Back to News
Market Impact: 0.5

X is now offering me end-to-end encrypted chat — you probably shouldn’t trust it yet

Technology & InnovationCybersecurity & Data PrivacyProduct LaunchesMedia & Entertainment

X (formerly Twitter) has launched 'XChat,' a new end-to-end encrypted messaging feature, but cryptography experts are widely criticizing its implementation as fundamentally flawed and untrustworthy, far inferior to industry standards like Signal. Key concerns include X storing user private keys on its own servers, admitting to potential 'adversary-in-the-middle' attacks by insiders, and lacking open-source transparency or perfect forward secrecy, which collectively undermine its claimed security and pose significant privacy risks for users.

Analysis

X's rollout of its 'XChat' encrypted messaging feature has been met with significant and credible criticism from cryptography experts, undermining its strategic goal of enhancing user trust and platform utility. The implementation exhibits several fundamental security flaws that render its end-to-end encryption claims untrustworthy. Key concerns center on X's decision to store user private keys on its own servers, protected by a simple four-digit PIN, in stark contrast to industry best practices like Signal, which stores keys on-device. The company's unverified claims of using Hardware Security Modules (HSMs) fail to mitigate these concerns. Critically, X itself admits in its support documentation that the current design is vulnerable to 'adversary-in-the-middle' attacks from the company or a malicious insider, a concession that effectively negates the core premise of private, end-to-end encrypted communication. Further red flags include the lack of open-source code for independent verification and the absence of 'perfect forward secrecy,' a feature that would limit the damage of a compromised key. The consensus from security researchers is that the feature, in its current state, offers no more security than existing unencrypted direct messages, representing a significant reputational risk and a poorly executed product launch that could erode user confidence rather than build it.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.80

Key Decisions for Investors

  • The flawed launch of XChat represents a significant execution failure and reputational risk, likely hindering X's ability to attract privacy-conscious users and grow engagement, so investors should monitor user sentiment and platform activity for signs of deteriorating trust.
  • This event highlights a substantial technical and credibility gap between X and established secure messaging competitors, casting doubt on its ability to successfully execute its broader 'everything app' strategy.
  • View X's promises of future audits, open-sourcing, and technical whitepapers with caution, as the current product demonstrates a disconnect between ambition and execution capability.
  • The negative expert reception underscores the high barrier to entry in the secure communications space, potentially reinforcing the market position of established and trusted platforms.