Explainer

Worldcoin: Pay the Poor for an Iris Scan, Build an ID Nobody Can Refuse

Look into a chrome sphere, hand over the pattern of your iris, and receive some cryptocurrency. The pitch is that the world needs a way to prove a human is human in an age of bots. The question worth asking is the usual one: who ends up owning the proof?

The first time someone explained Worldcoin to me, I assumed I had misheard. A company backed by Sam Altman was putting chrome spheres the size of a bowling ball in shopping malls, photographing people’s irises, and paying them in a cryptocurrency token for the privilege. In return you received a “World ID” — a credential that says, in effect, a real and unique human being stands behind this account. It sounded like the opening scene of a film nobody would greenlight because the symbolism was too heavy-handed. It is not a film. It is running in dozens of countries, it has verified something on the order of eighteen million people by the company’s own account, and it is the most interesting bad idea in technology right now.

I want to be careful here, because the easy version of this essay writes itself and is mostly wrong. The easy version says: creepy eyeball scanner, crypto grift, rich men buying the bodies of poor people. Some of that is closer to true than the company would like. But the problem Worldcoin is aiming at is real — genuinely, urgently real — and dismissing the project without engaging that fact means losing the argument that actually matters.

What the thing actually is

Strip away the branding and there are four pieces.

  • The Orb. A purpose-built imaging device that photographs your iris at high resolution. You look into it; it looks into you. There are now field agents operating Orbs in malls, pop-up kiosks and partner shops across a long list of countries, with a smaller handheld version reportedly on the way.
  • The iris code. The Orb converts the image into a numerical code — a mathematical signature derived from the texture of your iris, which is unusually distinctive. That code is checked against every other code in the system. If it is new, you are a new human.
  • World ID. The credential you get back. Its entire purpose is one narrow claim: one person, one account, and this person has not already registered. In principle you can prove that claim to a website using cryptography without revealing who you are — the site learns “unique human,” not your name.
  • The token. Early enrollees in many countries received an allocation of the project’s cryptocurrency, WLD. Reported amounts varied by country and by year; in some places it was described as roughly fifty dollars’ worth at the time. The token funds the network, rewards adoption, and — this matters enormously — supplies the incentive that got millions of people to look into the Orb in the first place.

The project was co-founded by Sam Altman and built by a company called Tools for Humanity, with a separate foundation stewarding the token and protocol. It rebranded from “Worldcoin” to simply “World” in late 2024, a change that tells you exactly how the company wants to be read: not a coin, an identity layer. In 2026 it announced integrations with mainstream consumer platforms — dating and video-conferencing services among them — which is the tell that this is no longer a crypto experiment. It is bidding to become plumbing.

The problem it is aiming at is not fake

Here is where I have to be fair, because I think most critics skip this part and it costs them.

Generative AI has made counterfeit humans nearly free. A convincing fake person — profile photo, posting history, voice, video, a plausible biography, the patience to argue with you for three weeks — now costs approximately nothing to manufacture at scale. Every system we built on the quiet assumption that behind each account sits a person is now structurally broken: reviews, polls, petitions, comment sections, dating apps, queue systems for scarce goods, and eventually elections. “Proof of personhood” is not a made-up need invented to sell a token. It is the load-bearing assumption of the consumer internet, and it has quietly failed.

I should also grant the company its central technical claim. World says the iris photograph itself is not retained on its servers — that the image is processed on the device, the code is derived, and the original is deleted, with the codes themselves later split across multiple parties so that no single holder possesses a usable record. If that is implemented as described and holds up under independent audit, it is meaningfully better than the alternative most governments and platforms have built, which is a giant central database of raw biometrics sitting behind whatever security the procurement budget allowed.

So: real problem, non-trivial engineering, a privacy architecture better than the default. Now the hard questions.

An iris is not a password

The objection I cannot get past is the simplest one, and no amount of cryptographic elegance dissolves it.

If a password leaks, you change it. If a card number leaks, the bank reissues it. If a phone number is compromised, you get a new SIM. Every security system we trust is built on the ability to revoke and reissue the thing that was compromised. Your iris cannot be reissued. It is the same iris at nineteen and at seventy. Whatever is derived from it today is derived from it forever.

This means the system is making a promise it has no standing to make. The promise is not “we are handling this safely,” which may well be true this year, under this management, with this architecture, in this regulatory climate. The promise is “this will be handled safely for the rest of your life, by every entity that ever acquires this company, through every future change of law, and against every attack technique that will exist in 2050.” No company can make that promise. Nobody can. The asset is permanent and the custodian is not.

Every security system we trust rests on the ability to revoke and reissue what was compromised. You cannot reissue your iris. The asset is permanent and the custodian is not.

And the derived-code defence only goes so far. Codes are derived by algorithms, algorithms get revised, revisions get applied to whatever data survives, and the definition of “anonymous” is precisely the point regulators keep disputing. Germany’s data protection authority found the arrangement non-compliant with European law and ordered deletion; the company appealed and has argued for judicial clarity on whether its privacy technology legally counts as anonymisation. That is not a settled technical fact. It is a live legal question with millions of irreversible enrolments already banked against a favourable answer.

Consent, when the person consenting needs the money

The second objection is the one that made me angry rather than merely uneasy.

