The EU's open-source age verification project has sparked controversy after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement. The system uses keys stored in protected hardware (Android TEE, StrongBox, Apple Secure Enclave) to prevent credential cloning, but critics argue this creates dependency on a narrow set of approved devices and operating systems. Linux is not explicitly excluded — desktop users could scan a QR code via a supported mobile wallet — but no native Linux wallet exists. A further governance constraint limits real-world credential issuance to apps on an EC-approved list, meaning open-source community builds may not qualify even if the code is public. The project has promised a security review and threat model, but the core tension between open-source principles and hardware-gated trust remains unresolved.