Repository navigation
Releases: LiudvigVladislav/SHIFROM
Release list
PHANTOM Alpha 2
PHANTOM Alpha 2
A protocol-hardening snapshot focused on real X3DH, identity-key separation, and a safe Alpha 1 → Alpha 2 migration.
Tagged on 2026-04-30. This release documents the exact state of v0.1.0-alpha.2; it does not include the later Alpha 2 work that subsequently landed on master.
Looking for the current state of the project? See the
README onmaster—
development has moved substantially beyond this tag.
Highlights
Alpha 2 replaces the provisional Alpha 1 session bootstrap with a real X3DH four-DH handshake, separates long-term identity signing from ratchet key material, adds signed and one-time prekeys, and provides an explicit migration path for existing Alpha 1 identities.
The existing X25519 identity is preserved, so users retain the same public identity and QR code. Protocol-incompatible Alpha 1 ratchet state is intentionally discarded and re-established under the hardened handshake.
Cryptographic hardening
- Real X3DH four-DH session bootstrap with a SignedPreKey and optional OneTimePreKey.
- Fresh ephemeral X25519 keypair per new session, closing the Alpha 1 identity-as-ratchet-seed weakness.
- Two-keypair identity model:
- X25519 identity key remains the stable public identity.
- A new Ed25519 identity-signing key authenticates SignedPreKey bundles.
- SignedPreKey verification before a session is accepted.
- OneTimePreKey consumption for stronger first-session forward secrecy.
- HKDF-SHA256 session derivation with a versioned PHANTOM X3DH salt.
- SessionManager rewrite so first-message bootstrap and subsequent Double Ratchet traffic use the new protocol consistently.
- The inactive SenderKey-signing design and its limitations are documented in ADR-017 rather than presented as a working group-signature mechanism.
See ADR-009 for the key hierarchy and handshake design.
Prekey infrastructure
- Relay endpoints for publishing, fetching, checking and consuming prekey bundles.
- A 1:1 binding between the preserved X25519 identity and the new Ed25519 signing key; conflicting bindings are rejected.
- Local SQLDelight storage for SignedPreKeys and OneTimePreKeys.
- Initial publication of one SignedPreKey and 100 OneTimePreKeys.
- Automatic OPK replenishment when the local pool falls below 20 keys.
- Weekly SignedPreKey rotation.
- Prekey lifecycle wiring during onboarding and application startup.
Alpha 1 → Alpha 2 migration
Existing Alpha 1 installations are detected automatically on first launch.
The migration:
- Preserves the existing X25519 identity and public QR-code identity.
- Generates and persists a new Ed25519 signing keypair.
- Generates and publishes the new signed/one-time prekey bundle.
- Removes old ratchet and SenderKey states rooted in the provisional Alpha 1 bootstrap.
- Marks affected conversations as requiring a new handshake.
- Preserves previous messages as read-only history.
The migration is designed to be idempotent and resumable if the network or relay becomes unavailable during prekey publication.
Because the wire protocol changed, Alpha 1 and Alpha 2 sessions are not mutually compatible. Contacts must migrate and re-establish their sessions; the app does not silently fall back to the weaker Alpha 1 handshake.
See the migration document for the detailed flow and recovery cases.
Privacy, safety and application changes
- Android
FLAG_SECUREprotection blocks screenshots and recent-app thumbnails. - Safety Number verification is wired to the real identity fingerprint calculation.
- Message Requests now require confirmation before blocking a sender.
- Client-side reporting is connected to the relay report endpoint.
- Per-conversation mute and pin controls.
- Consolidated long-press message actions and clearer pin attribution.
- Voice recording moved to OGG/Opus at 48 kHz mono / 48 kbps.
- Standard, Private and Ghost privacy-mode configuration surfaces were added. Their advanced transport behavior is not part of this tagged snapshot.
- Unsupported or incomplete Phase 3 features are hidden or shown with honest empty states.
