Attestation Is Not a One-Time Check: How Acurast Verifies Its Processors

Acurast runs on hundreds of thousands of everyday smartphones, called Processors, and the only way to guarantee that these are real untampered phones is to use the attestation checks from Google and Apple. Here’s how it protects the network and everyone who contributes to it.
Why attestation is at the heart of Acurast
Acurast runs on ordinary smartphones owned by people all over the world, so it needs a way to trust a phone without trusting whoever holds it. That is what attestation does.
Just as your phone proves itself to your banking app or to Apple Pay and Google Pay, a sealed security chip inside the phone signs a statement, backed by Google’s Key Attestation on Android and Apple’s App Attest on iPhone, confirming that the phone is genuine, the operating system is unmodified, and the phone isn’t rooted or jailbroken (unlocked to get around the manufacturer’s security).
Acurast checks that statement before a phone can run a single deployment (a piece of code a developer sends to the network to run). Because the proof comes from hardware not even the owner can open, a developer’s data stays private, results can be shown to come from exactly the code that was deployed, and nobody has to take anyone else’s word for it.
When attestations can’t be trusted anymore
Attestation isn’t a one-time stamp, because the keys behind it can fall into the wrong hands.
Occasionally a manufacturer’s signing keys leak, or a flaw in a chip or firmware lets someone extract a key from a real phone. With such a key, a bad actor can produce attestations from a server or an emulator (oftware that pretends to be a phone) that look exactly like they came from a genuine phone, and can even copy one phone’s identity across hundreds of virtual ones.
When Google or Apple learns of a leak, they revoke the affected keys. The catch is that a revoked attestation still looks perfectly valid on paper; it only fails if whoever checks it also consults the revocation lists. Fraudsters count on networks that don’t check revocations. They use leaked keys to pose as legitimate phones, even when all they are running is an emulator or, worse, a script that does nothing but emit heartbeats, the regular check-ins a phone sends to show it is online.
So Acurast keeps checking: the protocol is regularly audited by independent security firms, and the team continuously monitors activity on chain. Acurast recently strengthened how the network identifies forged attestations.
As part of this ongoing validation, phones with revoked attestations are continuously removed from the pool of Processors. They can no longer claim rewards and they won’t receive any deployments.
If your genuine phone has been affected
Revocations are a blunt instrument, and in rare cases they catch legitimate phones too.
Older phones received their attestation keys at the factory, and the same key is often shared by an entire batch or model. If that key leaks or the model is found to have a flaw, Google revokes it for everyone who has it, including honest owners who never did anything wrong. Google itself acknowledges that this can have a large impact on affected users, which is why Android is moving to short-lived, per-phone keys that are renewed automatically rather than revoked in bulk.
To be upfront: Acurast cannot override a revocation.
Accepting a revoked key for a genuine phone would mean accepting it for the forgeries too. If your real phone stopped receiving deployments, there is unfortunately little that can be done about a revoked key. Phones that use Google’s newer Remote Key Provisioning (each phone gets its own short-lived keys over the internet instead of at the factory) are not affected by leaks of factory keys, but whether a phone uses it depends on the manufacturer and model, not just the Android version.
So if the Acurast Hub (the web dashboard for managing phones) shows “Revoked” for the attestation of one of your legitimate phones, wipe it, make sure it is fully updated to the latest official version from the manufacturer, confirm it is not rooted and its bootloader (the startup software that loads Android) is locked, and then onboard it again.
This may succeed, or you may be unlucky and the phone is stuck with a revoked key. In that case, there is unfortunately nothing Acurast can do.



