If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf.
Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.
Malwares can possibly do that even on non rooted phones if a privilege escalation attack is possible. And just yesterday, there was an article here about exactly one of those.
Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.
So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.
Which they would be anyway since PayPal isn’t a bank and isn’t FDIC insured.
They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).
If you have a rooted phone, download malware, and hit the allow button to give the malware root access, then it can do whatever it wants.
If you have a nominally unrooted phone on an old Android version and download malware, it can exploit a kernel bug and give itself root access and do whatever it wants.
Protecting against the first case and not the second is at best security theater.
For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.
It's probably just a generic error message for failing that Google Play Protect thingamajigger that attests provenance of the vendor OS from boot. Will be interesting to see whether the Motorola phones have this endorsement when they ship. Most devices would probably fail because they are rooted rather than because they are GrapheneOS. I wouldn't put it past a scammer talking grandma into rooting their phone.
It isn't due to the Play Integrity API. That shows a notification on GrapheneOS with a toggle for blocking it to work around it for services not enforcing providing a result. If that was the issue, the original poster would have known from the notification. The issue ended up being PayPal shipping incorrect anti-tampering code incompatible with secure spawning. The original poster figured that out and got it working by disabling the per-app secure spawning toggle.
It will be possible to install the official GrapheneOS on the devices. Shipping devices with the official GrapheneOS is planned but may not be there at launch.
One thing that I'm actually excited about regarding AI is that the pointless policy checkboxes that have never been effective in adding any actual security are even less so effective now that everyone can wield their very own security researcher.