TL;DR: The EU Age Verification App Was Hacked in 2 Minutes
The EU age verification app stores authentication controls, including PIN encryption, rate-limiting counters, and biometric bypass flags, in a plain-text, user-editable local configuration file. Security consultant Paul Moore bypassed the full authentication system in under two minutes by deleting two values and restarting the app. A separate March 2026 analysis found the issuer component cannot verify that passport verification actually occurred on the device, meaning the entire trust chain is unverifiable. These are not bugs. They are design decisions that any startup security review would have flagged in a first pass. The deeper question is what the credential expiry dates, verification limits, and EUDI Wallet integration roadmap say about what this infrastructure is actually being built to do.