Is Molly safe? The honest answer

Published: October 7, 2026 Updated: October 8, 2026

Short answer: Molly is as safe as its code being public makes it. It is an independent, open-source fork of Signal, so anyone can read its code, and it uses the same Signal protocol and end-to-end encryption as the official app. The honest caveats: it is built by a small independent team rather than a large foundation, so releases trail Signal's; and the biggest real-world risk is not the app itself but fake download sites and third-party APK mirrors pretending to be Molly. Safety here is mostly a supply-chain question: get it from Molly's official site or its official F-Droid repository, and the risk picture is boring. Get it anywhere else, and all bets are off. Below is the full breakdown, including the cases where official Signal is simply the better call.

Illustration of a shield with a magnifying glass, symbolizing that Molly's open-source code can be inspected

What "safe" can mean for a chat app

When people ask whether an app is safe, they usually mean one of three different things, and it helps to separate them. First: is the code honest? Can anyone verify what the app actually does, or do you have to take the developer's word for it? Second: is the cryptography sound? Are messages actually end-to-end encrypted with a protocol experts trust? Third: is the download genuine? Is the file on your phone the one the developers published, unmodified?

Molly scores well on the first two by construction. Its code is open-source, published for anyone to read, which is the strongest form of the first claim an app can make. Closed-source apps ask for trust; open-source apps allow verification. And the cryptography question is settled by the fork relationship: Molly speaks the same Signal protocol as the official app, so its encryption properties are the protocol's properties, not something a small team reinvented. The third question, the download, is where you do the work, and it gets its own section below.

Open-source does not mean "reviewed by thousands of experts", by the way. It means review is possible. That distinction matters, and anyone who tells you open code automatically equals secure code is selling something.

Keypoints graphic for: What
Key points: what safe can mean for a chat app.

Who builds Molly, honestly

Molly is built and maintained by independent developers. It is not a product of Signal Foundation, it is not endorsed by Signal, and it has nothing like Signal's team size or funding. Saying that is not an insult; it is the central fact of the trust decision, and the developers themselves do not pretend otherwise.

What the small team means in practice: Molly's releases follow Signal's with a gap. When Signal ships a new version, the Molly developers have to review the changes, apply their modifications, and publish their own builds. That takes time, so Molly users wait longer for new features and, more importantly, for fixes. The gap is usually described in qualitative terms, days to weeks, not a fixed schedule, because it depends on how big each upstream change is. If you are the kind of person who wants security fixes the hour they ship, that lag is a genuine cost, and official Signal is the better fit for you.

The smaller team also means a narrower support surface: the fork's own issue tracker and documentation rather than Signal's support operation. For straightforward use this rarely matters. For weird bugs it can mean slower answers. Neither of these is a reason to call Molly unsafe; they are reasons to understand what you are choosing. For background on the fork itself, see what Molly is.

Keypoints graphic for: Who builds Molly, honestly
Key points: who builds molly, honestly.

The real risk: who builds it, not the code

Here is the uncomfortable truth about every popular open-source app: the code being clean does not help you if the file you installed was not built from that code. Attackers know people search for "Molly APK download", and they build lookalike sites that serve modified installers, bundle the real app with spyware, or simply take you to an unrelated download. This is not theoretical. It is the standard playbook for every sought-after app distributed outside the Play Store.

The defense is simple and absolute: molly.im or its official F-Droid repository, and nothing else. The official site is Molly's official site; the F-Droid repository is at Molly's official F-Droid repository. If a site offers you a "Molly Pro", a "Molly Plus", a modded build with extra features, or any Molly download from a file mirror, close the tab. There is no pro version. There is no plus version. Those do not exist, and anything wearing those names is either a scam or malware. Our Molly install guide walks through the safe sources step by step, and the same warning applies to official Signal downloads, covered in our APK mirror warning.

One more supply-chain habit: be suspicious of any page that claims to be the "official Molly site" at a different domain. Molly's developers publish from molly.im. Anything else claiming official status is lying to you.

Get Molly from its official site

Molly is distributed by its own developers. The only safe sources are the official site and its official F-Droid repository.

Open molly.im

F-Droid users: add molly.im/fdroid as a repository instead.

The encryption is the same Signal protocol

Molly connects to the same Signal network and speaks the same protocol as the official app. Your messages are end-to-end encrypted the same way, your calls use the same setup, and your contacts cannot tell which app you use. The fork changes the app around the protocol: notification plumbing, database encryption options, build configuration. It does not reimplement the cryptography.

That is worth understanding clearly, because it bounds both the praise and the criticism. Molly is not "more encrypted" than Signal; the encryption is identical. And the realistic attack surface a fork adds is in the surrounding code, the build process, and the update channel, not in the message encryption. If someone tells you Molly is safer because of its encryption, or less safe because of its encryption, they have misunderstood what a fork is. Compare the two apps directly in Molly vs Signal.

Can you trust Molly? It depends what you're protecting

"Is it safe?" is the wrong question without "safe for whom, against what?" Here is the honest version:

Your situationVerdictWhy
Everyday user who wants private messagingMolly from molly.im is fineOpen code, same protocol, sane defaults. The fork lag is a minor cost.
Phone without Google services (Huawei, GrapheneOS)Molly-FOSS is the natural pickThe FOSS build exists precisely for this case; see Molly on Huawei.
Journalist, activist, or anyone with real adversariesThink carefully; official Signal may fit betterThe release lag and smaller review surface matter more when the stakes are high. Consider your whole setup, not just the app.
Someone who wants fixes the day they shipUse official SignalNo fork can beat upstream's release speed. This is structural, not a criticism.
Someone who downloaded Molly from a random mirrorUnsafe until proven otherwiseUninstall it, get the real build from molly.im, and treat the old install as compromised.

Notice what this table does not say: it does not say Molly spies on you, and it does not say Molly is magically safer than Signal. Both of those claims would be FUD or cheerleading. The truth is duller: it is a competent fork with a small team, and your experience of its safety will be dominated by where you downloaded it and whether its trade-offs match your situation.

Red flags to avoid

Download the official Signal APK

from Signal's official site (file hosted by Signal, not by us)

The bottom line: Molly's safety story is good but not magical. Open code you can inspect, the same proven protocol as Signal, a small honest team, and one non-negotiable rule about where you download it from. Match the tool to your threat model, keep the download source clean, and there is nothing to be afraid of. If any part of that feels like too many conditions, official Signal is right there, and there is no shame in choosing it. Read our safety guide for the official APK for the other half of the picture.

Frequently asked questions

Is Molly affiliated with Signal Foundation?

No. Molly is an independent fork built by third-party developers. It is not made by, endorsed by, or affiliated with Signal Foundation in any way.

Is it legal to use Molly?

Yes. Molly is open-source software that connects to the Signal network using the public protocol. Using an independent client is not illegal; it is simply unofficial.

Can Molly read my messages?

Molly uses the same Signal protocol with the same end-to-end encryption as the official app. Messages are encrypted on your device and can only be read by you and the recipient. The code is open-source, so this is verifiable rather than a promise.

Why does Android warn me when installing Molly?

Android warns about any app installed outside Google Play, including perfectly legitimate ones. The warning is about the install source, not a verdict on Molly. Verify you downloaded it from molly.im and proceed.

Is Molly on F-Droid safe?

Yes, provided you add the official Molly repository at molly.im/fdroid. F-Droid builds from published source, and using the developers' own repository removes mirror risk.

Should I use Molly or official Signal?

Use Molly if you have a specific reason: no Google services on your phone, or you want its extra features like database passphrase encryption. Otherwise official Signal is simpler, updates faster, and has full official support.

Keep reading