kenkencw
**Device:** OnePlus 5T **Android Version:** 10 (OxygenOS) **TrickyStore Version:** v1.4.1 (245) **Description:** When trying to pass Play Integrity using a valid keybox, the hardware attestation fails and falls back to DEVICE_INTEGRITY. I checked the logcat and found that TrickyStore module is crashing with a `NullPointerException` during the attestation process. **Logcat Output:** 09-25 01:21:24.991 1415 2714 E TrickyStore: failed to get verified boot hash from original certificate 09-25 01:21:24.991 1415 2714 E TrickyStore: java.lang.NullPointerException 09-25 01:21:24.991 1415 2714 E TrickyStore: at Ca.n(Unknown Source:359) 09-25 01:21:24.991 1415 2714 E TrickyStore: at Ca.m(Unknown Source:117) 09-25 01:21:24.991 1415 2714 E TrickyStore: at fa.b(Unknown Source:147) 09-25 01:21:24.991 1415 2714 E TrickyStore: at D1.onTransact(Unknown Source:139) 09-25 01:21:24.991 1415 2714 E TrickyStore: at android.os.Binder.execTransactInternal(Binder.java:1032) 09-25 01:21:24.991 1415 2714 E TrickyStore: at android.os.Binder.execTransact(Binder.java:1005) **Cause analysis:** It appears that the original Keymaster implementation on the OnePlus 5T (Android 10) either does not provide the `verifiedBootHash` in the attestation extension or uses an unexpected format. This causes TrickyStore to throw an NPE when attempting to extract it to build the spoofed certificate. **Request:** Could you please add a null check for the verified boot hash extraction? If it's null or missing, perhaps it could fallback to a dummy/zeroed hash so that the module doesn't completely crash on older devices.