Early enrolment did not spread evenly across humanity. Reporting from multiple countries described queues forming in lower-income neighbourhoods, students and informal workers and people in precarious jobs lining up for the token. Some of the sharpest coverage came from Kenya, Indonesia, Brazil and parts of South and Southeast Asia. Brazilian regulators specifically objected that paying for biometric data corrupts consent — their data law requires it to be free, informed and unambiguous, and a cash-equivalent payment to someone who needs cash is none of those things in any meaningful sense.

I want to state this precisely, because “exploitation” is a lazy word. Nobody was forced. The people who queued were making a rational decision with the options available to them: a permanent, irreversible disclosure in exchange for money they needed now. That is a real choice. It is also exactly the choice that consent law exists to scrutinise, because when the payment is large relative to your income, the biometric is permanent, and the risk is a diffuse harm decades away, “consent” stops describing anything we would recognise as free agreement.

This is the same asymmetry I keep running into when I look at data dignity: the value extracted flows one way, the permanence of the disclosure binds the other. A person in a Nairobi mall and a venture investor in San Francisco are both parties to this transaction, and only one of them is putting up something they can never get back.

It also rhymes uncomfortably with things I have written about closer to home. The debate over Aadhaar, UPI and privacy turns on a system that was genuinely transformative and genuinely coercive at the same time — voluntary in principle, unavoidable in practice, because once enough services demand the credential, refusing it stops being a choice. And the expansion of facial recognition in India followed the same script: deployed for a narrow, sympathetic purpose, then quietly widened once the cameras were already installed and the database already existed. The mechanism is never a dramatic seizure. It is scope creep on infrastructure people accepted for a different reason.

The regulators have not been subtle

The regulatory record is, by now, substantial. As reported across the last three years: Kenya suspended operations and later saw a court rule against them; Spain and Portugal ordered halts; Brazil banned the exchange of crypto for biometrics and reaffirmed it with the threat of daily fines; Indonesia, Thailand, Hong Kong, the Philippines and others have suspended, restricted or investigated the project; Germany’s Bavarian authority ordered deletion and the company paused its scanning stations there while appealing. Meanwhile the United States, where biometric and crypto rules are fragmented across states, has become a growth market.

That pattern is the most informative thing in this entire story. The project expands fastest where oversight is weakest, and stalls wherever a mature data protection regime takes a hard look. You do not need a conspiracy to read that. It is simply what happens when a business model and a legal principle are in direct conflict.

The argument I actually want to have

So here is where I land, and it is not where the easy version of this essay lands.

Proof of personhood is going to exist. The need is real and growing, and something will fill it. The question is not whether we build it. The question is who owns it, who is accountable for it, and what it is made of.

On ownership: a credential that gates access to ordinary life is a public utility, whatever legal form it arrives in. Utilities that everyone must use should be accountable to everyone who must use them — through law, through courts, through the boring machinery of democratic oversight. A privately held, token-funded network whose growth targets are set by its investors is not that, no matter how sincere its founders are. Sincerity is not a governance structure.

Proof of personhood will exist; something will fill that need. The real question is who owns it, who answers for it, and whether it has to be made out of our bodies.

On mechanism: biometrics are the wrong substrate for this job specifically because they are permanent. There are other approaches — cryptographic credentials issued by institutions you already deal with, attestations that expire and rotate, schemes that prove uniqueness within a bounded context rather than across all of humanity forever. They are messier and less elegant. Messy and revocable beats elegant and permanent when the thing at stake is your body.

And on the pattern underneath all of it: this is a clean example of how technology gets captured. Not by villainy, but by sequence. A genuine problem appears. A private actor moves first, because private actors move fastest. The solution scales to the point where refusing it means exclusion. And then the terms — who holds the data, who can be denied, what else the credential gets used for — are set by whoever already owns the infrastructure, negotiating with people who no longer have the option of walking away.

The Orb is a striking object, and I think that is partly the point. But the real design decision is not the sphere. It is that a system which may become mandatory to participate in modern life is being assembled by a company, funded by a token, and priced in the irises of people who needed fifty dollars more than they needed to think it through. We are allowed to want the problem solved and still refuse this particular solution. That is not obstruction. That is the whole job.

Kenney Jacob is the author of Captured, a history of who takes, who pays, and who fights back.

Frequently asked questions

What is Worldcoin?

A project co-founded by OpenAI's Sam Altman that scans people's irises with a device called the Orb to issue a unique digital identifier — 'World ID' — intended as proof that someone is a real, unique human rather than a bot. Early participants were typically offered cryptocurrency tokens in exchange for enrolling.

Why is Worldcoin controversial?

Because it collects an immutable biometric — you cannot reissue your iris the way you can a password — often from people in lower-income countries drawn by the token payment, raising questions about meaningful consent. Several national regulators have investigated, restricted or banned its biometric collection over data-protection concerns. Supporters say the biometric is deleted after a local code is derived; critics question the verifiability of that and the wisdom of one private entity holding the keys to proof-of-personhood.

Do we actually need proof of personhood?

The underlying problem is real: as AI makes convincing fake accounts and content cheap, distinguishing humans online becomes genuinely harder. The disagreement is not about the problem but about the answer — whether such infrastructure should be a private, token-funded venture or public, accountable and interoperable, and whether biometrics are the right mechanism at all.

← All articles