The short answer
Most Ukrainian banks’ apps work on GrapheneOS with sandboxed Google Play: Privat24, monobank, Oschad, Sense SuperApp, MyRaif and KredoBank have compatibility reports from 2022 to 2026. We tested monobank, Privat24 and MyRaif ourselves in 2026: they work. Reserv+ works even in a profile with no Google services. Diia works under two conditions: it is installed from the Play Store under a separate Google account, and exploit protection is relaxed for that one app. Binance works.
The NFC chip works, while tap-to-pay through Google Wallet and Google Pay is unavailable on GrapheneOS: Google permits it only on operating systems it has certified itself, and Ukrainian banks run NFC payment through Google Pay. With a GrapheneOS phone you pay with the physical card or with a watch that has its own NFC wallet.
Why banks have questions about GrapheneOS at all
Most financial apps check the device through Google’s Play Integrity API, which has three levels. GrapheneOS passes Google’s “basic” level. The “device” and “strong” levels require the operating system to be certified by Google, and no system other than Google-certified Android passes them. The GrapheneOS developers put it plainly on 10 May 2026: the Play Integrity API bans GrapheneOS although it is more secure than anything Google permits.
GrapheneOS does not try to bypass the check by faking responses, because such a bypass breaks with every Google update. Instead the project offers developers Android’s standard hardware attestation mechanism, which GrapheneOS supports in full and which gives a bank a stronger guarantee than Play Integrity. In practice: an app that requires only the basic level, or never calls Play Integrity, works; an app that requires Google certification refuses.
Sandboxed Google Play
GrapheneOS installs the optional Google services and the Play Store as ordinary apps without system privileges, with only the permissions we grant them. For most banking apps that is enough: they get notifications, SMS codes and the other functions they expect from Google services, and the system stays hardened. We recommend keeping Google Play, Diia and the banking apps in a separate, isolated user profile with a separate Google account created for that profile alone.
From the GrapheneOS guide: some banking apps carry their own anti-analysis mechanisms, and the “Native code debugging” toggle in the exploit protection settings can interfere with them. If an app crashes, that toggle may be the quick solution.
Banks: what has been verified
| App | Status | Source |
|---|---|---|
| Privat24 (PrivatBank) | Fully working. Occasionally asks for the SMS permission for Google services; the codes arrive without it. | Tested by GemiGuard, April 2026 |
| monobank | Fully working. | Tested by GemiGuard, April 2026 |
| Oschad (Oschadbank) | Works. On first setup the first two logins after the PIN hung on loading; the third passed. | PrivSec, Pixel 8, 27 November 2024 |
| KredoBank | Works. | PrivSec, Pixel 9, 24 December 2025 |
| Sense SuperApp (Sense Bank) | Fully working. Does not start without Google services. | PrivSec, Pixel 7, 2 June 2026 |
| MyRaif (Raiffeisen Bank) | Fully working. | Tested by GemiGuard, April 2026 |
Diia
Diia 4.34.3 works on Pixel 8a, 9 and 10a, confirmed by several independent sources in July and August 2026, under two conditions.
First: it is installed from the Play Store, under a registered Google account, in the profile with sandboxed Google Play. Installed through the Aurora Store, Diia closes immediately after launch without any message, because the app checks where it was installed from.
Second: exploit protection is relaxed for Diia. The working recipe: in the app’s settings turn off every protection option except the hardened memory allocator, allow verified links, and grant the phone, nearby devices, network and notifications permissions. This applies to Diia alone; the rest of the system stays in its normal mode.
Diia.Signature, the qualified electronic signature, is unconfirmed as of September 2026: by users’ observations its passport number recognition relies on Google ML Kit modules distributed only through the official Play Store.
Reserv+
Reserv+ 2.3.2 works, confirmed on Pixel 9 and Pixel 8a in July 2026, and in the strictest configuration: a separate profile without Google services and without the Play Store, installed through Aurora, every exploit protection option on. No Play Integrity dependency was observed.
That agrees with what the Reserv+ developers announced in April 2026: the app received stronger protection and no longer works on devices with administrator (root) rights. GrapheneOS gives no root, and the bootloader is locked again with GrapheneOS keys after installation, so to Reserv+ it is an ordinary phone.
NFC and paying by phone
The NFC chip on a Pixel with GrapheneOS works: it is switched on in the connection settings, it reads tags and chipped documents, and apps with their own contactless wallet pay through it. In Europe Curve Pay works that way; in Australia the Commonwealth Bank app pays with its own function.
Tap-to-pay through Google Wallet is unavailable on GrapheneOS, and that is Google’s decision, not a GrapheneOS limitation. Google Wallet’s help page: the wallet does not run on phones that “are rooted, run a custom ROM, or have modified factory software”, “have an unlocked bootloader” or “are untested and haven’t been approved by Google”; Google advises reinstalling the original operating system in that case.
Ukrainian banks run tap-to-pay through Google Pay: PrivatBank links the card to Google Pay from the Privat24 app, monobank adds the card to Google Pay from its app or through Google Wallet. Neither bank currently offers its own NFC wallet inside the app, so on GrapheneOS tap-to-pay through these banks is unavailable. You pay with the card, or with a watch that has its own wallet: Google Wallet on a Wear OS watch paired with a GrapheneOS Pixel pays, and PrivatBank, for example, supports Garmin Pay and SwatchPay, which do not depend on the phone’s system.
Binance and other crypto exchanges
Binance works with sandboxed Google Play: repeated confirmations on the GrapheneOS forum from 2022 through 2025 and a PrivSec report from November 2024. The app asks for the Play Integrity API now and then and carries on working. By contrast, since September 2025 the Play Store on GrapheneOS refuses to install Coinbase as “not compatible”, although the directly installed APK runs.
Updates
What works today may stop working tomorrow, and the reverse: compatibility moves with app updates, not with the system. A Pixel with GrapheneOS remains a very secure device. Signal, Molly, Threema and SimpleX work.
Buy a Pixel with GrapheneOS: models
Sources
GrapheneOS documentation
- GrapheneOS, usage guide, sections “Sandboxed Google Play” and “Banking apps”. — grapheneos.org
- GrapheneOS, attestation compatibility guide for developers. — grapheneos.org
- GrapheneOS, statement on the Play Integrity API, 10 May 2026. — grapheneos.social
Compatibility reports
- PrivSec, banking app compatibility with GrapheneOS, the “Ukraine” section, and reports 124 (Privat24), 323 (monobank), 539 (Oschad), 839 (KredoBank), 999 (Sense SuperApp), 1000 (MyRaif), 536 (Binance). — privsec.dev
- GrapheneOS forum, “Does Diia app work for anyone?”, March to August 2026. — discuss.grapheneos.org
- GrapheneOS forum, “Ukrainian gov. apps (Diia, Rezerv+) and contactless payments”, July to August 2026. — discuss.grapheneos.org
- GrapheneOS forum, “NFC payments on graphene”, 2025 to 2026. — discuss.grapheneos.org
- GrapheneOS forum, “Google Wallet NFC payments on WearOS Watch with GrapheneOS on the phone”, May 2025. — discuss.grapheneos.org
- GrapheneOS forum, “Crypto exchange apps working on GrapheneOS”, 2022 to 2026. — discuss.grapheneos.org
Google, the banks and the state apps
- Google Wallet Help, “Fix problems with tap to pay transactions”. — support.google.com
- Reserv+, the chatbot’s notice on rooted devices, quoted on 24 April 2026. — 7eminar.ua
- PrivatBank, “PrivatBank with Google Pay”. — privatbank.ua