Authors - Zumna Usman, Madiha Khalid, Weiwei Jiang, Momina Shaheen, Umar Mujahid, Muhammad Najam-ul-Islam Abstract - The Internet of Things (IoT) networks operate under strict resource constraints having limited computational capability, memory, bandwidth, and energy, while still being required to combine essential security goals such as confidentiality and mutual authentication with efficiency, particularly in Radio-Frequency Identification (RFID)-based systems. For this reason, Ultra-Lightweight authentication protocols are commonly used, where traditional cryptographic techniques are often too demanding. The Random Rearrangement Block Matrix-Based Ultra- Lightweight RFID Authentication Protocol (RUAP) was introduced to strengthen security. In this paper, RUAP is analyzed and shown not to eliminate fundamental weaknesses. By applying a probabilistic disclosure attack, it is shown that public messages leak exploitable statistical information, making it possible to fully recover the identifier in reduced configurations and to recover about 71.77% of a 96-bit identifier. It is further shown that RUAP’s asymmetric key update mechanism allows adversaries to trigger desynchronization, resulting in denial of service.