Except those crypto-card thingies (not the implantable ones) were duplicated as a result of the recent RSA breakin, which is how Lockheed was attacked.
The working theory is that RSA retained information on the crypto "seeds" used to initialize the hardware tokens at the factory. When this database was hacked the attackers obtained a copy of this seed material. This was enough to duplicate the code sequence displayed on the key, though possibly in conjunction with a phishing or social engineering attack to obtain the target user's serial number (or a few current codes).
That's the theory anyway. Not everyone agrees that it's the Chinese-attacking-US-defense-contractors story again.
What everyone does agree on though is that RSA is withholding critical information about the severity of the compromise, or maybe even being a little disingenuous about it.