Product1 distinct publisher3 min readPublished
The toolkit proves a fact such as being over 18 without the document leaving the handset, which is the opposite of the vendor model behind 153 million stolen licence scans, and so far no regulator has confirmed that it accepts this method as valid proof.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A person scanning both sides of a driver's licence at a rental counter was not, in their own mind, feeding a data archive. According to security researcher Brian Krebs, the Nexus service is now selling records that include front and back scans and infrared and ultraviolet images, along with timestamps tied to ordinary moments such as renting a car or visiting a dispensary, all collected because a business asked to see an ID [11]. Four image types per record across more than 153 million records is upwards of 600 million images that existed only because someone needed to confirm a single fact [12].
The mechanism ProveKit offers instead is narrow and worth understanding before anyone commits to it. World ID Credentials read data from an NFC-enabled identity document and keep it on the handset; ProveKit then proves specific attributes from that credential without exposing the rest of the document [5]. Because the proof is generated on the phone or in the browser, the underlying information does not travel to a server for processing [2]. World says that data stays inaccessible to World Foundation, Tools for Humanity and other third parties [6]. Privacy-preserving identity schemes are not new, but proof generation has carried computational and infrastructure requirements that made ordinary consumer hardware a poor host [13].
The reporting leaves one question unresolved, and it is the one a compliance lead will ask on the first call. The source does not identify any regulator, settlement or standards body that currently accepts a ProveKit proof as evidence that an age check happened [15]. That matters because retained scans are how teams currently demonstrate they checked. Swapping a file an auditor can open for a cryptographic assertion they cannot is a real trade, and it is the trade being proposed.
The diligence items are unusually legible for a launch like this. The codebase ships as production-ready open source with support for Noir, the Rust-inspired language Aztec built for zero-knowledge applications, so teams can define their own provable claims [7]. It targets 128-bit post-quantum security, requires no trusted setup, uses the WHIR hash-based commitment scheme, and has been independently audited by Least Authority [8]. World puts proof generation at seconds on a typical smartphone and under 30 seconds on a low-end device used in testing, with offline operation and limited memory supported [3]. The 30-second figure is the one to design against, since the slowest handset in your user base sets the wait, and the source does not say which device produced it.
The forcing function is a one-line inventory of what remains on your infrastructure after the check completes. If the answer is a copy of a document, you are operating an archive whose value to an attacker rises with every customer, and the timestamps make it a location history as well [11]. If the answer is a proof of one attribute, the breach you cannot suffer is the one where the images were never collected. ProveKit is already integrated into World ID across its identity network [4], and World frames the open-sourcing as extending that model to age-gated websites, financial services, online marketplaces and travel [14]. The path worth taking today is the attribute proof wherever the requirement is an attribute, and the document-scanning path only where a specific rule names the document itself.
Ranked by verification strength, evidence, and original report placement.
World has introduced ProveKit, an open-source zero-knowledge proving toolkit designed to let people prove facts about themselves, such as being over a certain age, holding a valid identity document, or meeting nationality or residency requirements, without revealing the underlying personal data.
ProveKit generates proofs locally on a smartphone or browser, meaning the underlying information does not need to be sent to an external server for processing.
ProveKit is already integrated into World ID, where it supports privacy-preserving verification across World's identity network.
World ID Credentials can store information obtained from NFC-enabled identity documents locally on a user's device, and ProveKit can then prove specific attributes from those credentials without exposing the rest of the document.
World is releasing ProveKit as a production-ready open-source codebase that supports Noir, the Rust-inspired programming language developed by Aztec for building zero-knowledge applications, allowing developers to create additional types of provable claims.
Security researcher Brian Krebs reported that a dark web service called Nexus is selling digital scans of more than 153 million drivers licences from people in the United States and Canada, apparently siphoned from a widely used identity verification vendor whose clients include several Fortune 500 companies.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
The counter scan that cleared a customer for entry is now for sale by name1 distinct publisher
product
Zero-knowledge age checks move the risk to enrolment, and that is where nobody is looking1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One issuer-aligned account
Take World's own statements out and little remains standing. The timings, the offline operation and the promise that credential data is beyond reach of World Foundation and Tools for Humanity are all company assertions, carried in a piece The Next Web marks as contributed rather than newsroom-produced. The audit that would test some of them is named but never shown. The one hard, checkable number in the whole story — 153 million licence scans — is Brian Krebs's, relayed secondhand.
One deployment, and World owns it
World ID is a real integration and worth crediting — but it is the vendor running its own toolkit. Not one external adopter, pilot or design partner appears, and the four sectors the story gestures at are named as opportunity, not as customers. Open-sourcing lowers the cost of trying ProveKit; nothing yet shows anyone outside World's network has.
Overstated against what is shown
The vocabulary runs ahead of the record: production-ready, post-quantum, seconds on a phone, works offline. What is demonstrated is a first-party integration and an unpublished audit. The gap widens because the breach does the persuading — 153 million stolen scans make the on-device model feel inevitable, yet that evidence belongs to someone else's reporting and says nothing about whether ProveKit works as described. And a verification method no regulator has blessed is not yet a substitute for the checks businesses are required to perform.
Product announcement wearing press clothes
The publisher's own note says the newsroom did not write this, and the text reads as World intended: its framing, its timings, its guarantee, its roadmap through to a version two. Every named third party — Aztec via Noir, Least Authority via the audit — functions as corroboration for the issuer. World gains directly if developers route identity checks through World ID's proving layer, and that interest is never disclosed in the piece as an interest.
Low, and structurally so
Confidence is capped by the shape of the sourcing rather than by any specific doubt: one publisher, contributed copy, no independent measurement, no second account to disagree with. What we can say firmly is narrow — the code is out, it runs inside World ID, and Krebs's breach numbers are on the record elsewhere. Everything about how well it works, and whether anyone must accept it, is waiting on evidence that has not arrived.