Revolut Blocks GrapheneOS Logins: Google Certification, Not Security

09.08.2026 6 min 11

Revolut has started blocking GrapheneOS users from signing into its banking app, and the hardened Android project says the reason has nothing to do with security. In a thread published on 6 August 2026, GrapheneOS accused the fintech of enforcing Google Play licensing and device certification while presenting the restriction as a safety measure. The Revolut GrapheneOS dispute is small in headcount and large in principle: it is a clean example of a private company deciding that a phone is only trustworthy if Google says so.

The Revolut GrapheneOS Block: What Changed

Users on GrapheneOS began reporting that new login attempts simply fail. The gate is Google Play Integrity, an API that tells an app whether the device is running Google-certified software. De-Googled and independently built Android systems fail that check by definition, no matter how current their patches are, because certification is a licensing status rather than a measurement of how secure the device is.

According to GrapheneOS, Revolut goes further and rejects devices that report a yellow Android Verified Boot state. Yellow means the bootloader is locked with a signing key that is not the manufacturer's, which is exactly what a verified custom operating system looks like. GrapheneOS says the same restriction was reportedly not applied to the orange state, which indicates an unlocked bootloader and is the objectively weaker configuration of the two.

The Android 9 Problem

The project's core argument is an inconsistency, not a preference. "Revolut recently banned using GrapheneOS without any justification," GrapheneOS wrote. "They're falsely claiming to be doing it for security reasons. In reality, they're enforcing licensing Google Play. Revolut doesn't enforce security standards. It runs on Android 9 with no patches since 2018."

To be precise about that last line: the complaint is about the floor Revolut sets for its customers, not about the app's own codebase. Revolut still lets its app run on handsets stuck on Android 9, a 2018 release that has been out of security support for years. Those devices pass the check because they shipped with Google's blessing, while a phone running a current, monthly-patched, hardened build is refused because it did not. If the goal were protecting customer accounts, the ranking would run the other way.

Play Integrity Versus Hardware Attestation

There is a technical alternative, and GrapheneOS says it has been documenting it for years. Android's hardware attestation reports what a device is actually running: the hardware model, the boot state, the operating system, and the security patch level, signed by a key burned into the phone at the factory. Play Integrity answers a different and much cruder question, namely whether the software is Google-approved.

A bank that genuinely wanted a security floor could set one with attestation: require a locked bootloader, a verified boot chain and a patch level no older than some cutoff, then admit any device that clears the bar. Choosing the certification signal instead means the policy tracks Google's commercial relationships rather than the state of the phone in the customer's hand.

This Is Not the First Round

Revolut first tried to shut out the OS in January 2025. GrapheneOS found that the app was checking whether the build machine hostname and username were set to "grapheneos" and changed those values to "build-host" and "build-user", which restored access for more than a year. The current block is harder to route around, because a Play Integrity verdict is produced by Google's infrastructure rather than by a string inside the ROM.

Revolut has not published a detailed response to the accusations. Asked about them, the company said only that its app fully supports Android and iOS, and it has not explained why a locked, verified, fully patched device fails a check that an abandoned 2018 build passes.

Why It Matters Beyond One App

Play Integrity has quietly become the admission ticket to ordinary life on a phone. Banking, payments, ticketing and a growing number of government and identity apps all query it, and every one of them inherits Google's definition of an acceptable device. The practical result is that choosing a more private operating system costs you access to services that have no privacy dimension at all, which is a strong disincentive dressed up as a technical requirement. The same dynamic is visible when a platform vendor turns the phone itself into an identity document, as Apple did with mandatory UK age verification tied to the Apple ID in iOS 26.4.

There is also a competition question sitting underneath this. If a European bank can make a Google licence a precondition for reaching your own money, the certification programme stops being a quality mark and starts working as a chokepoint, and regulators have shown interest in far smaller forms of platform leverage.

Important: Workarounds are fragile. Community reports suggest a throwaway Google account can sometimes get a session through, but that depends on how the check is rolled out and can stop working without notice. If your bank is the only route to your money, set up a fallback now - web access, a second device or a second institution - rather than after a login fails.

What Affected Users Can Do

  • Keep your existing session: the block reported so far targets new logins, so avoid signing out or wiping the device until the situation is clearer.
  • Use the web interface: browser access does not run Play Integrity checks and is the most reliable fallback for account operations.
  • Complain in writing: support tickets and formal complaints leave a paper trail, and in the EU and UK that trail is what a financial ombudsman or regulator will look at.
  • Do not unlock your bootloader to "fix" it: an orange boot state weakens your device and is not a supported route back in.

The wider lesson is about who gets to define a trustworthy device. People who move away from default platform software usually do it to reduce how much of their behaviour is collected, and they are the same audience that already treats network-level privacy tools as basic hygiene rather than a niche hobby - the reason interest in privacy tooling for Android keeps rising alongside every story like this one.

Conclusion

Conclusion: The Revolut GrapheneOS block is not a security decision, it is a certification decision. Until Revolut explains why a fully patched, verified-boot device is riskier than an unpatched Android 9 phone, the reasonable reading is that Google's licensing status, not the state of the handset, decides who gets access to their own bank account.

privacysecuritygoogleandroidukgrapheneosrevolutdigital rights

Read also