GrapheneOS, the privacy-focused Android alternative, has publicly accused fintech company Revolut of deliberately blocking its users — and the project says the real reason has nothing to do with security.

In a post on X on August 6, the GrapheneOS project laid out its case bluntly:
“Revolut recently banned using GrapheneOS without any justification. They’re falsely claiming to do be doing it for security reasons. In reality, they’re enforcing licensing Google Play. Revolut doesn’t enforce security standards. It runs on Android 9 with no patches since 2018.”
The typo is theirs — and the frustration is real. This is not a new conflict. GrapheneOS says Revolut first attempted to block its users in January 2025, at which point the project changed detectable build values to restore access. That workaround held for over a year. Now, GrapheneOS says the blocking has returned, with users reporting login failures once again.
What GrapheneOS Says Revolut Is Actually Checking
According to GrapheneOS, Revolut is rejecting devices that report a “yellow” Android Verified Boot state — meaning the bootloader is locked but the OS is signed with a non-stock key, which is exactly how GrapheneOS works on Pixel phones. The project points out that Revolut does not apply the same restriction to “orange” boot states, where the bootloader is unlocked entirely, which is arguably a weaker security posture.
GrapheneOS contends this is not a security check at all but a licensing enforcement mechanism — a way to verify that a device is running Google-certified software with Play Services installed through official channels. The project has repeatedly urged Revolut to use Android’s hardware attestation instead, which can verify a device’s hardware identity and patch level without excluding alternative operating systems.
The Security Hypocrisy Argument
The sharpest part of GrapheneOS’s complaint is the inconsistency. Revolut’s Android app reportedly still supports Android 9, released in 2018, which has not received security patches in years. A fully patched GrapheneOS installation on a current Pixel phone is, by any measurable standard, more secure than a stock Android 9 device — yet Revolut blocks the former and permits the latter.
That undercuts any claim that this is about protecting users from insecure devices. If Revolut genuinely cared about device security, it would enforce minimum Android version and patch-level requirements across the board, not target one specific privacy-oriented OS.
Revolut’s Response
When contacted by Android Authority, Revolut declined to comment on the specific allegations but said the app “fully supports both Android and iOS.” That non-answer does not address why GrapheneOS — which is Android, running on Google’s own Pixel hardware — is being singled out.
A Workaround Exists, but It Shouldn’t Have To
GrapheneOS recommends affected users sign into a spare or disposable Google account and install Revolut through its sandboxed Google Play Store. This reportedly bypasses the current checks. But the project warns this is not a reliable long-term solution if Revolut continues to update its detection methods.
This dispute is a clear example of a broader pattern in mobile banking: apps enforcing Google Play licensing under the banner of “security,” effectively penalizing users who choose more private, more hardened operating systems. For anyone who has deliberately moved to GrapheneOS to reduce their exposure to Google’s data collection, being told they also lose access to their bank is not a minor inconvenience — it is a direct cost imposed for choosing privacy.
Sources: GrapheneOS (@GrapheneOS), via CyberInsider and Android Authority






