Security researcher James Arnott discovered critical vulnerabilities in Belgium's Connective eID software, used by over two million people across major banks and government agencies, which failed to verify which websites could communicate with the application. The flaws allowed malicious websites to silently read card details, trick users into revealing their PINs via spoofed prompts, forge legally binding electronic signatures, and even execute remote code on victims' machines without any special permissions. Nitro Software Belgium fully patched the vulnerabilities 146 days after the initial report and awarded a $200 bug bounty, with no CVEs assigned.