Revolut "Security": Punishing Hardened Phones to Protect the Google Leash

You flash a Pixel to GrapheneOS because you want a phone that does not feed Google every radio ping by default. You keep it patched. You open Revolut to check your own balance, and the login screen stops you. Device security, it says.

GrapheneOS says that line is a cover story. Look at what Revolut still allows through the door, and the cover falls off.

The 2018 Pass

Revolut still supports Android 9. Google launched that release in 2018. Base security patches for that generation stopped years ago. Dig an old handset out of a drawer, boot software that has not seen a platform fix in a long time, and Revolut will still let you log in and move money. GrapheneOS put it bluntly: Revolut does not enforce security standards. The app runs on Android 9 with no patches since 2018.

GrapheneOS phones ship current Android source builds with exploit mitigations stock firmware never adds. The project says its builds greatly exceed the privacy and security of devices Revolut still welcomes. Yet a fresh login on GrapheneOS gets treated like a threat, while the unpatched 2018 path stays open. GrapheneOS called Revolut "incredibly negligent when it comes to security."

Hunting Signatures

According to GrapheneOS, Revolut is not applying one integrity bar to every phone. The project says Revolut specifically tries to detect and ban GrapheneOS. In their own write-up of the fight, they describe checks aimed at build values used for deterministic builds, and a ban on yellow verified boot (locked with a non-stock key) while orange unlocked boots were treated differently until they worked around that too.

Android already has a path a bank can use to verify hardware without demanding Google's commercial stack. Hardware attestation lets an app ask the chip whether the boot chain is locked and whether the OS image matches what the vendor signed. GrapheneOS supports that path. The project has pointed Revolut at its attestation compatibility guide for years and told the company to verify GrapheneOS that way instead of only permitting Google-licensed devices.

Revolut did not take that route. GrapheneOS says verifying them properly would show a locked, hardened install, which undercuts the security excuse. The fight already ran once. GrapheneOS worked around a Revolut block in January 2025 and got the app working again for everyone. The project now says login problems are returning. People already signed in often keep working. Fresh logins are where the wall shows up.

The Google Play Tollbooth

Here's the thing. GrapheneOS's read is that the ban is about enforcing Google Play licensing, not about protecting your money. An OS that runs modern hardware without Google's proprietary services proves you can bank, message, and live without the telemetry leash. When a fintech app leans on Play integrity and installer checks as the gate, your choice of OS becomes a compliance problem for them.

GrapheneOS goes further. It says Revolut ships closed-source third-party libraries with privacy, security, and compatibility problems, including libraries sold as security tools that create weaknesses. It also says Revolut support has been told to make inaccurate claims about GrapheneOS security and compatibility to excuse the ban. When Android Authority pressed Revolut, the company had no comment on the allegations. It said the app fully supports Android and iOS. When they say Android, they mean the commercial bundle that keeps Google in the loop, not every locked Pixel you can flash yourself.

Living on a Workaround

If you need the balance today, GrapheneOS's current advice is ugly on purpose. Sign into a spare Google account so basic integrity passes. Install Revolut through the sandboxed Play Store so the installer check passes. GrapheneOS can keep Google services in a sandbox without handing them the whole system, which is why the trick sometimes works.

The project is clear the workaround will not hold forever. Revolut can change the detection again. You end up babysitting throwaway accounts and package installs just to reach money that is already yours. That is what "security" looks like when the real requirement is Google's commercial leash.

Who Owns the Phone

Vendors sell you vigilance. Then they score vigilance by how much corporate surveillance you leave running. An outdated handset on ancient software does not threaten the advertising ecosystem, so the bank treats it as fine. A hardened phone that refuses the telemetry bundle breaks the commercial model, so the bank treats it as infected.

When hardening your hardware costs you the bank app, you learn who still holds the keys. You paid for the glass and the silicon. Revolut still gets to decide which OS you are allowed to boot if you want their app to answer, and Google's licensing sits under that decision whether they say the word security or not.

0 comments

Leave a comment