Nothing Chats just got pulled from Google Play store over security concerns

A picture of the Nothing Phone 2 with a customized home screen
(Image credit: Tom's Guide)

Last week Nothing announced a brand new chat app, Nothing Chats, which effectively brings a version of Apple’s iMessage to Android. That way you’re not sending messages and files by the old, insecure SMS and MMS systems. Unfortunately, Nothing has now pulled the app from Google Play, and it’s apparently all due to serious security concerns. 

Nothing Chats works, and the process requires you to let Sunbird log into your iCloud account from its servers — allegedly powered by a Mac Mini. Which is sketchy enough already, but it gets worse than that. According to a report from Texts.com, it turns out Songbird messages aren’t end-to-end encrypted. Apparently, it’s not that difficult to compromise the system either.

9to5Google spotted that the site’s owner, Dylan Roussel, went into much greater detail on a Twitter/X thread. 

Roussel claims that Sunbird works by decrypting and transmitting messages via HTTP to a Firebase cloud-syncing server and storing them in unencrypted plain text. He noted that Sunbird also has access to these messages, since they’re logged as errors by debugging service Sentry.

Sunbird is said to have claimed that transmitting via HTTP is fine, because it’s only used as part of the initial request. Roussel notes that this still leaks users' email addresses. It still doesn’t change the fact that Sunbird messages are publicly visible via the Firebase real time database, and not encrypted.

Nothing’s FAQ claims that the Sunbird system is secure and end-to-end encrypted, while also stating that messages and Apple credentials are not stored at any point in its journey. According to Roussel, the exact opposite appears to be true.

One of the biggest benefits of iMessage is that it’s end-to-end encrypted by default. Apple also cited additional security as one of the reasons why it will be adopting the RCS messaging standard next year. In both cases your messages are secure, and inaccessible by third parties — Apple included.

So if you’re going to be left to communicate in a hilariously insecure manner, you may as well stick with the traditional SMS option. At least that doesn’t ask you to log into a third-party server with your Apple credentials.

The official Nothing Chats page confirms that the beta app has now been pulled from the Play Store, with launch being delayed until Nothing and Sunbird can fix “several bugs." Which is putting it lightly. 

When asked for comment, a Nothing spokesperson said “We’ve removed the Nothing Chats beta from the Play store and will be delaying the launch until further notice to work with Sunbird to fix several bugs. We apologize for the delay and will do right by our users.”

In the meantime, your dream of hiding as a blue-bubbled Apple user without buying an iPhone is not going to come true anytime soon. And given everything that’s come to light, it’s probably something you should try and avoid going forward.

More from Tom's Guide

TOPICS
Tom Pritchard
UK Phones Editor

Tom is the Tom's Guide's UK Phones Editor, tackling the latest smartphone news and vocally expressing his opinions about upcoming features or changes. It's long way from his days as editor of Gizmodo UK, when pretty much everything was on the table. He’s usually found trying to squeeze another giant Lego set onto the shelf, draining very large cups of coffee, or complaining about how terrible his Smart TV is.

Read more
RCS messaging on an iPhone
Forget green bubbles — iPhones will soon get encrypted RCS messaging to Androids
DeepSeek logo on smartphone in front of merging US and Chinese flags
DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
An illustration of a person holding a smartphone with a padlock in front of speech bubbles on the screen
The best encrypted messaging apps in 2025
How to tell if you've been blocked on WhatsApp
The best WhatsApp alternatives in 2025
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
Google Messages on an Android phone screen
Google Messages may start letting you delete embarrassing text messages — here’s how
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam