Revolut Blocks GrapheneOS Users From Logging Into Its App

GrapheneOS accuses Revolut of enforcing Google Play licensing under a security label, blocking de-Googled phones.

If you’re tired of censorship and surveillance, subscribe to Reclaim The Net.

Banking app Revolut has started blocking people who run GrapheneOS, the hardened Android build, from logging into its app. GrapheneOS said on X that the ban came "without any justification" and that Revolut is "falsely claiming to be doing it for security reasons" when "in reality, they're enforcing licensing Google Play."

Revolut banned using GrapheneOS without justification, citing security reasons while running outdated Android 9.

The project posted the accusations yesterday. GrapheneOS said it "worked around Revolut's blocking of GrapheneOS in January 2025 and got it working for everyone," and the checks are now back. CyberInsider reported the same day that users already signed in were mostly still able to use the app, and said the checks may be applied during authentication or device verification.

An app asks Google's Play Integrity service whether the phone is running software Google has certified. A de-Googled phone answers no, and the app stops. Whether the operating system is secure, whether it gets patches, how fast those patches arrive, none of that is part of the exchange.

GrapheneOS fails that test because Google does not certify it, and security is the reason the project exists.

Revolut's help page is written in general terms. It says "App security is always improving to help protect against new and evolving threats" and that "a recent update might have added stricter checks to make the app experience safer and more reliable." To run the app, the page says, a device must be on "official, certified firmware (no custom ROMs)" and have a locked bootloader. It must also carry the latest OS and security updates, have no unlocked root access, and use the official app from a trusted store.

Revolut doesn't name a version number or patch date, so the app has no way to test the "latest OS and security updates" it asks for. There is no hardware requirement either. Certified firmware and a locked bootloader are the two conditions Google's signature answers on its own, and both are where GrapheneOS fails.

GrapheneOS put the same objection more sharply, turning it on Revolut's own app: "Revolut doesn't enforce security standards." The app, it said, "runs on Android 9 with no patches since 2018," which is the project's way of saying that Revolut's minimum supported Android release is one whose security updates ended years ago.

The app still supports a version that launched in 2018. GrapheneOS called Revolut "incredibly negligent when it comes to security" and said, "Revolut specifically tries to detect and ban GrapheneOS."

There was a route Revolut could have taken. GrapheneOS said Revolut could use Android's hardware attestation, which reports the actual hardware, boot state, OS version and patch level, and that it sent Revolut its compatibility guide years before this.

Revolut stayed with the Play Integrity check.

GrapheneOS said that logging into a "throwaway Google account so basic integrity passes" and installing Revolut "via the sandboxed Play Store so the installer check passes" "likely still works for most users." The project added that it will "be shipping a secure solution fixing apps with an installer check in the near future." GrapheneOS warns the workaround may not keep working in the long term. That is the project's account of what works. What Revolut does to an account it finds getting around the check is not known.

This is the latest hostile act against people who opt for privacy, security, or simply to avoid Big Tech giants. What this costs is an entire group of people. Someone who bought a Pixel and installed a hardened Android build now cannot open their bank app, while someone on an unpatched 2018 handset can, all supposedly in the name of security.