A security researcher has shown it takes less than two minutes to bypass the European Union’s new age verification app using nothing more than a basic file edit on an Android phone.

Paul Moore, who works as a security consultant, posted a screen recording on X showing exactly how it’s done. 

He went through the regular setup first. The app had him create a six-digit PIN, confirm it, pick a verification method, and receive the official 18+ digital credential. Everything looked normal up to that point.

Then Moore switched to a file explorer, opened the app’s shared_prefs folder, and deleted the encrypted PIN entries from eudi-wallet.xml. After restarting the app and entering a brand new PIN, it accepted the change and let him use the original credentials.

The same config file also controls other security features. Reset the rate limiting number to zero, and you can keep guessing PINs indefinitely. Change one boolean value and the app skips biometric checks completely. It all takes just basic file editing.

This demo dropped right after the European Commission announced the app was technically ready. Ursula von der Leyen had called it a high-privacy, open-source solution to protect kids online and urged countries to adopt it fast.

Keep in mind that it’s still labeled as an early development version on GitHub. The readme itself warns that security and privacy standards are lower than final releases and advises against using it in production.

eu-age-verification-app-github-notice

Still, Moore warned that an app like this could lead to a serious breach down the line. The video has already racked up over 2.6 million views.

Online reactions on Reddit and X have been all over the place. Some say physical access to a rooted phone compromises almost any app anyway. Others called the design sloppy, especially since the PIN isn’t properly linked to the actual identity data.

Telegram founder Pavel Durov took it further. In a post, he argued the app was hackable by design because it trusted the device completely. He suggested the EU might now use this breach as an excuse to strip away the privacy features and quietly turn the whole thing into a broader surveillance tool for social media.

pavel-durov-eu-age-verificaiton-app-reaction

The EU plans to push national versions into digital identity wallets later this year. Whether they fix these core problems first remains to be seen.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2742 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.

Next article View Article

Some Instagram users unable to see posts when using search function [Updated]

Update 28/04/26 - 10:46 am (IST): It appears the Instagram search glitch has resurfaced, with a fresh wave of users taking to Reddit to report that the search...
Apr 28, 2026 2 Min Read