Hmm, I wonder if the worldcoin team also thought of that possibility?
(Yes, they did, the iris processing is done inside a hardware enclave so that the obvious attack is not possible)
https://whitepaper.worldcoin.org/technical-implementation
I am broadly anti-Worldcoin but it is reasonably competently executed at a technical level. It would be good to understand what they actually did before declaring it to be impossible.