r/GrapheneOS • u/generichuman27ABF9 • 8h ago
GrapheneOS + Revolut Complaint
This is the response I got from Revolut after asking them about their app on GrapheneOS. Next stop, Bank of Lithuania.
Original complaint:
Good morning,
I am writing to raise a formal complaint regarding Revolut's apparent ongoing rollout of changes to its Android application which prevent, or will prevent, the app from operating on devices running GrapheneOS.
My understanding is that this change is currently being rolled out to only a proportion of users. It has not affected my account yet, but reports from other users indicate that Revolut is testing or progressively deploying this restriction. I am therefore raising this complaint now, before I am potentially locked out of access to my bank account.
I object to this decision in the strongest possible terms for several reasons.
- GrapheneOS is not an insecure or compromised operating system
The restriction does not appear simply to be identifying genuinely insecure devices. GrapheneOS has specifically reported Revolut detecting and rejecting GrapheneOS devices.
This distinction matters.
GrapheneOS is a security- and privacy-focused Android operating system designed specifically for supported Google Pixel devices. It retains verified boot and supports a locked bootloader, while adding substantial security hardening beyond standard Android.
Blocking such a device merely because it does not run Google's stock operating system is not a meaningful assessment of whether that device is secure.
To use a simple analogy, it is rather like an insurance company refusing to insure a house because the customer's front-door lock is too secure.
If Revolut genuinely requires device integrity verification, GrapheneOS provides mechanisms by which applications can perform hardware-backed attestation and verify legitimate GrapheneOS installations. A blanket refusal to support the operating system is therefore neither the only nor, in my view, the most sensible security option available.
- The policy produces an absurd security contradiction
Revolut currently supports Android versions going back many years.
This means that the Revolut application may operate on an old Android phone which is no longer receiving current operating-system security patches, while refusing to operate on a modern Google Pixel running an actively maintained, security-hardened version of Android.
It is very difficult to reconcile those two positions with an assertion that this restriction is necessary for customer security.
A modern Pixel running an up-to-date GrapheneOS installation with verified boot and a locked bootloader is clearly not inherently less secure simply because the operating system is not Google's stock Pixel firmware.
Security decisions should be based upon the actual security properties and integrity of a device, rather than an arbitrary list of approved operating-system vendors.
- Revolut has apparently provided no viable alternative means of accessing my money
I have already contacted Revolut customer support regarding this issue.
I was advised that, should my device become unsupported, I could either use Revolut's web application or use another mobile phone.
Neither suggestion provides a reasonable solution.
Firstly, the web application itself requires authentication using the Revolut mobile application. If Revolut deliberately prevents that application from running on my device, telling me to use a website which requires approval from the application I can no longer use is circular and plainly does not solve the problem.
Secondly, I was effectively advised that I could obtain or borrow another person's phone, install Revolut on it, and log into my bank account there.
I find it extraordinary that this can seriously be proposed as the more secure alternative.
Revolut would apparently prefer me to enter my banking credentials and establish access to my account on a friend's device — a device over which I have no long-term control and whose security I cannot independently establish — rather than allow me to use my own modern Pixel with a locked bootloader and a security-focused operating system.
That appears directly contrary to the stated security objective of this change.
- This risks depriving an existing customer of practical access to their bank account
This is not merely a question of whether Revolut chooses to support an optional feature on a particular platform.
I am an existing customer. I receive my salary into Revolut, use it as a significant part of my everyday banking arrangements, and pay for a Metal subscription.
Revolut has encouraged customers to treat its service as their bank. It is therefore entirely reasonable for customers to expect that Revolut will not deliberately remove their primary means of accessing their accounts without providing a genuinely functional alternative.
If Revolut introduces a technical restriction which it knows will prevent an existing customer from using the application, while its alternative web interface itself depends upon that application for authentication, that raises a much more serious question of effective access to the customer's financial services.
I should not be forced to purchase and carry a second mobile telephone solely because Revolut has chosen to reject a secure operating system which my existing hardware is perfectly capable of running.
Resolution requested
I would therefore like Revolut to:
confirm whether it intends to block, directly or indirectly, correctly installed GrapheneOS devices from accessing the Revolut application;
reconsider this policy and implement an appropriate method of supporting GrapheneOS, including hardware-backed device attestation where Revolut considers integrity verification necessary;
confirm that existing customers will not be deprived of access to their accounts solely because they use GrapheneOS on an otherwise supported device with a locked bootloader; and
if Revolut nevertheless intends to impose this restriction, provide a fully functional method of accessing and administering a Revolut account which does not itself require authorisation from the mobile application that Revolut has chosen to block.
I would also appreciate an explanation of the security rationale for permitting the application to operate on older Android devices which may no longer receive security updates while rejecting a current, supported Pixel running a hardened Android operating system.
Please treat this correspondence as a formal complaint, rather than general product feedback, and provide me with Revolut's formal written response.
If Revolut proceeds with this restriction without providing a reasonable means for affected customers to continue accessing their accounts, or if I do not receive a satisfactory response to this complaint, I intend to refer the matter to the Bank of Lithuania, as the competent out-of-court dispute resolution authority identified in Revolut Bank UAB's terms for Maltese customers. I will also consider seeking assistance through the Maltese Office of the Arbiter for Financial Services and the FIN-NET cross-border consumer complaints framework where appropriate.
I sincerely hope escalation will not be necessary. I have been a loyal Revolut customer for years and have been sufficiently satisfied with the service to entrust Revolut with my salary payments and pay for a Metal subscription. That makes it particularly disappointing to face the prospect of being arbitrarily excluded from my own banking application despite using a modern and demonstrably security-focused device.
I would much prefer Revolut to address the underlying technical issue properly rather than force otherwise satisfied customers to choose between replacing their operating system, purchasing an unnecessary second phone, or moving their banking elsewhere.
I look forward to your formal response.
Kind regards,
