EU age-verification app hacked twice in three months
In April of this year, security researcher Paul Moore showed he could hack the European Commission’s age-verification reference app in “under 2 minutes.”
— Paul Moore – Security Consultant (@Paul_Reviews) April 16, 2026
Now, three months later he notes: “Despite 3 months of security hardening and genuine improvements across the board, the fundamental issue cannot be solved.”
Moore has demonstrated two distinct bypasses of this newer version of the app. It could be bypassed using both a modified client and an automated relay to a legitimate remote device. Moore documented the modified-client bypass and the subsequent relay demonstration on X.
#EU#AgeVerification unfixable bypass: ✅ Automate the device ✅ Detect and relay the QR code ⏱️ Push to GitHub
Once an age verification QR code appears, it will detect & automatically relay to a legitimate device that completes the verification remotely.
“The security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts this assumption, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.
“Half of what Moore demonstrated is solvable. A cloned app with the ID checks ripped out should never have reached a verification endpoint, as this is a solved problem. The spec mandates hardware-backed keys but puts app attestation explicitly out of scope. They protected the credential but left the client unverified. The other half, relaying the QR code to an adult’s real device, is not solvable by any attestation technology, ours included.”
The EU really needs to solve this issue and look at other items just like it. Otherwise it will end badly for them.
This entry was posted on August 4, 2026 at 7:52 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
EU age-verification app hacked twice in three months
In April of this year, security researcher Paul Moore showed he could hack the European Commission’s age-verification reference app in “under 2 minutes.”
Now, three months later he notes: “Despite 3 months of security hardening and genuine improvements across the board, the fundamental issue cannot be solved.”
Moore has demonstrated two distinct bypasses of this newer version of the app. It could be bypassed using both a modified client and an automated relay to a legitimate remote device. Moore documented the modified-client bypass and the subsequent relay demonstration on X.
Ted Miracco, CEO, Approov had this to say:
“The security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts this assumption, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.
“Half of what Moore demonstrated is solvable. A cloned app with the ID checks ripped out should never have reached a verification endpoint, as this is a solved problem. The spec mandates hardware-backed keys but puts app attestation explicitly out of scope. They protected the credential but left the client unverified. The other half, relaying the QR code to an adult’s real device, is not solvable by any attestation technology, ours included.”
The EU really needs to solve this issue and look at other items just like it. Otherwise it will end badly for them.
Share this:
Like this:
Related
This entry was posted on August 4, 2026 at 7:52 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.