Interface refresh
The Android client received its first complete PHANTOM design-system pass:
- shared color, spacing and typography tokens;
- bundled Geist, Inter and JetBrains Mono variable fonts;
- refreshed chat list, bubbles, composer and chat header;
- revised onboarding, profile, settings and verification surfaces;
- consistent archive, saved-message, contact, request and group shells;
- corrected navigation, iconography, ripples and empty states.
Some of these screens are foundations for later features and should not be read as proof that every represented feature is operational in this tag.
CI and verification
The repository gained GitHub Actions coverage for:
- Android builds and JVM tests;
- Rust relay tests;
- Codeberg mirroring.
The tagged protocol-hardening surface records 83 targeted tests:
- 11 X3DH four-DH crypto vectors;
- 10
SessionManagerTestcases; - 9
DefaultMessagingServiceTestbootstrap cases; - 8
MigrationManagerTestcases; - 7
PreKeyLifecycleServiceTestcases; - 17 relay unit and HTTP-integration tests;
- 11
PreKeyApiClienttests; - 10
IdentityManagerTestcases.
Known limitations
This remains an early Android pre-release:
- The tag predates the later Xray/REALITY, Tor and REST-fallback work now present on
master; transport in this snapshot is direct WSS. - The custom Double Ratchet/X3DH implementation over libsodium has not received an independent third-party cryptographic audit.
- Alpha 1 contacts must migrate before an Alpha 2 peer can establish a new session with them.
- Existing conversation history remains readable, but old sessions are intentionally invalidated and contacts must be re-established.
- At this tag, voice delivery was not reliable on the tested Tecno/HiOS path without a VPN; later work on
master(REST fallback, encrypted media pipeline) addresses this. - The relay PreKeyStore uses in-memory state with JSONL persistence and is not yet designed for large-scale deployment.
- No iOS or production web client is included.
- Groups, channels, attachments and nearby mesh communication are not available as complete user-facing features.
- No Alpha 2 APK is attached to this release; GitHub provides source archives for the tag.
- The annotated Git tag is not cryptographically signed.
See the known-issues snapshot at this tag and the current register on master.
Documentation
- Architecture overview
- ADR-009 — Identity and prekey separation
- ADR-017 — SenderKey signing-key removal
- Alpha 1 → Alpha 2 migration
- Security policy
Full changelog
Alpha 2 contains 66 commits after Alpha 1:
PHANTOM Alpha 1
PHANTOM Alpha 1
A privacy-focused, censorship-resistant messenger combining Telegram-style UX with Signal-grade security.
This is the first Alpha-tagged release of PHANTOM. End-to-end encryption, sealed-sender envelopes, and a self-hostable relay server, all production-deployed and verified end-to-end.
What ships
- End-to-end encrypted 1-on-1 chat via libsodium + Double Ratchet
- Sealed-sender envelopes — relay sees only routing metadata, never sender identity
- Trust Tier flow — first message from an unknown contact lands in Message Requests
- Store-and-forward delivery through a Hetzner-hosted Rust relay over WSS
- QR contact exchange and
phantom://invite/<base64>deep links - Encrypted local storage (SQLDelight + SQLCipher; DH private key wrapped by Android Keystore)
- Foreground-service WebSocket with Wi-Fi
WIFI_MODE_FULL_HIGH_PERFlock + partial wake lock - Terms of Service + Privacy Policy wired into onboarding (EN + RU); themed HTML mirrors at
/terms,/privacy,/terms/ru,/privacy/ruonphntm.pro - AGPL-3.0-or-later licensed; SPDX headers across the source tree; third-party attributions in
NOTICE - 16/16 crypto integration tests green on Pixel 8 Pro / API 35
What's intentionally not in Alpha 1
- iOS / desktop / web clients
- Voice and video calls
- Attachments
- Group chats (state-machine and Sender-Keys crypto are present but not surfaced)
- Tor / Bluetooth / Wi-Fi Direct transports
These are scoped to Alpha 2 / Beta — see ROADMAP.md.
