CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulation

Parents: That "Age Verified" Label Just Got Beaten by a Chrome Extension

Parents: That "Age Verified" Label Just Got Beaten by a Chrome Extension

The app cost two million euros and two years of work. A security researcher bypassed it in under two minutes. Then — after three months of patches and fixes and expert review — he bypassed it again, the same way, using a browser add-on he built with AI assistance.

TL;DR

The EU spent €2 million building an app to verify people's ages online — it's been beaten twice by the same researcher using a simple browser extension, and experts say the core design can't be patched. Every "age verified" label on every platform deserves fresh skepticism.

If you're a parent, that should land like a cold cup of water to the face. Because the whole promise of age verification — the reason governments are mandating it, the reason platforms are rolling it out — is that it gives families a reliable gate. Kids stay out. Adults get in. Everyone sleeps easier.

Except the gate keeps falling off the hinges.

What Actually Happened

Back in January 2025, the European Commission announced a €2 million contract with a German-Swedish consortium to build an official age-verification app. The plan was serious: the app would eventually connect to the European Digital Identity Wallets — think a digital ID system being rolled out across all 27 EU member states, touching an estimated 450 million people by the end of 2026. Age verification wasn't just about protecting kids on one website. It was supposed to be a building block for identity infrastructure across an entire continent.

In April, the app went public. A security researcher named Paul Moore looked at it. Within minutes, he had a workaround. He built a Chrome extension (a small add-on for the Chrome browser, the kind you'd use to block ads or save coupons) that let him sidestep the age check entirely — no valid ID required, no biometric data (meaning your face, fingerprint, or other body-based proof of identity) submitted.

Cybernews reported that Moore described the app's fundamental architecture as broken at a level that cannot be fixed by patching. His argument was pointed: if someone doesn't want to submit real identity information in the first place, no amount of security updates stops them. The lock is on the outside of a screen door. This article is part of a series — start with That Try On Glasses Button Just Mapped Your Face 468 Ways.

The Commission said the April version was a demo. They pushed fixes. Three months passed. 2,411 recorded changes were made to the app's publicly viewable code on GitHub. Then Moore tested it again. Same result. Bypassed.

"This is about putting power back into the hands of parents." — EU Commission President Ursula von der Leyen, on the age-verification app's launch

That quote was meant to be reassuring. Right now it reads more like an uncomfortable irony.


The Number That Stings

€2,000,000
spent on an age-verification app beaten twice by the same researcher using a browser add-on
Source: Cybernews / European Commission

Two million euros is not a rounding error. That's a serious investment, with serious engineers, on a serious timeline. And yet the researcher who broke it — twice — reportedly built his bypass tool with AI assistance, the same kind of AI tools available to any curious teenager with a laptop and a free afternoon.

That gap — between what was spent and how easily it fell apart — is the thing worth sitting with.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Court-ready facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why "We Fixed It" Doesn't Actually Fix It

Here's the part that deserves more attention than it's getting. After the first bypass, the Commission said the issue was resolved. Security updates were applied. The story mostly moved on. Then the second bypass happened — same technique, same researcher — and the word from experts was blunt: this isn't a bug you can patch out. The core design of the system has a flaw that requires rebuilding from scratch, not updating.

That's a different kind of problem. A patch fixes a hole in the wall. What Moore is describing is a wall made of the wrong material.

Analysis from Heise Online, a respected German tech publication, pointed to specific weaknesses including how the app handles its rate limits (the technical guardrails that are supposed to slow down or stop repeated bypass attempts) and how its biometric checks — the face-scan step meant to confirm you're a real person of the right age — can be circumvented before they even trigger. Previously in this series: One Phone Call Away From Losing Everything You Own Online.

The deeper technical breakdown at CADChain frames it this way: when the entire identity infrastructure for a continent is being built on top of this kind of system, an architectural flaw isn't just a product problem. It's a foundation problem.

Why This Matters Beyond Europe

  • Age gates are spreading fast — Governments in the US, UK, Australia, and across the EU are all mandating age verification for social media, gaming, and streaming platforms right now. The pressure to deploy something — anything — is enormous.
  • 📊 Speed creates shortcuts — When regulators set hard deadlines, companies build fast. Fast builds have cracks. The EU's app had 2,411 code changes and still failed. Rushed systems at smaller companies will have fewer.
  • 🔮 Kids learn faster than bureaucracies — The bypass tool took minutes to build with AI assistance. The fix took three months and didn't hold. That timeline asymmetry is the real story here.

The False Comfort Problem

Here's what worries me most — and it has nothing to do with the technical architecture. It's about what parents do when they see "age verified" on a platform.

They exhale.

That exhale — that moment of "okay, the system is handling this" — is exactly what bad actors and curious kids are counting on. The verification label is doing real psychological work even when it's not doing real technical work. It shifts responsibility off parents and onto platforms. It turns active oversight into passive trust. And when the gate turns out to be theatrical, the most protected-feeling families are often the least protected ones.

Think about it from a teenager's perspective. Word spreads fast. A workaround that takes two minutes to execute gets shared in group chats before the Commission has scheduled its first remediation meeting. The kids who want to get around an age gate will find the gap long before the adults who built the gate know a gap exists.

The Proton Blog — yes, the privacy-focused tech company — published a detailed breakdown of why this specific bypass worked, and their conclusion was sobering: the system's zero-knowledge design (meaning it was built to avoid storing your personal data, which sounds good for privacy) created the exact conditions that made it easy to fool. The feature meant to protect your data became the feature that protected the bypasser.

Good intentions. Wrong outcome. No warning label on the packaging. Up next: Parents That Age Verified Label Just Got Beaten By A Chrome .

Key Takeaway

An "age verified" label on a platform tells you the platform ran an age check. It does not tell you whether that check actually worked — or whether your kid found the workaround in a group chat last week. The gate is a starting point, not a finish line.

So What Can You Actually Do?

Look — nobody's saying age verification is worthless. Even an imperfect gate slows some people down. The question is whether you're treating it as a supplement to your own involvement or a replacement for it. Because right now, the evidence strongly suggests it's the former, and a lot of families are accidentally treating it like the latter.

One genuinely useful thing: have the conversation about workarounds directly with your kid. Not accusatory, not panicked. Just honest. Something like: "Hey, I know these age gates exist. I also know smart people beat them all the time. So I'm not counting on the gate — I'm counting on us talking." That conversation does more than any verification system, and it doesn't have a browser-extension-shaped hole in it.

If you've ever stared at an online profile and wondered whether the person is who they claim to be — whether the age, the face, the identity all actually match — that instinct is exactly right. It's the instinct that good identity-checking technology exists to support, not to replace. The goal is informed skepticism, not comfortable assumption.

Systems like this should function as one layer of protection, not the whole wall. The families who stay safest are the ones who treat every gate as temporary — because, as it turns out, they usually are.


A €2 million system, built by a consortium of experts, reviewed by government regulators, updated 2,411 times — and a researcher with an AI-assisted Chrome extension walked through it like it wasn't there. Twice. If that's what "keeping kids safe online" looks like right now, then the most dangerous thing a parent can do is feel safe because a platform told them to.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search