• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Dorsey Says Bitchat Software Lacks Security Review

Akinola Ajibola by Akinola Ajibola
July 10, 2025
in Security, Service news
Share on FacebookShare on Twitter

Bitchat is an open source chat app that was introduced on Sunday by Block CEO and Twitter co-founder Jack Dorsey. The app promises to provide “private” and “secure” conversation without the need for a centralized infrastructure.

Unlike other texting apps that rely on the internet, this one uses Bluetooth and end-to-end encryption. Bitchat’s decentralized design makes it potentially a safe software for high-risk settings where internet access is restricted or regulated. Bitchat’s system design “prioritizes” security, according to Dorsey’s white paper outlining the app’s protocols and privacy features.

However, security specialists are already questioning the app’s security claims because, according to Dorsey herself, neither the app nor its code have been examined or tested for security flaws.

However, considering that the app and its code have not been examined or tested for security flaws at all—by Dorsey’s own admission—security researchers are already questioning the app’s security promises. “This software has not received external security review and may contain vulnerabilities and does not necessarily meet its stated security goals,” Dorsey said on Bitchat’s GitHub website after the launch. Until it has been reviewed, do not use it for production purposes and do not depend on its security in any way.” Although it wasn’t present when the app first launched, this warning is now also visible on Bitchat’s official GitHub project page.

Although it wasn’t present when the app first launched, this warning is now also visible on Bitchat’s official GitHub project page.

As of Wednesday, Dorsey updated GitHub to include the phrase “Work in progress” next to the warning.  

This most recent disclaimer was issued in response to security researcher Alex Radocea’s discovery—which was detailed in a blog post—that it is feasible to pose as someone else and fool a person’s contacts into believing they are speaking with the real contact.

Bitchat’s “broken identity authentication/verification” system, according to Radocea, enables an attacker to intercept a user’s “identity key” and “peer id pair”—basically, a digital handshake meant to create a trustworthy connection between two app users. Bitchat designates these connections with a star icon and names them “Favorite.” Allowing two Bitchat users to communicate while being aware that they are speaking to the same individual is the aim of this feature. 

TechCrunch sent a request for comment to Dorsey’s Block email address, but he did not reply.

In order to report the security vulnerability he found in the Bitchat Favorites system, Radocea opened a ticket on the GitHub project on Monday. Dorsey quickly and without comment tagged it as “completed.” (Dorsey reopened the ticket on Wednesday, stating that publishing directly on GitHub is the best way to report security vulnerabilities.)

Dorsey’s assertions that Bitchat features “forward secrecy,” a cryptographic approach that guarantees that an attacker cannot decrypt previously delivered messages even if they steal or compromise an encryption key, raised worries from another individual.

Additionally, a potential buffer overflow fault was also disclosed. This kind of security flaw is frequent and allows a hacker to force a device’s memory to spill out to other regions, potentially compromising data.

Users of Bitchat should not yet put their trust in the service, Radocea said.

“Having security is a wonderful way to go viral. However, when creating something like this, it would be extremely clear to verify a basic sanity check, such as whether the identity keys actually do any cryptography, Radocea told TechCrunch. “The project in its current state may put people in danger because there are those who would take the security messaging literally and depend on it for their safety.”

Radocea questioned Dorsey’s warning that Bitchat has not been tested for security, stating his and other people’s results.

“I would contend that it has undergone an external security review, and the results are not encouraging,” he stated.

Related Posts:

  • deccanherald_2025-07-15_likoucgy_Sun-Day-Tracker-app
    Bitchat By Jack Dorsey Tracks Sun Exposure
  • c23425a0-5b64-11f0-93fb-86d607ec7e6f
    Bitchat Bluetooth Messaging App On App Store
  • Bitchat-uygulamasi-1024x576
    China Pulls Jack Dorsey's Bitchat App From Apple Store
  • 1200-675-24546247-850-24546247-1751976670867
    Former Twitter CEO Launches Bitchat Bluetooth Messaging App
  • bitchat_github_1751955828498
    Amid Violent Anti-Corruption Protests, Nepalis Turn…
  • skynews-whatsapp-phone-messaging_6156083
    WhatsApp Introduces Chat Lock To Lock & Hide Chat Threads
  • logo-featured-blog
    NordVPN Launches Custom Protocol to Bypass Network…
  • JACK-DORSEY
    Jack Dorsey’s New Company Struggles After Forcing AI…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: bitchatjack dorseymessagingsecurity
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Google’s Gemini-powered ‘Rambler’ Dictation comes to Gboard, Raising Pressure on Voice Startups May 12, 2026
  • ‘Daybreak’: OpenAI Launches Cybersecurity Push to Rival Anthropic’s Glasswing May 12, 2026
  • Google Links First-Ever Zero-Day Discovery to AI-Assisted Hacking May 12, 2026
  • Googlebooks: Google’s Android-Powered AI Laptops Are Coming This Year May 12, 2026
  • TikTok Launches In-App Travel Booking Service ‘TikTok GO’ in the US May 12, 2026
  • GitLab Opens Voluntary Layoffs as It Reshapes for AI Era May 12, 2026
  • Instructure Reaches Deal With Hackers After Twin Breaches Of Canvas Platform May 12, 2026
  • TikTok Rolls Out Ad-Free Subscription Plan In UK May 11, 2026
  • WhatsApp Plus Launches On iOS With Premium Features May 11, 2026
  • Venmo’s Biggest Refresh In Years May 11, 2026
  • Threats Rise Against Data Centers & Its Critical Tech Foundation May 11, 2026
  • Vodacom Aims At Exceeding 275 Million Customer Base May 11, 2026

Browse Archives

May 2026
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.