Updated 2026-04-28 — what's new since first Alpha 1 build
- Chat input bar inset fix — input no longer clips behind IME or navigation bars on Android 14/15 gesture-nav devices (
f46d2772,d2320b95— root-causeenableEdgeToEdge()migration) - Terms of Service + Privacy Policy in onboarding flow, available also as themed HTML at
phntm.pro/termsandphntm.pro/privacy(d2320b95,99a93c41) - Russian localisation of legal pages with EN/RU switcher (
09012ab1,b3629bed) - 6 RFC-2142 contact addresses (
security@,support@,privacy@,legal@,abuse@,press@phntm.pro) inSECURITY.mdand Settings → About (b2056987) - License hygiene — full AGPL-3.0 LICENSE, SPDX headers on 121 source files, NOTICE with third-party attributions, README license section finalised (
e99aac0e…0bc715e1) - Project history — durable
docs/PROJECT_LOG.mddecision log (707a03c1) - Profile UX: numeric keyboard with
mm.dd.yyyyformatter for date-of-birth field; identity cached in anAppContainerStateFlowso Profile no longer flashes "Loading…" on every navigation; self-avatar shared across top-bar / chat list / calls / settings via the sameStateFlow; circular ripple on the top-bar avatar - Transport reliability for large payloads: OkHttp transport-level ping disabled (
pingInterval(0)) — its 8 s pong-timeout was killing every voice envelope mid-upload because pingInterval is also the pong-timeout in OkHttp. App-levelRelayMessage.Ping/Pong(10 s / 60 s) is now the sole liveness check.ACK_TIMEOUT_MSandPONG_TIMEOUT_MSbumped to 60 s; relayRELAY_MAX_PAYLOAD_BYTESdefault is 1 MiB (was 64 KiB) so voice notes fit. Voice messages now deliver end-to-end on stock-Android-to-stock-Android in ~1 s for a 75 KB envelope — see KNOWN_ISSUES.md ISSUE-001 for the residual Tecno-class-OEM limitation
Known limitations
ISSUE-001 — Aggressive-OEM Android skins (Tecno HiOS verified, Xiaomi MIUI / Huawei EMUI strongly suspected) park the Wi-Fi radio mid-session even with a foreground notification. Effect on the user is ~1–3 s extra message-delivery latency under reconnect; no message loss (store-and-forward is durable). Stock Android (Pixel emulator on Wi-Fi) is stable across multi-minute QA sessions on the same code path. Long-term fix via Unified Push (FOSS, no Google dependency) is on the Alpha 2 roadmap.
Full register in KNOWN_ISSUES.md.
Verification
- Release APK file SHA-256:
3af1053019e547f86c9e1a1e4d69d0e9922b4576f20c5e3d1fb2a197a9f47622 - Release signing certificate SHA-256:
aa:17:09:48:3e:bd:47:f1:21:ce:0b:d1:46:92:d1:d5:75:fd:28:a0:d6:5c:4b:2e:20:1a:be:88:2c:ab:1f:02 - Signed by:
CN=PHANTOM Messenger, O=Willen LLC, C=US - APK size: 92,306,502 bytes
- Production relay:
wss://relay.phntm.pro/ws(Hetzner Helsinki, EU jurisdiction;RELAY_MAX_PAYLOAD_BYTES = 1 048 576) - Build: master post Alpha 1 patch series
Documentation
- README — project overview, architecture, threat model, build instructions
- RELEASE_NOTES — what's in Alpha 1 in full detail
- KNOWN_ISSUES — honest limitations register
- ROADMAP — what comes next
- SECURITY — responsible-disclosure policy
- docs/ARCHITECTURE — 5-layer system design
- docs/CRYPTO — primitives, X3DH, Double Ratchet, key rotation
- docs/threat-model/Threat_Model_v0 — adversary model