GrapheneOS says Revolut is blocking users again – and this time it’s personal
It claims the bank is singling it out

- Revolut is again blocking GrapheneOS users, with the project alleging the bank has deployed targeted detection methods beyond standard Play Integrity checks.
- GrapheneOS says it exceeds Revolut's own security standards, calling the ban compliance theater over genuine risk
- The crackdown reflects a broader trend, with Volkswagen, McDonald's, and government apps similarly locking out privacy-focused devices.
- Affected users are being pushed toward banks offering web portals and hardware tokens – highlighting the growing cost of opting out of Google's ecosystem.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
GrapheneOS just reignited its feud with Revolut, accusing the digital bank of once again locking out its privacy-focused users over Google's Play Integrity API.
In a series of furious social media posts, the GrapheneOS project claimed that Revolut is actively banning devices running the hardened Android distribution, citing false security concerns.
The project accuses the digital bank of enforcing Google’s device certification rather than evaluating the platform's actual security.
“GrapheneOS doesn’t fail to meet any security standard they defined – it greatly exceeds the privacy and security of anything they allow,” it posted on Wednesday in a string of messages on X.
Privacy vs usability
The latest dispute centers on the Google Play Integrity API, which many Android developers use to verify devices before allowing apps to run.
While GrapheneOS passes the API’s Basic Integrity checks, it intentionally fails stronger “device integrity” or certification checks because it is not a Google-certified factory operating system.
The project claims that developers ultimately decide how strictly to enforce those checks and added that it shared its attestation compatibility guide with Revolut for several years before the reported ban.
Deliberate targeting?
According to GrapheneOS, Revolut first attempted to block the operating system in January 2025 before the community discovered a workaround.
The project now says the bank has introduced additional GrapheneOS-specific detection methods, and users are once again reporting login failures.
“Revolut specifically tries to detect and ban GrapheneOS."GrapheneOS project
“Revolut specifically tries to detect and ban GrapheneOS,” the project wrote, adding that previous workarounds required changes after the bank began checking build characteristics unique to the operating system.
The project said it was developing another technical fix, but for now, a temporary measure, it claims, works for most users: log in to a throwaway Google account and then install Revolut through the sandboxed Google Play Store.
Revolut has not yet issued an official statement on this issue.
Not just Revolut
The digital bank is not alone in its implementation of similarly restrictive Play Integrity policies.
Earlier this year, GrapheneOS users reported being locked out of Volkswagen’s companion app, preventing remote vehicle functions, while McDonald’s apps in several countries outside the US have also been reported to reject GrapheneOS devices.
Other affected apps include those that protect sensitive information, such as government services, authentication platforms, and digital identity applications.
Banking options for deGooglers
Revolut’s move to block GrapheneOS leaves those looking to de-Google their lives in a quandary.
“Which bank should GrapheneOS users use? I am worried about losing access to the app if they block my device,” one user posted on X.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The advice given appears all very Y2K: use a bank that still has a phone number and website.
As one Japanese poster replied: “I have chosen the solution of 'not using services that are only available through smartphone apps in the first place’ in order to deGoogle. For example, for banking, I select institutions that provide web access and hardware tokens, without forcing authentication via smartphone.”
What is GrapheneOS?
GrapheneOS is a security-and privacy-hardened version of Android available primarily for Google Pixel devices.
Favored by journalists, researchers, developers, and privacy-conscious users, it removes Google dependencies where possible, while adding exploit mitigations, stronger sandboxing, and advanced security features.
Last month, the project made headlines after its “duress PIN” feature was reportedly used to trigger a factory reset during the seizure of a phone by US law enforcement, raising concerns about encrypted devices and digital evidence.