Phone:
(+65)8319-0742
When a user opens Revolut and logs in, the app does not simply verify a password against a stored hash. Instead, it collects a constellation of hardware and software identifiers that together create a digital fingerprint of the device. This fingerprint becomes part of the authentication decision, flagging new devices or suspicious changes before the user even reaches the account dashboard. The system is called device binding, and it forms the backbone of Revolut’s anti-fraud protection alongside SMS codes, biometric verification, and behavioral analysis.
The practical question is straightforward: what exactly does Revolut collect to recognize your device, and what happens to that data afterward? The answer requires understanding which identifiers matter most, how they persist across app updates and operating system changes, what regulatory framework governs their storage, and what risks emerge when a device is lost, stolen, or compromised. A user who understands these mechanisms can make better decisions about backup authentication methods, account recovery, and whether to log in on shared or borrowed devices.
How Revolut login device binding works
Device binding in Revolut login begins the moment you install the app and create an account or log in for the first time. The system collects a baseline snapshot of the device’s unique characteristics. This includes the device model, operating system version, unique hardware identifiers built into the phone (such as IMEI for cellular devices or the Android Device ID), app signature or certificate fingerprint, and other software-level markers such as the presence of rooted or jailbroken environments.
On subsequent logins, the app collects the same set of identifiers and compares them against the stored baseline. If the identifiers match, the device is recognized as trusted. If they diverge—perhaps because the user updated iOS, changed security settings, or logged in on a different phone—the app triggers a verification step, typically requesting an SMS code or prompting biometric re-authentication. This happens even if you have already entered the correct phone number and passcode.
The binding mechanism serves a clear purpose: it prevents unauthorized access even if someone obtains your phone number and passcode. An attacker who knows your credentials but is using a different device will hit the device binding check. However, the system is not infallible. Device identifiers can change legitimately (after a factory reset, OS update, or app reinstall), can sometimes be spoofed, and can be extracted if malware or physical access compromises the device. The security model therefore assumes that most attackers cannot easily replicate the exact fingerprint, but does not claim that the fingerprint is cryptographically unforgeable.
Importantly, device binding does not happen in isolation. Revolut’s anti-fraud protection also monitors login velocity (repeated attempts from different devices in short time windows), geographic inconsistencies (your account logged in from two locations that are physically impossible to travel between), and behavioral patterns such as unusual trading activity or large fund transfers. A recognized device with normal patterns will complete login more quickly. An unrecognized device or anomalous behavior may prompt additional verification, even if the device fingerprint eventually matches.
Which hardware identifiers Revolut collects and retains
The most persistent identifier on an Android device is the Android Device ID (also called ANDROID_ID), a 64-bit number generated during the first boot and stored in the device’s secure partition. Revolut can access this without special permissions, and it remains the same across app reinstalls unless the device is factory reset. Similarly, the International Mobile Equipment Identity (IMEI), which identifies the cellular modem and is unique to the physical phone hardware, can be read by the app if it has telephony permissions (which most banking apps request).
On iOS, the landscape is more restricted. Apple does not expose a hardware-level unique identifier comparable to ANDROID_ID or IMEI to third-party apps. Instead, Revolut relies on the Identifier for Vendors (IDFV), which is unique per app and per user but resets if the user deletes all apps from that vendor. This limitation means iOS device binding is less hardware-dependent and more software-dependent than Android binding. The app also collects the device model (iPhone 14, iPhone 15 Pro, etc.) and OS version, which are less unique but still contribute to the fingerprint.
Beyond hardware IDs, Revolut’s login system collects application-level identifiers. The app signature or certificate fingerprint is a cryptographic hash of the signing certificate used to build the app. This ensures that a modified or sideloaded version of the app, even if it contains legitimate credentials, will not match the official app’s fingerprint. The app also checks for signs of compromise, such as whether the device is rooted (Android) or jailbroken (iOS), which disables some OS-level security controls and increases the risk of credential theft or session hijacking.
Revolut also collects and analyzes software environment markers: the list of installed apps, enabled accessibility services, screen lock status, and whether a VPN or proxy is active. A user who installs Revolut fresh on a new device will show a different app inventory than the previous device. A sudden addition of suspicious apps or activation of unexpected accessibility services can be flagged. However, these markers are less stable than hardware IDs; a normal app update or the user installing a productivity tool can shift the fingerprint, potentially triggering a re-authentication step.
Why device fingerprinting alone is insufficient for security
Device fingerprinting is powerful because it creates a high barrier to account takeover for attackers who do not have the physical device. But it has inherent limitations that Revolut addresses by layering additional authentication factors. A compromised or stolen phone means the attacker has both the correct credentials and the correct device fingerprint, effectively bypassing the binding layer entirely. This is why Revolut login requires a PIN or passcode that is separate from the device unlock code, and why biometric verification (Face ID, fingerprint) is checked at the point of sensitive transactions even after the device has been authenticated.
