GrapheneOS has spelled out exactly why its Motorola support is a 2027 story and not a 2026 one, and the answer is hardware. In a technical overview published on its own forum on 26 July, the privacy-focused Android build says it will only run on phones whose chips implement the newest generation of secure element rate limiting — the tamper-resistant hardware that caps how many times someone can guess your PIN. No Motorola phone on sale today qualifies, and the project is explicit that Pixels are still the only devices that do.

The line that matters is short and unambiguous. “Currently, only Pixels provide the hardware security features and updates required by GrapheneOS. That’s going to change in 2027 thanks to our partnership with Motorola Mobility and progress being made by Qualcomm,” the project wrote in the opening post of its overview of protections against data extraction from locked devices.
Why GrapheneOS needs specific hardware, not just an unlockable bootloader
The Motorola partnership was announced at MWC 2026 and ends GrapheneOS’s long-standing exclusivity to Google’s Pixel line. What was never clearly explained at the time was why the first device is a 2027 product rather than something Motorola already ships. This post answers that.
Disk encryption on a modern Android phone is not realistically breakable head-on. So the attack that actually works against a locked, powered-off phone is brute force: feed it PIN after PIN until one lands. The defence is a secure element — a separate chip that counts failed attempts and refuses to cooperate past a threshold, independently of anything software can be talked into doing.
GrapheneOS cites the rate limiting scheme called for by Android 16 QPR2, and the numbers are worth knowing because they now describe the floor for any phone the project will support:
- 20 attempts total — that is the hard ceiling on PIN or password guesses.
- 4 hours — the delay imposed after 10 failed attempts.
- 41 days — the delay after 15 failed attempts, which is a lockout in everything but name.
- Repeats don’t count — the five most recent unique failed attempts are rejected early, so entering the same wrong PIN twice doesn’t burn two of your twenty.
“GrapheneOS only supports devices implementing the latest generation secure element rate limiting,” the project states. That single sentence is the whole eligibility rule, and it is a hardware rule — it cannot be patched onto an existing handset.
There is a second requirement stacked on top, and it is the more interesting one politically. The secure element on supported devices has what the project calls insider attack resistance: the Owner user has to successfully authenticate before the secure element’s firmware can be updated at all. A correctly signed update with a higher version number is not sufficient on its own. GrapheneOS is blunt about the purpose — it exists to stop a government coercing the manufacturer into shipping a signed firmware update that quietly removes the attempt limit.
What this means if you own a Motorola phone now
It means you are almost certainly not getting GrapheneOS. The requirement is tied to silicon, so no amount of goodwill from Motorola’s software team retrofits it onto a Edge or a Razr already in your pocket. The realistic reading of the project’s own wording is that the first supported Motorola devices will be new hardware built around a Qualcomm platform that meets the bar, arriving in 2027. GrapheneOS has not named a model, a chipset or a date beyond the year, and neither has Motorola.
That is worth being clear-eyed about rather than disappointed by. A privacy OS that ran on hardware without a modern secure element would be selling a promise the chip underneath cannot keep. The stricter line is the honest one. But it does mean “Motorola will support GrapheneOS” is a statement about phones that do not exist yet, not an upgrade path for anything currently on shelves.
How this compares to what OEMs are doing on their own
The twenty-attempt ceiling is a useful benchmark right now, because Android OEMs are tightening lock screen limits independently and not always as gracefully. Samsung’s One UI 9 policy permanently locks a device after 13 consecutive wrong entries, recoverable only by a factory reset. GrapheneOS is describing a different philosophy for a similar threat: escalating delays that make brute force pointless without a cliff edge that a legitimate owner can walk off.
The rest of the overview covers features already shipping on Pixels — a locked-device auto-reboot timer set to 18 hours by default, passwords raised from a 16-character limit to 128 to allow diceware passphrases, an optional second-factor fingerprint PIN, USB data blocked at both software and hardware level while locked, and the duress PIN that wipes the device. That duress feature is the same one now at the centre of a US prosecution, and the project’s own framing of it here is notably modest: it calls the feature a minor part of the bigger picture and says GrapheneOS does not depend on it to protect user data.
Sources: GrapheneOS forum, Android Open Source Project






