Telegram Founder Pavel Durov Warns EU Age Verification App is a Surveillance Tool, Claiming It Was Hacked in Minutes

### Digital Sovereignty in Question: Scrutiny Mounts Over EU’s Mandatory Age Verification Tech

The European Union’s ambitious move to implement mandatory age verification technology has sparked a wave of criticism, positioning the initiative at the intersection of digital safety and civil liberties. While European Commission President Ursula von der Leyen championed the app, promoting it as a state-of-the-art solution that adheres to the ‘highest privacy standards,’ critics, most prominently Telegram founder Pavel Durov, have painted a starkly different picture. According to Durov, the application is not a private solution, but a sophisticated form of digital surveillance, undermining the very principles of data protection it purports to champion.

**A Technical Flaw and A Concern for Privacy**
Durov’s warnings are backed by technical skepticism. He publicly alleged that security researchers were able to compromise the app’s defenses in less than two minutes—a timeline that dramatically challenges the notion of robust, high-level protection. This supposed vulnerability is rooted in the app’s core design philosophy. Security analysts, such as the cited Paul Moore, identified that the technology relies too heavily on trusting the operating device itself. In essence, by granting the application broad permissions to the device, it creates a critical security vulnerability—a ‘basic design error’—that makes it susceptible to manipulation, potentially leading to what is termed an ‘enormous breach.’ This technical critique suggests that the purported safeguard mechanism is, in reality, a gaping hole waiting to be exploited.

**Bigger Picture: Global Trends and Surveillance Fears**

This controversy reflects a larger trend sweeping across the globe. The EU’s initiative is paralleled by regulatory actions in countries such as Australia, which banned social media access for individuals under 16, along with joint testing efforts in Denmark, France, Spain, and Italy. Germany has also put forth proposals mandating similar restrictions. From a policy perspective, while the stated goal is undeniably the protection of minors from harmful online content, the methods employed are generating significant alarm bells. Critics emphasize that these laws lead to the creation of centralized data ‘honeypots.’ Such data concentration drastically increases the systemic risk of both governmental overreach and malicious cyberattacks, a concern echoed by opponents in the UK regarding its own proposed digital ID scheme, which warned of sliding toward a ‘police state’ mentality.

**The Digital Rights Debate Continues**
Pavel Durov, a figure known for his strong advocacy in the sphere of free speech, has maintained a continuous critique against governments perceived as chipping away at digital freedoms. His warnings are deeply rooted in a fear of technological overreach. He argues that the sequence of events—proposing a seemingly harmless, ‘privacy-respecting’ app, allowing it to become ‘hacked,’ and subsequently removing privacy features under the pretext of ‘fixing’ the flaws—is a calculated maneuver. Durov suggests that the true motive of the European bureaucracy is to establish a system where age verification morphs into a pervasive, monitoring apparatus for all European citizens, ushering in an era characterized by digital restrictions and the erosion of personal autonomy. This debate underscores a fundamental conflict: how to legislate for online safety without sacrificing core democratic principles and individual digital rights.