An analysis of X's new XChat features shows that X can probably decrypt any user's messages, as the company stores its users' private keys on its own servers
Update 6/10: Based on a short conversation with an engineering lead at X, some of the devices used at X are claimed to be using HSMs.
Context & Ripple Effects
XChat was initially presented as an encrypted messaging rollout with disappearing messages and file sharing; this analysis tests whether that early encryption promise matches the system’s key-management design.
The issue matters as XChat’s messaging ambitions expand: later coverage frames Chat as a DM replacement and a standalone app that claims end-to-end encryption. The engineering lead’s HSM comment adds an important qualification, but does not by itself resolve the analysis’s concern over who controls private keys.
First-order effects
- Users and prospective users must treat XChat’s encryption claim as qualified: if X retains usable private keys, X may be able to decrypt message content.
- X faces a credibility and technical-disclosure burden around its key custody and the role of HSM-backed devices, particularly as it promotes Chat as an E2EE replacement for DMs.
Second-order effects
- Messaging users and security-conscious organizations may compare services less by an E2EE label and more by whether private keys remain outside the provider’s reach.
- A standalone XChat product positioned around encryption will face closer scrutiny of its implementation than a feature-level rollout, making architecture details more consequential to adoption.
Third-order effects
- The episode points to a broader shift from marketing encryption as a feature to evaluating verifiable key control as the meaningful privacy boundary.
- If this pattern persists, privacy competition in messaging will increasingly turn on whether providers can technically access keys, not simply on whether they describe a service as end-to-end encrypted.
The trend: Messaging privacy is moving toward implementation-level accountability, where key custody determines whether encryption claims carry practical meaning.