove. It is not proof that no such theft has ever occurred anywhere. It is evidence that the bodies who would record it do not record it, and the bodies who would know of a case could not produce one.
So Where Does Card Fraud Actually Come From?
The same report shows what the money is really lost to.
Fraud on cards issued in the EU and EEA came to €1.3 billion in 2024, which is 0.033% of the value of card payments. Put another way, about one euro in every three thousand spent on cards was fraudulent. Most of that is remote fraud: someone using your card number online, taken from a data breach or a phishing page rather than from your pocket.
For fraud that happens face to face, the leading category is the oldest one there is. Lost or stolen cards accounted for 42% of the value and 56% of the cases of in-person card fraud in 2024. Counterfeit cards accounted for 11% of the value.
Two things follow. First, the dominant risk to your card is a thief with their hands on it, or a retailer's database leaking your number to someone who never comes near you. Second, neither of those cares what your wallet is lined with.
It is worth sitting with how ordinary that list is. A pickpocket, a coat left on a chair, a wallet on a café table, a breached online shop. These are the ways cards are actually misused, and they are the reason banks build fraud detection and refund policies rather than sell you shielding.
Why a Contactless Card Is a Bad Target
Even if someone did read your card, what they get is close to useless.
EMVCo, the body that maintains the contactless standard, describes the mechanism plainly: a one-time use security code is generated for every transaction. The card does not hand over a reusable secret. It answers a specific challenge with a value valid for that transaction only, so a captured reading cannot be replayed at a shop or typed into a website.
Set that against the alternative available to a criminal. Card numbers stolen in bulk from a breached retailer are sold in quantity, work for online purchases, and require no proximity to anyone. A crime that needs you to physically approach one stranger at a time, to harvest a credential that expires on use, is not a rational way to steal money. That, more than any shielding, is why it does not happen.
The Card in Your Wallet That Can Be Copied
Here is the part the RFID wallet industry never mentions.
Your bank card is not the only contactless card you carry. Most people also carry an office door pass, a building fob, a gym card or a transit card. Many of those run on MIFARE Classic, a chip whose cipher has been broken in public research for well over a decade.
Nicolas Courtois, presenting at SECRYPT 2009, described a card-only attack: the attacker "only needs to be in the proximity of the card for a number of minutes," with no access to the genuine reader. He put roughly 200 million MIFARE Classic cards in circulation at the time, used for rail and building passes. Later refinements cut the time required substantially.
That is precisely the threat model the RFID wallet was sold to you for — someone standing near you, copying a card through a pocket. It is real. It just applies to the wrong card.
The consequence differs too, and not in your favour. A cloned bank card runs into a bank's fraud detection, gets stopped, and the money comes back. A cloned door pass opens a door, and nobody refunds that.
None of this makes MIFARE Classic a crisis you need to act on today. Plenty of sites have moved to newer chips, and cloning a pass is only useful to someone who wants into your particular building. The point is narrower: the one contactless card in your wallet with a demonstrated proximity attack against it is the one no wallet on the market advertises protection for.
So Should You Buy One?
For the bank card in your pocket, there is no evidence-based reason to.
There are two situations where shielding is worth thinking about, and neither is the one on the packaging:
- You carry a legacy access credential. An office, building or transit card on older technology is the credential with a demonstrated proximity attack against it. If your employer issues one, the sensible move is to ask their security team what it is rather than to buy a wallet.
- Your organisation requires it. Some workplaces mandate a shielded sleeve for the badge. That is a policy question, not a consumer one.
For everyone else, a shielded lining protects a card that does not need protecting and does nothing for the ways money is actually taken.
If you want to spend the effort somewhere useful, spend it on the categories that do show up in the statistics. Turn on transaction alerts so a stolen card announces itself within seconds rather than at the end of the month. Know how to freeze the card from your banking app, and know it before you need it. Keep the wallet in a front pocket or an inside pocket in crowds, since the leading in-person fraud category still begins with someone physically taking the card. None of that costs anything, and all of it addresses a risk the numbers actually record.
What We Put in Our Wallets, and What We Do Not
We should be straightforward about our position here, because it is convenient for us.
Our wallets do not have RFID shielding. We have never built it in. So an article concluding that you do not need it is exactly what a brand in our position would write, and you should treat it accordingly.
So every claim above carries an attribution, and every source sits at the foot of this page with a link. The EBA and ECB report is free to download. The EMVCo description is on EMVCo's own site. The MIFARE research is a published conference paper. You do not have to believe us; you can read what we read.
What we do build is a wallet cut from full grain vegetable tanned leather, hand stitched, with no lining at all. That last detail matters here. Shielding has to live somewhere, and in most wallets it is a metallic layer bonded inside a lining — which adds a bond line that can peel away from the leather over the years. We make the same argument about linings in our guide to stitchless card holder construction, where removing components is the whole design.
So leaving it out suits us twice over: it matches the evidence, and it removes a component we would rather not build. We would sooner say that plainly than pretend we reached the conclusion from a neutral standpoint.
Frequently Asked Questions
Does a leather wallet block RFID on its own?
No. Leather is not a meaningful barrier to a radio signal at these frequencies. Any brand claiming its plain leather wallet blocks RFID is describing something the material does not do.
Do RFID-blocking wallets work?
A properly built shielded pocket does attenuate the signal, so the product generally does the thing it says. The question is whether the thing is worth doing for a bank card, and the fraud statistics suggest it is not.
Can someone charge my card by walking past me?
Taking a payment requires a real merchant account tied to a real business, and the transaction has to clear. UK Finance's position, quoted above, is that no verified case of this has been reported in the UK.
Is contactless less safe than chip and PIN?
Contactless transactions in the EU are more often exempted from a PIN prompt, which is why they exist. In the 2024 data, in-person card payments exempted from strong authentication showed fraud rates generally lower than remote transactions and often below the overall card fraud rate.
What actually protects my card?
Noticing quickly that it is gone, and checking your statements. Lost and stolen is the leading in-person fraud category, and the countermeasure is reporting speed rather than hardware.
Should I shield my passport?
An e-passport is a separate case with its own protocol, and it spends most of its life at home rather than in a pocket. If you want a shielded sleeve for travel, buy the sleeve rather than rebuilding your everyday wallet around it.
The Short Version
RFID blocking answers a question almost nobody is being harmed by. Card fraud in Europe is a lost card, a stolen card, or a number lifted from a database — and none of those care what your wallet is made of.
The proximity attack the marketing describes does exist. It works on office and transit passes, not on the card with a bank's fraud department behind it. If that risk applies to you, the answer is your employer's security team, not a wallet lining.
Our wallets and card holders are hand stitched in Istanbul from full grain vegetable tanned leather, with no lining and no shielding. They also arrive firm, which is a separate thing worth knowing before you buy — breaking one in takes a few weeks of daily carry.
Sources
- European Banking Authority and European Central Bank, 2025 Report on Payment Fraud (EBA/REP/2025/40), December 2025, covering 2024 data. ecb.europa.eu — retrieved 8 August 2026.
- EMVCo, EMV Contactless Chip. emvco.com — retrieved 8 August 2026.
- Courtois, N. T. The Dark Side of Security by Obscurity — and Cloning MiFare Classic Rail and Building Passes, Anywhere, Anytime. SECRYPT 2009, Milan. IACR ePrint 2009/137. eprint.iacr.org — retrieved 8 August 2026.
- Grimes, R. The truth about RFID credit card fraud. CSO Online, 19 December 2017. csoonline.com — retrieved 8 August 2026.



