Brussels EU Age Verification App — Hacked in 2 Minutes
Politico coverage: Brussels launched an age checking app. Hackers say it takes 2 minutes to break it. – POLITICO 2
Additional coverage:
Cybernews — New EU age verification app hacked in minutes: https://cybernews.com/security/eu-age-verification-app-hack/ 3
April 17, 2026
Cyber experts say they have found holes in Brussels’ age verification app, despite claims by the EU executive that it is “technically ready.
Within hours of the EU’s app release, security consultant Paul Moore found it would store sensitive data on a user’s phone and leave it unprotected.
Brussels launched an age checking app. Hackers say it takes 2 minutes to break it.
Cyber experts say they have found holes in Brussels’ age verification app, despite claims by the EU executive that it is “technically ready.”
European Commission President Ursula von der Leyen presented the age-verification tool in Brussels on Wednesday, saying it was “technically ready” and will soon be available to use as countries move to ban kids from social media.
“It is fully open source. Everyone can check the code,” von der Leyen said.
Cyber and privacy experts immediately dove into the source code on the GitHub software platform and reported several issues with the app’s design.
The saga is turning into a PR disaster for Brussels.
Brussels launched an age checking app. Hackers say it takes 2 minutes to break it.
Cyber experts say they have found holes in Brussels’ age verification app, despite claims by the EU executive that it is “technically ready.”
Cyber and privacy experts immediately dove into the source code on the GitHub software platform and reported several issues with the app’s design.
The saga is turning into a PR disaster for Brussels. But underneath the controversy over the code lie deeper divisions between privacy campaigners, child rights groups, tech firms and politicians over how to protect minors online — as leaders promise to shield kids from social media and porn sites.
Within hours of the EU’s app release, security consultant Paul Moore found it would store sensitive data on a user’s phone and leave it unprotected, he wrote in a widely shared post on X. Moore claimed to have hacked the app in under 2 minutes.
Baptiste Robert, a prominent French white hat hacker, confirmed many of the issues and told POLITICO it was possible to bypass the app’s biometric authentication features, meaning someone would be able to forgo entering a PIN code or using Touch ID to access the app.
Olivier Blazy, a cryptographic researcher who is part of a French task force on digital identity, said: “Let’s say I downloaded the app, proved that I am over 18, then my nephew can take my phone, unlock my app and use it to prove he is over 18.”
> Brussels EU Age Verification App — Hacked in 2 Minutes <
For every measure there will be a countermeasure.
But hacked in two minutes? That’s impressive. Either the hackers are really good or the EU app developers are really dumb.
Hmm…it’s probably both.