Worldcoin and the Inherent Insecurity of Biometric-based Identity Systems

v1: April 5, 2023

Author: Jesse Charlie

All versions of this article

Background Information (Skip to main Article if already know)

  1. (Background info: Public/Private Key Encryption)
    When we encrypt messages, we create a key pair: one public and one private. The private key is generated locally, and proving our identity relies on the public key being related to the private key, which is entirely in our control. We can prove our private key is in our control because we generated it on our device. Since our key pair algorithm is based on entropy of randomness, it is very difficult to randomly stumble upon our key through brute force.
  2. (Background info: Worldcoin's goal)
    Problem: The need for proof of personhood on the internet.
    What: Proof of Personhood is a cryptographically provable method of proving who you are (public/private key pairs), proving that you are who you say you are (preventing impersonation with false key pairs), and confirming your humanity (distinguishing between humans and robots with unique key pairs).
    Why: To differentiate between AI and humans on the internet, distribute Universal Basic Income (UBI) effectively, prevent bots in natural rate limiting (replacing CAPTCHA as AI becomes smarter), etc.
    Solution: Many methods can establish proof of personhood. However, Worldcoin argues that biometrics are necessary to create a complete proof of personhood system and prevent fraud.

Main Article

  1. Worldcoin's Architecture is based solely on Iris Biometrics:
  2. The Inherent Insecurity

This differs fundamentally from generating a cryptographic key pair locally on your device. Classical cryptography inserts random bits to the key length, creating a key pair. Biometrics inserts biometric data into the algorithm generating a key pair at best and relies on a trusted third party's hardware attestation at worst. This means that, at best, your identity can be stolen by someone scanning your eyeballs, and at worst, Worldcoin themselves can reset your identity.


Worldcoin fails to create a true proof of personhood protocol because it fails to:

  1. Prevent fraudulent iris hashes in the database, as we must trust a third party to add new hashes. (Neither blockchain nor reversible functions can solve this problem).
  2. Securely connect biometric information to identity, either relying on a trusted third party to attest your identity (like a government-issued ID) or using biometric data to generate a key pair (which can be stolen by scanning your eyes or copying the key pair before it leaves the orb).

In classical encryption, someone can impersonate you if they have your private key, which can be derived only by breaking the encryption algorithm, brute forcing your key, or intercepting the hardware that reads the key.

With Worldcoin, someone can impersonate you by scanning your iris (forcibly or surreptitiously) at best, and at worst, Worldcoin themselves can impersonate you. There's no way to connect biometrics to a key pair unless the key pair is generated using biometrics or if a trusted third party attests that your biometrics are tied to your key pair.

Moreover, Worldcoin can create unlimited fake iris hashes, rendering the one-to-one human-to-ID protocol ineffective.

This is concerning because:

  1. Powerful AI may be gatekept behind World ID, potentially requiring an insecure identity system to access resources that could exponentially benefit users. (Sam Altman is part of Worldcoin and OpenAI, which currently has the most powerful publicly available general AI.)
  2. Governments could use this system to access facilities and services (mostly outside the US and possibly the EU, since the US would likely create its own system if Worldcoin succeeds).
  3. Web services and banks could use World ID.

The primary purpose of Worldcoin (biometrics proving that one person has only one ID) fails, necessitating alternative methods without biometrics for creating Proof of Personhood.