Age verification EU, hacked in 2 minutes, poorly coded surveillance

Paul Moore skirts the EU's age-verification app in under 2 minutes. The EUDI standard promised zero-knowledge. Its implementation stores the PIN in an editable XML.

The EU’s age verification app, launched on April 14, 2026, was bypassed in under two minutes. The real scandal isn’t the bug, it’s the implementation choice.

The Facts

On April 14, the Commission unveils its age verification app, a cornerstone of the online child protection system across the 27 member states. Three days later, British consultant Paul Moore publishes a demo, completely bypassing it in under two minutes. French cryptographer Olivier Blazy confirms the diagnosis. A moratorium signed by 400+ researchers had already warned in March. No one listened.

The Three Flaws

  • Editable config, the encrypted PIN is stored in eudi-wallet.xml, locally modifiable.
  • Boolean biometrics, a true/false flag governs biometric auth. Flip, skip.
  • PIN not linked to the vault, an attacker redefines the PIN by reusing previous profile credentials.

The Alternative Existed, Within the Standard Itself

The EUDI Wallet standard allows for selective disclosure via SD-JWT VC (Selective Disclosure JSON Web Token Verifiable Credentials), proving one’s age without revealing birthdate or linking sessions, using zero-knowledge proofs. Implementations like IRMA/Yivi (Radboud University), AnonCreds (Hyperledger), and Google ZK age assurance already exist.

The EU wrote the right standard. The reference app betrayed it by storing the PIN in an editable XML.

The Pattern

Same logic as Chat Control / CSAR, Brussels pushes a surveillance infrastructure, no one audits it upfront, beginner-level flaw. The EUDI Wallet will soon manage IDs, prescriptions, fiscal signatures for 450 million Europeans. A trivial flaw today isn’t just an incident, it’s a warning.

Digital sovereignty means the right to not prove one’s age at every click. And if we must, then via ZKP, not via a finger-in-the-dyke XML.

To Read on MacSouverain

Read: Chat Control 2, the mass surveillance that doesn’t say its name

Read: NIS2 vs CSAR, two opposing security logics

Sources