Device fingerprints can also change legitimately in ways that inconvenience users without improving security. A major OS update, a factory reset to fix a problem, or even some security patches can alter identifiers enough to trigger a challenge. If the user no longer has access to the phone number associated with the account (because they switched carriers or lost the SIM), they cannot receive the SMS code needed to re-authenticate on the new device. This is a real recovery problem: biometric authentication is convenient but does not help if the device itself is inaccessible.
Additionally, device fingerprinting relies on the assumption that the identifiers cannot be easily duplicated or forged. On Android, rooting tools can sometimes allow modification of system properties including ANDROID_ID, though doing so is complex and leaves traces. On iOS, jailbreaking similarly enables deeper device manipulation. An attacker with physical access to an unlocked device, or malware with sufficient privileges, may be able to read or modify fingerprint components. The security provided by device binding is therefore real but conditional: it works well against remote attackers and moderate against determined or sophisticated local attackers.
Storage, encryption, and regulatory compliance of device fingerprints
Revolut stores device fingerprints in encrypted form, either in its backend database or in encrypted local storage on the device itself. The company holds European Banking Authority (EBA) authorization through Revolut Bank UAB in Lithuania, and operates as a UK Financial Conduct Authority (FCA)-regulated entity through Revolut Ltd in the UK. These regulators require that authentication data be protected with encryption both in transit and at rest, and that the data be retained only as long as necessary for the stated purpose.
In practice, this means device fingerprints are encrypted with strong ciphers (typically AES-256) during transmission to Revolut’s servers, stored encrypted in the backend, and accessible only to processes that authenticate with appropriate cryptographic keys. The local copy on your device, if one exists, is also encrypted using the operating system’s built-in encryption. However, encryption is only as strong as the key management: if Revolut’s key infrastructure is breached, or if a backup process inadvertently copies unencrypted data, the fingerprints could be exposed.
Regulatory frameworks also impose data minimization requirements. Revolut should not store device fingerprints longer than needed for the specific purpose of recognizing devices and preventing fraud. The company’s privacy policy states that such data is retained for the duration of the account plus a set retention period for fraud investigation and regulatory compliance, typically measured in years rather than indefinitely. However, users cannot directly audit how long Revolut actually retains their device fingerprints, only what the policy claims. Verification requires either a formal data access request under GDPR (in the EU) or equivalent privacy regulations elsewhere, or independent security audits that are not routinely public.
What happens when you change devices or reset your phone
When you log in to Revolut on a completely new device, the app has no record of that device in its database. The device fingerprint will be new, triggering an immediate challenge. Revolut will ask for verification through SMS code (sent to your registered phone number) or, if available, through a backup code or recovery mechanism. This is the system working as designed: it prevents someone from adding your credentials to a phishing app and accessing the account immediately.
If you reset your iPhone or perform a factory reset on your Android phone, the device fingerprints will change. On Android, the ANDROID_ID is regenerated. On iOS, the IDFV changes. When you reinstall Revolut and log in again, the app will see a different fingerprint and require re-verification. Some users find this inconvenient, especially if they have lost access to the original phone number or backup recovery codes. Revolut’s account recovery process is designed to address this, but it typically involves identity verification (providing ID documents, answering security questions) which can take time.
Device binding also has implications for backup and restore workflows. If you use cloud backup (iCloud for iOS, Google Drive for Android) to restore your device after a factory reset, the backup typically does not restore app-specific data such as Revolut’s locally stored encryption keys or session tokens. This is a security feature: it means that a stolen or compromised backup cannot be used to log into Revolut on a different device without going through the full authentication flow. However, it also means that legitimate users must re-authenticate after a restore, which some may not expect.
Users should be aware that restoring from a backup after a factory reset creates a new device fingerprint even though it may be the same physical phone. The difference is that the OS and app ecosystem are freshly installed. This is why Revolut’s anti-fraud system treats it as a new device and requires verification. If you anticipate doing a factory reset, documenting backup codes or removing the device from trusted device lists beforehand can simplify the re-authentication process afterward.
Risks of sharing devices or logging in on borrowed phones
Logging into your Revolut login on a shared device, such as a family member’s phone or a public computer, presents several risks that device binding alone cannot mitigate. Once you log in and the device is authenticated, anyone with physical access to the phone can access your account without needing to repeat the full authentication flow. Session tokens may persist, and the device may remain trusted for several hours or until explicitly logged out. Even with a device lock code, a determined person with access to the unlocked device could transfer funds, view transaction history, or access linked cards.
Revolut’s session timeout (typically 30 minutes of inactivity in sensitive contexts) helps, but it is not a complete solution. Some features, such as viewing recent transactions or checking balance, may not require re-authentication if the device is still recognized as trusted. The biometric verification that Revolut requires for sensitive actions (large transfers, card orders, trading) provides another layer, but only if you have enabled it and if the biometric data (your fingerprint or face) is not the same as the person with physical access.
