The "Silver Bullet" for Age Verification Has Already Been Hacked
Key Takeaways
- The Electronic Frontier Foundation has published an analysis arguing that zero-knowledge proofs (ZKPs), increasingly touted as a privacy-preserving solution for age verification, are gameable, hackable, and create dangerous centralization risks.
- A security researcher found they could bypass the EU's age verification "mini-wallet" app — which uses ZKPs — using a Chrome extension that repeatedly fed the same "over-18" token without triggering fresh verification.
- ZKP-based age verification systems create a single issuer of credentials who can track every time that credential is used and, under pressure, remove a user's access to the internet entirely.
- Over 400 security researchers have signed an open letter stating that age assurance checkpoints, even when implemented with privacy in mind, cause more harm than good.
Supporters of age verification laws have increasingly pointed to zero-knowledge proofs as the solution to the privacy objection — a way to verify that a user is over a certain age without collecting their identity documents or linking their offline identity to their online activity.
The EFF has been tracking this argument, and on August 18th published an analysis concluding that ZKPs are neither the privacy protection their proponents claim nor a reliable mechanism for age verification. According to reporting by EFF staff technologist Daly Barnett, they're gameable, hackable, and introduce new centralization risks that are arguably more dangerous than the systems they're meant to replace.
The proof of concept came from the EU's own rollout. By the end of 2026, the 27 EU member states are expected to have age verification infrastructure in place through a "mini-wallet" app integrated with the European Digital Identity Wallet. The ZKP features, according to the EFF's analysis, aren't yet active in the version of the app available to everyday users — only in a closed demo build that most people can't access.
Despite this, a security researcher found they could bypass the system using a quickly built Chrome extension that tricked the app into repeatedly accepting the same "over-18" token without ever requesting fresh verification. An age verification system that accepts the same credential indefinitely, without re-checking, is not verifying ages. It's verifying that the credential was issued once.
We referenced this case in our coverage of Brazil's Supreme Court challenge to ECA Digital — the question of whether zero-knowledge proofs could satisfy the law's "reliable" verification standard was presented as an open and potentially positive development. The EFF's analysis suggests the answer, in current implementations at least, is no.
Why ZKPs Create a New Problem Instead of Solving One
ZKPs are mathematically sophisticated: they allow one computer to prove something is true to another computer without revealing the underlying data. In age verification, the idea is that your device proves you're over 18 to a website without sharing your date of birth, government ID, or any other personal data. That sounds appealing.
The EFF's concern is with what the system requires to work in practice. Every ZKP-based age verification scheme needs an issuer — an entity that verifies your age once and issues you a credential (a "token") that you then use across the internet. That issuer knows who you are. And because every use of the credential links back to that original verification, the issuer can track every website and service you access using it.
More critically: that issuer can revoke your credential. An authoritarian government, a court order, or a security breach at the issuer could leave you unable to access any platform that requires verification — which, as age verification expands, could mean most of the internet. The EFF describes this as creating a single point of failure for internet access: one entity whose decisions about your credential determine your ability to participate in digital life.
Over 400 security researchers signed an open letter making a similar argument: age assurance checkpoints, even when implemented with privacy in mind, create centralized identity infrastructure that is "extremely vulnerable to both cyberattack and authoritarian overreach."
The EFF adds that the EU's mini-wallet — once fully integrated with the EUDI Wallet — will concentrate passport data, driver's licenses, travel information, and financial information in a system that has already demonstrated it can be bypassed with a Chrome extension.
What This Means for the Broader Age Verification Debate
The ZKP argument has been doing significant work in legislative discussions. When critics of age verification raise privacy concerns, proponents increasingly respond that ZKPs solve the problem — that it's now possible to verify age without collecting data. The EFF's analysis, and the EU's own implementation failures, show that this response was premature.
We've covered age verification laws across this series from multiple angles: Iowa's law blocking Pornhub users, France's law struck down as unconstitutional, the KIDS Act and SCREEN Act advancing in the US Senate, Brazil's biometric age verification challenged at its Supreme Court, Australia's ban built partly on a report with AI-hallucinated citations. In each case, the argument for the law rests partly on the claim that the technical infrastructure to implement it responsibly either exists or is coming.
The EFF's analysis adds a specific and important data point: the most privacy-protective version of that infrastructure, the one proponents have been pointing to as the solution, has already been demonstrated to be bypassable with a browser extension and creates centralization risks that didn't exist under the systems it was supposed to improve.
No method of online age verification is simultaneously privacy-protective, fully accurate, and free from security risks. Lawmakers who have accepted ZKPs as the answer to that problem are working from a premise that isn't supported by current implementation evidence. The age verification paradox doesn't disappear because the cryptography gets more sophisticated. It just moves to a different layer of the stack.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
