WraithLink documentation

WraithLink is a hardened mobile operating system for Google Pixel devices. It is built from the GrapheneOS and AOSP source trees and keeps their strong security foundations - verified boot, a hardware secure element, exploit mitigations - while adding a layer aimed squarely at physical coercion and targeted seizure: a decoy-duress unlock, a hidden WraithVault profile, a panic wipe, encrypted DNS, Tor routing, and a no-log peer-to-peer messenger.

Independent project. WraithLink is not affiliated with or endorsed by GrapheneOS or Google. It stands on their open-source work and preserves the upstream attribution required by their licenses.

Where to begin

  • Install - flash WraithLink from your browser or with the fastboot command line.
  • Devices - which Pixels are supported, and why the hardware matters.
  • Duress & WraithVault - the credential model that opens a believable everyday phone while your secrets stay in a vault that can vanish on command.
  • Security model - what WraithLink defends against, and the limits we state plainly instead of overselling.

How WraithLink is different

Most "secure" phones stop at encryption and a good lock screen. That protects a phone that is lost or stolen while switched off. It does very little the moment someone is standing in front of you demanding the PIN. WraithLink is designed for that moment. Your normal PIN opens your real, lived-in phone. A second PIN opens the very same phone - but quietly destroys the hidden WraithVault on the way in, so what a coercer sees is a genuine device with nothing worth taking. A third, separate credential wipes everything.

The rest of the system is tuned to keep that story believable and the attack surface small: encrypted DNS so lookups aren't leaked, per-connection MAC randomization so you aren't tracked across Wi-Fi, 2G disabled to blunt fake-tower attacks, USB data locked while the screen is locked, and a first-boot wizard that walks you through all of it.

Honest expectations

WraithLink defeats theft, coercion, and casual inspection. It is not built to beat a forensic laboratory that images your storage before you ever touch the device - no software can undo a copy that was already made. For that threat, use the panic wipe. The security model page is deliberately candid about this.