
GrapheneOS says Revolut has begun blocking customers who use its privacy-focused Android operating system, alleging that the fintech company is presenting the restriction as a security measure while actually enforcing Google Play licensing and device-certification requirements.
The GrapheneOS project raised the issue in an X thread published earlier today, after receiving reports that some users could no longer log in to Revolut. According to the project, customers who were already signed in generally remained able to use the app, suggesting that the checks may be applied during authentication or device verification.
GrapheneOS is an open-source, security-hardened Android operating system designed primarily for Google Pixel devices. It strengthens Android’s application sandbox, exploit protections, permission controls, and update model while allowing users to install Google Play services as sandboxed applications rather than privileged system components.
Revolut is a UK-headquartered financial technology company offering banking, payments, currency exchange, investment, and card services through its mobile application. Its reliance on device-integrity checks is not unusual for a financial platform, but GrapheneOS argues that Revolut’s implementation targets operating-system characteristics rather than measuring the device’s actual security posture.
The project claims that Revolut checks build-related values used by GrapheneOS for its deterministic builds and rejects devices that report a yellow Android Verified Boot state, which indicates a locked bootloader using a non-stock signing key. GrapheneOS noted that Revolut reportedly did not apply the same restriction to an orange boot state, normally associated with an unlocked bootloader.
GrapheneOS said it previously changed some detectable build values and worked around Revolut’s blocking in January 2025. However, it believes Revolut still intends to prohibit the operating system and has now introduced or reactivated checks affecting new login attempts.
As a temporary workaround, the project suggested signing into a disposable Google account so the device can pass Play Integrity’s basic integrity assessment, then installing Revolut through the sandboxed Google Play Store to satisfy the application’s installer check. GrapheneOS also said it plans to introduce a more secure compatibility solution for applications that verify their installation source.
The developers dispute any suggestion that GrapheneOS fails established security standards. They argue that Revolut permits devices running obsolete Android versions without current security patches while rejecting fully updated GrapheneOS installations.
GrapheneOS also said Revolut could use Android’s hardware attestation capabilities to verify supported hardware, boot state, operating system version, and patch level, without excluding alternative operating systems. The project said it had shared its attestation compatibility guide with Revolut for several years before the reported ban.
Revolut has not issued an official statement on the matter as of this writing.







Leave a Reply