Cebulka Blog

Popular Messengers Compared by OpSec Profiles

This article evaluates the OpSec profile of popular messengers designed for anonymous and secure darknet communication where enforced end-to-end encryption and anonymity are expected minimum standards. Each messenger is assessed based on security, privacy features, and anonymity guarantees.

Messenger comparison

The list below compares messengers evaluated by their OpSec profile. Enforced anonymity and enforced E2E encryption are considered the expected minimum of a secure-by-default setup.

Session

+ Open-source client
+ Enforced E2E encryption
+ Enforced anonymization (Session network)
+ Decentralized

OnionXMPP

+ Open-source client
+ Enforced E2E encryption
+ Enforced anonymization (Tor network)
- Centralized

Cwtch, Ricochet Refresh, Briar

+ Open-source client
+ Enforced E2E encryption
+ Enforced anonymization (Tor network)
+ Decentralized
- High risk of Guard Discovery attack [1]

Bitmessage

+ Open-source client
+ Enforced E2E encryption
+ Enforced anonymization (Bitmessage network)
+ Decentralized
- High risk of Sybil attack [2]
- Unmaintained since 2018

Matrix (Clearnet)

+ Open-source client
+ Enforced E2E encryption
+ Decentralized
- No enforced anonymization

SimpleX

+ Open-source client
+ Enforced E2E encryption
+ Decentralized
- No enforced anonymization [3]

Threema

+ Open-source client
+ Enforced E2E encryption
- No enforced anonymization
- Payment linked to identity [4]
- Centralized

Signal

+ Open-source client
+ Enforced E2E encryption
- No enforced anonymization
- SMS verification required
- Centralized

Tox, Skred

+ Open-source client
+ Enforced E2E encryption
+ Decentralized
- No enforced anonymization
- P2P leaks IP to recipients [5]

Wire

+ Open-source client
+ Enforced E2E encryption
- No enforced anonymization
- Phone number (if used) and IP shared with authorities
- Leaks device and user IDs in push notifications
- Collects telemetry and crash reports data
- Centralized

XMPP (Clearnet)

+ Open-source client
+ Decentralized
- No enforced E2E encryption
- No enforced anonymization

Zangi

+ Decentralized
- Closed-source client
- Proprietary E2E encryption [6]
- No enforced anonymization
- P2P leaks IP to recipients

Telegram

+ Open-source client
- No enforced E2E encryption [7]
- No enforced anonymization
- SMS verification required, bans for virtual numbers [8]
- Phone number and IP shared with authorities [9]
- Collects telemetry and crash reports data
- Centralized

WhatsApp

- Closed-source client
- Snake-oil E2E encryption [10]
- No enforced anonymization
- SMS verification required, bans for virtual numbers
- Transparent phone number, IP shared with authorities
- Collects telemetry and crash reports data
- Centralized

Notes

[1] "High risk of Guard Discovery attack" (Cwtch, Ricochet Refresh, Briar). These messengers communicate over locally hosted Onion Services. While this design has advantages in terms of decentralization, hosting long-lived Onion Services gives an attacker greater opportunities for probing and for various Bandwidth and Rendezvous Point overuse attacks. Hosting an Onion Service has a different threat model than being a Tor client connecting to a server; the chances of a successful Guard Discovery attack and subsequent deanonymization of the Onion Service location are higher. A few experienced administrators who are aware of this risk apply additional mitigations to their Onion Services, but Cwtch, Ricochet Refresh, Briar do not include them. Tor ships with built-in vanguards-lite, which is of limited use and is not designed for hosting long-lived Onion Services. The Tor Project is aware of this but has not yet included the full "vanguards" addon functionality; vanguards-full is planned for Arti, their new experimental Tor client.

Sources: 1, 2, 3, 4

[2] "High risk of Sybil attack" (Bitmessage). While Tor has its guard node mechanism and actively seeks and removes malicious nodes based on various characteristics, and while the Session network makes Sybil attacks expensive through a financial barrier, Bitmessage is an example of an open peer-to-peer network with free node entry, highly vulnerable to large-scale Sybil attacks.

Sources: 1, 2, 3, 4

[3] "No enforced anonymization" (SimpleX). SimpleX does not enforce the use of any anonymization network at the network level. Moreover, its authors falsely claim to have implemented "2-hop onion message routing", which is merely an option for the sender to choose an SMP router and does not differ from using a proxy. This has nothing to do with Tor onion routing and gives users a false sense of security. The SimpleX authors also demonstrate a lack of technical knowledge about anonymity networks; therefore, using SimpleX is discouraged.

Sources: 1, 2, 3

[4] "Payment linked to identity" (Threema). Although Threema is not a free app and requires a one-time payment, a user can obtain a license through their store using Tor Browser, without an email address, without filling in billing address details, and pay either in cash or in Bitcoin. Although Bitcoin is not a transparent, trackable coin, a payment can be made through an instant swap service from Monero. Moreover, the generated Threema ID is not associated with the payment details. However, this is not anonymous by default, and if done incorrectly, the payment processor may gather the true identity and reveal Threema use upon a law enforcement request. It is therefore considered a minor flaw.

Sources: 1, 2, 3

[5] "P2P leaks IP to recipients" (Tox, Skred). Tox makes no attempt to cloak your IP address when communicating with others, as the whole point of a peer-to-peer network is to connect you directly to your recipients. It therefore allows IP discovery by law enforcement without a subpoena, if no additional setup with Tor is made. The same weakness applies to Skred messenger as well.

Sources: 1, 2

[6] "Proprietary E2E encryption" (Zangi). Zangi's encryption is not open-source and has not been independently audited. There is no public peer review from security researchers. The handshaking mechanism could contain exploitable flaws, whether by mistake or intentional.

Sources: 1

[7] "No enforced E2E encryption" (Telegram). All communication is transparent to Telegram by default, and E2E encryption is only available in their "Secret Chats", which are supported only in the mobile apps. Meanwhile, Telegram markets its messaging platform with a focus on security. In this context, it is worth mentioning that they openly claim to use AI moderation tools for "proactive monitoring". An OCCRP investigation revealed that Telegram's network infrastructure is managed by a Russian engineer linked to the FSB. Telegram denies these claims.

Sources: 1, 2, 3, 4

[8] "SMS verification required, bans for virtual numbers" (Telegram). There are many user reports of Telegram banning entire ranges of virtual number operators, which can lead to losing an account later when Telegram is registered through an SMS activation service. Without 2FA enabled, many users of such SMS activation services also have their accounts hijacked, as their chosen phone number is later reassigned to another user.

Sources: 1, 2

[9] "Phone number and IP shared with authorities" (Telegram). Telegram changed its policies in 2024 and has agreed to actively cooperate with law enforcement since then. Telegram does not publish transparency reports on its website; they remain obscured in the @transparency bot and are limited to the country in which the Telegram account requesting data is registered.

Sources: 1, 2

[10] "Snake-oil E2E encryption" (WhatsApp). Your contact's encryption key can change legitimately when they reinstall the app, switch devices, or restore a backup. It can also happen when a centralized messaging platform is forced to conduct a Man-in-The-Middle attack and snoop on conversations, and Meta Platforms was accused of doing so in a 2026 lawsuit. WhatsApp automatically re-encrypts and sends your message with the new key without asking for approval. Even if key change notifications are enabled, you will be notified after the message has been sent, therefore a data leak is in such case unavoidable.

Sources: 1, 2, 3

Tags: