# SimpleX network: security review of protocols design by Trail of Bits

**URL:** https://discuss.privacyguides.net/t/simplex-network-security-review-of-protocols-design-by-trail-of-bits/21512
**Category:** General
**Created:** 2024-10-14T12:53:36Z
**Posts:** 6

## Post 1 by @jerm — 2024-10-14T12:53:36Z

> **[SimpleX network: cryptographic design review by Trail of Bits, v6.1 released...](https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html)**

> There are 3 medium and 1 low severity findings, all of which require a high difficulty attack to exploit — the attacker would need to have a privileged access to the system, may need to know complex technical details, or must discover other weaknesses to exploit them. Additionally, there are 3 informational findings.

---

## Post 2 by @ignoramous — 2024-10-14T12:59:51Z

Nice.

_Trail of Bits_ reviewed both the algorithm & the implementation? The implementation is where the zero-days are.

---

## Post 3 by @jerm — 2024-10-14T13:09:20Z

> ### Next: security audit in 2025
> 
> We are planning the implementation security assessment with Trail of Bits in the beginning of 2025. It will be a twice bigger assessment than we did in 2022 — it will cover both the core of the app and the handling of cryptographic secrets in the mobile applications.

---

## Post 4 by @anon48875053 — 2024-10-14T14:30:18Z

Good job @epoberezkin!

---

## Post 5 by @Cork — 2024-10-14T20:31:20Z

I’m a privacy newcomer. Can someone explain why this service can be trusted not to be some sort of government HoneyPot? I get that you have to place your trust somewhere, but why SimpleX?

---

## Post 6 by @jerm — 2024-10-15T12:36:12Z

> trusted not to be some sort of government HoneyPot?

It is open source and you can selfhost servers, it keeps getting security audits.

> but why SimpleX?

You can check their website, [https://simplex.chat/](https://simplex.chat/) and their [roadmap](https://github.com/simplex-chat/simplex-chat/?tab=readme-ov-file#roadmap).
