A security researcher has broken the European Union's age verification app for a third time since April, and this time the warning attached to the finding is more unsettling than the last two. According to reporting from TechRadar, the expert behind the repeated tests says the app's problems aren't just about proving how old someone is anymore. "The next step will be proving who you are," the researcher warned, a line that reframes the entire debate around the EU age verification app hack from an awkward bug story into a genuine identity-security concern.

What the Researcher Broke, Three Times Over

The EU's age verification app was built to let people confirm they meet a minimum age threshold without handing over unnecessary personal data to every website or platform that asks. That was the pitch, at least. Since it launched, the same security researcher has found ways to undermine that promise on three separate occasions. Each time, the flaws have chipped away at the core claim that the app is a privacy-preserving alternative to uploading a passport scan or driver's license photo directly to a website.

The details of each individual flaw matter less than the pattern they form. An app designed and marketed as a trustworthy, low-friction verification layer for hundreds of millions of EU citizens has now failed independent scrutiny three separate times in a matter of months. That is not a one-off implementation bug. It is a track record.

Why Age Verification Apps Are a Bigger Identity Target Than They Appear

It's tempting to think of an age check as a low-stakes piece of software. You're not proving your bank balance or your medical history, just whether you're over 18. But that framing misses how these systems are actually built. To verify age reliably, an app typically has to anchor itself to some form of official identity document or government-backed data source. That means the infrastructure behind an age gate often has a direct line to exactly the kind of identity data attackers want most.

This is the core of the researcher's warning. If age verification is the wedge issue that gets citizens comfortable installing a government-linked app on their phones, the next logical step for regulators and platforms is broader identity verification for other services. If the age-check layer can be manipulated or bypassed today, there's little reason to assume the identity layer that follows will be inherently more secure. A system that fails at the simpler task doesn't inspire confidence for the harder one.

This concern isn't unique to the EU. Similar tension is playing out wherever governments push mandatory age or identity checks, from proposals like Canada's Bill C-34 requiring ID checks for social media, to the patchwork of state age verification laws currently stuck in legal limbo in the United States. Each of these efforts asks users to trust that a verification layer built quickly, under political pressure, will hold up against real-world attackers.

The EU's Privacy Promises Versus This App's Real-World Security Gaps

When the app was introduced, officials framed it as a technically sound solution that would let users verify age without exposing identity documents to third parties. Repeated hacks complicate that narrative considerably. Privacy advocates have already been raising structural concerns about how age verification claims hold up under examination. As detailed in the EDRi advisor's breakdown of why age verification privacy claims don't add up, the gap between what these systems promise and what they can actually guarantee has been a recurring theme well before this latest hack.

That skepticism has translated into political action. EU citizens, backed by the Pirate Party, have pushed a formal initiative to make privacy protections in age verification legally binding rather than aspirational, a move covered in the report on EU citizens pushing to make privacy age verification binding. The existence of that campaign underscores a simple point: right now, the privacy guarantees attached to this app are policy commitments, not enforceable technical facts, and three separate hacks in a matter of months make that distinction hard to ignore.

What This Means For You

If you're an EU resident who has installed or is considering installing the age verification app, none of this means your data has definitely been exposed. It does mean the security assurances behind the app have not held up consistently under outside testing, and that's worth factoring into how much you rely on it for now.

Practically, that means staying cautious about what personal information you link to the app beyond what's strictly required, keeping the app and your device software updated, and paying attention to official EU communications about patches or fixes tied to each disclosed flaw. It also means supporting the push for binding, enforceable privacy rules rather than assuming voluntary commitments are enough, since that pressure is often what turns a promising design into a genuinely trustworthy one.

The broader lesson extends beyond this one app. As more governments experiment with mandatory age and identity verification, the EU's experience is becoming a useful case study in what can go wrong when speed to launch outpaces security testing.

Actionable takeaways:

  • Limit the personal data you attach to any age verification app beyond the legal minimum required.
  • Watch for official patch announcements and update the app promptly when fixes are released.
  • Follow independent security research rather than relying solely on official "technically ready" claims.
  • Support calls for legally binding privacy protections in age verification systems, not just voluntary promises.
  • Treat any app that touches identity or age data with the same caution you'd apply to financial or medical apps.