Nothing pulls its Sunbird-based iMessage app Nothing Chats from Play Store after a researcher found the app is not e2e encrypted, attachments are public, more
Sunbird has been promising iMessage support on Android for about a year now, but the company has always seemed rather sketchy.
Context & Ripple Effects
Nothing had only just planned an early Phone (2)-only rollout of its Sunbird-based bridge to iPhone contacts, making the security findings an immediate reversal of the product’s premise. The episode follows an established risk pattern: researchers previously found that Confide’s claimed end-to-end encryption was not genuine.
The withdrawal matters because cross-platform messaging products are judged not merely on reach, but on whether their technical handling matches their privacy claims. A later entrant, Beeper Mini’s E2EE iMessage service, underscores how central that assurance had become to the category.
First-order effects
- Nothing removed Nothing Chats from Google Play, cutting off the early iMessage-on-Android offering for its users while the reported message and attachment exposure is addressed.
- Sunbird’s role as the underlying service becomes a direct trust and due-diligence problem for Nothing after the planned Phone (2) rollout was overtaken by the security findings.
Second-order effects
- Android-to-iMessage bridge providers face greater pressure to substantiate encryption architecture and attachment access controls before asking users to route private conversations through them.
- Hardware brands seeking service differentiation have a stronger incentive to vet messaging partners independently; a privacy failure can rapidly become a brand-level issue rather than remain a vendor issue.
Third-order effects
- If this pattern persists, interoperability products will compete on verifiable security guarantees as much as on access to closed messaging networks, favoring designs with clearer trust boundaries.
- The episode points to a broader limit on workaround-based interoperability: consumer demand for cross-platform messaging will not sustain services whose privacy claims cannot be independently validated.
The trend: Cross-platform messaging is moving from novelty bridging toward a trust-first market in which encryption claims and data-access boundaries determine viability.