Additionally, logging into Revolut on a borrowed or shared device leaves artifacts. The device fingerprint is added to Revolut’s database as a trusted device. If you later log out without explicitly removing the device from trusted device lists, the device remains known to Revolut’s system. If the device owner, or someone with access to it later, tries to log into your account using your phone number and passcode, they will not trigger a device binding challenge because the device is already recognized. This is an indirect but real account takeover vector.
The safer practice is to log out immediately after use on a shared device, and to explicitly remove the device from your trusted devices list in account settings if that option is available. Ideally, users should avoid logging into Revolut on devices they do not control. If circumstances require it, changing your passcode immediately afterward, reviewing login history for any unexpected activity, and enabling additional security measures such as security keys (if Revolut supports them) are prudent steps.
How Revolut login device binding interacts with multi-factor authentication
Device binding is sometimes confused with multi-factor authentication (MFA), but they serve different purposes. Device binding identifies the hardware and software of the device itself. MFA requires multiple separate pieces of evidence of identity: something you know (a passcode), something you have (a phone number to receive an SMS, or a hardware key), and something you are (biometric data). Revolut uses both, and they work in concert.
A typical Revolut login flow involves entering a phone number, receiving an SMS code (factor 1: something you have), entering a PIN or passcode (factor 2: something you know), and then the app checks device binding. If the device is unrecognized, additional verification is required. Some transactions also require biometric re-authentication (factor 3: something you are). This layering is deliberate: no single piece of information or device attribute is sufficient to access the account.
However, this defense-in-depth approach depends on each component working. If you lose the phone associated with your Revolut account, you cannot receive SMS codes unless you update your registered phone number. If you forget your passcode, recovery requires a different verification path (security questions, identity documents). If your device is physically compromised by malware, biometric data could potentially be spoofed or the device itself could be used without triggering MFA. The strongest security posture requires maintaining multiple independent recovery pathways and understanding which one is easiest to access if primary authentication fails.
Future evolution of device binding and privacy trade-offs
As fintech platforms compete on both security and user experience, device binding mechanisms are evolving. Some companies are exploring behavioral biometrics (detecting whether the user’s typing pattern, swipe pattern, or navigation behavior matches their history), location-based binding (flagging logins from unexpected geographic regions), and machine learning models that score login requests as legitimate or suspicious without explicitly blocking them. Revolut’s anti-fraud protection already incorporates behavioral signals, but the specific implementation is proprietary and not disclosed to users.
The privacy trade-off is real. Collecting more data about devices, behavior, and context allows for more accurate fraud detection and fewer false positives that inconvenience legitimate users. However, it also means Revolut retains more sensitive information about how, when, and where users access their accounts. The regulatory framework, particularly GDPR in Europe, requires that data collection be proportionate to the stated purpose and that users have rights to access, correct, and in some cases delete the data collected about them.
Users can request a data access report from Revolut, which will show what device fingerprints, behavioral data, and other authentication markers the company has stored. This is a useful exercise to understand the scope of what is collected. However, the report may not clearly explain how each piece of data is used, how long it is retained after account closure, or whether it is shared with third parties for fraud analysis. Independent transparency reports and security audits remain limited, leaving users to trust Revolut’s representations about how device binding data is handled.
Frequently asked questions
Why does my Revolut login require extra verification even though I entered the correct passcode?
Revolut login uses device binding to recognize your device. If the device fingerprint has changed (due to an OS update, factory reset, or app reinstall), or if you are logging in from a new device, the app will ask for additional verification such as an SMS code or biometric confirmation. This is a security feature designed to prevent unauthorized access even if someone has your phone number and passcode.
What happens to my device fingerprint if I factory reset my phone?
Factory resetting your phone changes hardware and software identifiers including the ANDROID_ID (on Android) or IDFV (on iOS). When you reinstall Revolut and log in, the app will treat it as a new device and request re-verification via SMS code or other backup authentication. If you have lost access to your registered phone number, you may need to use account recovery procedures involving identity verification, which can take longer.
Is it safe to log into Revolut on a borrowed or shared device?
Logging into Revolut on a device you do not control introduces risk. Once you authenticate, the device is added to Revolut’s trusted device list and may remain recognized for several hours. Anyone with physical access to the unlocked device could potentially access your account without needing to re-authenticate. Best practice is to avoid using shared devices; if you must, log out immediately and remove the device from trusted device lists if possible, then change your passcode.
How long does Revolut keep my device fingerprint data?
Revolut’s privacy policy states that authentication and device data are retained for the duration of your account plus a set retention period for regulatory compliance and fraud investigation, typically measured in years. Exact retention periods are not disclosed publicly. You can request a data access report under GDPR (in the EU) or equivalent privacy laws to see what device fingerprints and other authentication markers Revolut has stored about you.