In recent weeks, the World App, part of the broader Worldcoin ecosystem, has gone viral. The reason? Its offer of IDR 800,000 in crypto for anyone willing to undergo a biometric eye scan using a device called the Orb.
While the offer may appear harmless (just a few seconds of scanning in exchange for digital currency) it raises a critical question: are we underestimating the value of our biometric data?
Understanding World App, World ID, and Worldcoin
World App is the official digital wallet developed by Tools for Humanity (TFH), the same company behind Worldcoin. Co-founded by Sam Altman, CEO of OpenAI, TFH promotes World App as a solution to verify that users are real humans and not bots in the age of generative AI and deepfakes.
To create a World ID, users must undergo iris scanning via the Orb, a metallic sphere equipped with high-resolution cameras and sensors. Upon successful verification, users receive Worldcoin (WLD), a cryptocurrency that can be stored and managed within the World App.
According to the project’s official communications, this digital identity system is designed to be secure, private, and anonymized using cryptographic methods such as zero-knowledge proofs. The company claims that biometric data is not stored permanently and remains local to the Orb device, which will eventually be wiped.
However, the volume and sensitivity of the data collected (from eye scans to facial and body images, even to vital signs such as heartbeat) have sparked growing concerns across multiple countries.
Data Privacy Concerns and Global Backlash
Biometric data is permanent, unique, and cannot be changed, unlike passwords or PIN codes. A breach of such information could lead to identity theft, surveillance misuse, or long-term privacy violations.
Despite assurances from Worldcoin, according to Channel News Asia, several countries have taken regulatory action:
Kenya suspended the project and ordered the deletion of iris scan data collected from its citizens, citing legal and ethical concerns.
Spain and Portugal also halted Worldcoin’s operations, highlighting gaps in data protection especially involving minors.
Hong Kong issued a cease order after determining the collection of facial and iris data violated privacy laws.
In Indonesia, the Ministry of Communication and Digital (Kominfo) has responded by freezing World App’s operations as a preventive measure, citing concerns over unregistered local operators and potential legal violations. According to official statements, PT Terang Bulan Abadi (believed to be the local facilitator) was not registered under the country’s Electronic System Provider (PSE) database, raising further red flags regarding compliance and oversight .
The Risks of Biometric Trade-Offs
Cybersecurity and artificial intelligence experts warn that biometric data (especially iris and retina scans) represents one of the most sensitive forms of personal information.
As noted by Adila Alfa Krisnadhi, an AI expert from Universitas Indonesia, the long-term consequences of biometric leaks can be far-reaching:
“Unlike passwords, biometric identifiers cannot be changed. If compromised, they pose a lifetime security risk,” she stated in an interview with Investor.id.
Beyond the technical risks, there is also a wider ethical implication: who owns this data, and how will it be used in the future?
Worldcoin claims to use a secure system called Secure Multi-Party Computation (SMPC) that encrypts iris codes and splits them across various storage locations to prevent single-point access. However, these processes remain unclear to most users and lack independent verification or third-party audits.
Our Public Awareness Is At A Critical Weakness
What this controversy truly highlights is a broader issue: the low level of public awareness around digital privacy and data protection.
In the face of financial incentives many individuals are willing to trade away sensitive data without understanding the risks. This phenomenon underscores the urgent need for public education on data privacy, particularly in regions where regulatory frameworks are still maturing.
While innovation in digital identity and decentralized finance continues to accelerate, ethical implementation and informed consent must not be sidelined. Any system that collects, stores, or utilizes biometric data must uphold the highest standards of transparency, security, and user protection.
Conclusion
Worldcoin’s vision of a human-centric blockchain economy may hold merit in theory. But its implementation reveals glaring concerns about governance, consent, and control of one’s own identity.
As cybersecurity professionals, policymakers, and users, we must ask:
Who owns our data once it’s scanned?
How do we verify that deletion claims are followed?
What protections exist if misuse occurs years later?
In today’s digital economy, our data is our identity and our currency.We must treat it with the seriousness it deserves.
For more insights on online safety, cybersecurity tips, and scam awareness, follow Cisometric on social media and stay updated on the latest threats. Together, we can build a safer digital environment in Indonesia.
Inside Trump’s Cyber Blunder: How a Wrong Chat Turned Into a National Security Mess
The incident now referred to as SignalGate began with what appeared to be a routine coordination effort among top-ranking U.S. government officials. A Signal group chat, titled “Houthi PC small group,” was created by a staff member
Indonesia Ranks 2nd with the Most Spam Calls in Asia Pacific
The data in GoodStats’ report is based on insights from the Hiya Global Call Threat Report Q1 2025, which recorded a shocking 12.5 billion suspected spam calls globally in just the first quarter of the year, which is equivalent to 137 million unwanted calls per day.
16 Billion Passwords Just Leaked: Here’s What You Need to Know and Do
In June 2025, Bob Diachenko, a Cybernews contributor, cybersecurity researcher, and owner of SecurityDiscovery.com, confirmed the existence of 30 exposed datasets, each containing tens of millions to billions of login records. Combined, these datasets account for 16 billion credentials, making it potentially the largest aggregated leak ever observed.
Juice Jacking: How Public Chargers Can Steal Your Data
Our devices have become more than communication tools. They now hold access to our finances, personal records, work documents, photos, and even health information. This level of connectivity makes our lives easier, but it also makes our devices attractive targets.
Tariff Trade: Our Personal Information as a Trade Offer?
Because in this era of AI, algorithmic profiling, and platform-driven everything, personal data is no longer just metadata, it’s also behavioral insight, political targeting, digital identity, and economic leverage.
Welcome to cisometric.com! In order to provide a more relevant experience for you, we use cookies to enable some website functionality. Cookies help us see which articles most interest you; allow you to easily share articles on social media; permit us to deliver content, jobs and ads tailored to your interests and locations; and provide many other site benefits. For more information, please review our
Privacy Notice.