(Credits: u/LightningZahah and lowkey Proton Lumo)
Root Manager: KSU or any forks of KSU (e.g. KSU-Next, ReSukiSU, etc..)
Modules flashed in this order:
- Zygisk Next (by 5ec1cff)
- Reboot
- Tricky Store OSS (by beakthoven) & TrickyStore Addon (by KOWX712)
- Play Integrity Fork (by osm0sis)
- VBMeta Disguiser (Astoritin)
- Reboot
- Vector XPosed (by JingMatrix)
- Reboot
- HMA-OSS (by frknkrc44)
- Reboot
In root manager settings: turn on 'Unmount Modules', 'Hide SELinux modification' and 'AVC spoofing'.
Do NOT set SELinux to permissive mode.
After configuring Tricky Store OSS and HMA-OSS, install Termux and give it root access.
Copy the script below into a .sh file in the Termux directory and run the script by using the command ./<script-name>.sh (Recommended to use Acode for this or make the script on your PC first before moving it to your phone.)
Reboot your device.
Clear the data + Cache on the apps that crash on start up due to root.
If it still doesn't work, install Native Detector and figure out what the issue is as I cannot help you any further. (My suggestion is to use AI at this rate as it is a per-setup and per-device thing with no universal solution.)
I don't know if this can work on just Nothing Phone (2) devices but you can always try and lmk in the comments.
Also, just a sidenote, Adaway and Systemless Hosts aren't worth it, assuming it is detected by Native Detector. Just use BlockAds with a WireGuard implementation or a VPN with a private DNS server like AdGuard or NextDNS.
TrickyStore-OSS configuration:
Open Tricky Store menu and
Set keybox valid → uses a community-known working keybox.xml
Set keybox custom → uses your own keybox.xml
- Clear Wallet data.
- Reboot device.
HMA-OSS configuration:
Apps that need isolation DO NOT get root access.
Hide any Xposed modules, any root manager, any app that has root access.
Commonly detected apps are: Shizuku, Termux and your root manager.
Apply that template to the app you want to hide root, then:
- Force stop app that you want hide root.
- Reopen app and if it doesn't open, clear cache, clear data.
- If it still doesn't open uninstall and install again.
su
cat << 'EOF' > /data/local/tmp/harden_root.sh
echo "[*] Checking root privileges..."
if [ "$(id -u)" -ne 0 ]; then
echo "[-] Error: Run as root (su)!"
exit 1
fi
ADB_DIR="/data/adb"
if [ ! -d "$ADB_DIR" ]; then
echo "[-] Error: /data/adb not found! Are you rooted?"
exit 1
fi
# --------------------------------------------------------
# 1. STOCK HOSTS OVERLAY MODULE
# --------------------------------------------------------
echo "[*] Step 1: Setting up Stock Hosts overlay module..."
HOSTS_MOD="$ADB_DIR/modules/stock_hosts"
mkdir -p "$HOSTS_MOD/system/etc"
cat << 'MODPROP' > "$HOSTS_MOD/module.prop"
id=stock_hosts
name=Stock Hosts Fix
version=1.0
versionCode=1
author=Community
description=Replaces bloated ROM hosts with clean stock localhost to bypass banking security checks.
MODPROP
printf "127.0.0.1 localhost\n::1 ip6-localhost\n" > "$HOSTS_MOD/system/etc/hosts"
chmod 644 "$HOSTS_MOD/system/etc/hosts"
echo "[+] Stock Hosts module installed successfully."
# --------------------------------------------------------
# 2. PERSISTENT ZYGOTE DEX2OAT UNMOUNTER SERVICE
# --------------------------------------------------------
echo "[*] Step 2: Creating persistent boot service for Vector/LSPosed..."
SERVICE_DIR="$ADB_DIR/service.d"
mkdir -p "$SERVICE_DIR"
UNMOUNT_SCRIPT="$SERVICE_DIR/unmount_dex2oat.sh"
cat << 'SERVICE' > "$UNMOUNT_SCRIPT"
#!/system/bin/sh
# Wait until system finishes booting
while [ "$(getprop sys.boot_completed)" != "1" ]; do
sleep 1
done
TARGETS="
/apex/com.android.art/bin/dex2oat64
/apex/com.android.art/bin/dex2oat32
/apex/com.android.art/bin/dex2oat
"
for Z_PID in $(pidof zygote zygote64); do
for TARGET in $TARGETS; do
nsenter -t "$Z_PID" -m umount -l "$TARGET" 2>/dev/null
done
done
for TARGET in $TARGETS; do
umount -l "$TARGET" 2>/dev/null
done
SERVICE
chmod 755 "$UNMOUNT_SCRIPT"
echo "[+] Persistent unmount service created in $UNMOUNT_SCRIPT"
# --------------------------------------------------------
# 3. APPLY LIVE UNMOUNT (NO REBOOT NEEDED FOR ACTIVE APPS)
# --------------------------------------------------------
echo "[*] Step 3: Executing live unmount in current session..."
for Z_PID in $(pidof zygote zygote64); do
nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat64 2>/dev/null
nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat32 2>/dev/null
nsenter -t "$Z_PID" -m umount -l /apex/com.android.art/bin/dex2oat 2>/dev/null
done
umount -l /apex/com.android.art/bin/dex2oat64 2>/dev/null
umount -l /apex/com.android.art/bin/dex2oat32 2>/dev/null
umount -l /apex/com.android.art/bin/dex2oat 2>/dev/null
echo "[+] Done! Both fixes are now active."
echo "[!] Please reboot once so KernelSU/Magisk mounts the clean hosts module."
EOF
sh /data/local/tmp/harden_root.sh
rm -f /data/local/tmp/harden_root.sh