Belgian eID signing software critical flaws shake trust in digital identity
Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens.
The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises.
A fundamental weakness was that the software failed to properly verify which website was communicating with the local eID application. Consequently, malicious websites, potentially even through embedded content , could communicate with the Connective application without meaningful user authorization.
Attackers could potentially access information from connected Belgian eID and payment cards and manipulate authentication workflows. Particularly dangerous was the possibility of displaying convincing authentication dialogs that could trick citizens into revealing their eID PIN.
A stolen PIN combined with access to the physical eID card could potentially enable attackers to generate unauthorized approval tokens and abuse legally binding electronic signatures.
Researchers also demonstrated drive-by Remote Code Execution (RCE), allowing a malicious website to potentially execute attacker-controlled code on a victim’s computer.
The vulnerabilities therefore challenged not just one application but the broader trust model surrounding Belgian digital identity, banking and government authentication; the reported flaws were patched on 22 July 2026.
The incident is a powerful reminder for the coming eIDAS2/EUDI Wallet ecosystem: digital identity infrastructure needs strict origin binding, secure local components, independent security testing and security-by-design, because compromising the identity layer can compromise trust across an entire ecosystem.
Read Security article for more information.

