Is Molly safe? The honest answer
Published: October 7, 2026 Updated: October 8, 2026
Short answer: Molly is as safe as its code being public makes it. It is an independent, open-source fork of Signal, so anyone can read its code, and it uses the same Signal protocol and end-to-end encryption as the official app. The honest caveats: it is built by a small independent team rather than a large foundation, so releases trail Signal's; and the biggest real-world risk is not the app itself but fake download sites and third-party APK mirrors pretending to be Molly. Safety here is mostly a supply-chain question: get it from Molly's official site or its official F-Droid repository, and the risk picture is boring. Get it anywhere else, and all bets are off. Below is the full breakdown, including the cases where official Signal is simply the better call.
What "safe" can mean for a chat app
When people ask whether an app is safe, they usually mean one of three different things, and it helps to separate them. First: is the code honest? Can anyone verify what the app actually does, or do you have to take the developer's word for it? Second: is the cryptography sound? Are messages actually end-to-end encrypted with a protocol experts trust? Third: is the download genuine? Is the file on your phone the one the developers published, unmodified?
Molly scores well on the first two by construction. Its code is open-source, published for anyone to read, which is the strongest form of the first claim an app can make. Closed-source apps ask for trust; open-source apps allow verification. And the cryptography question is settled by the fork relationship: Molly speaks the same Signal protocol as the official app, so its encryption properties are the protocol's properties, not something a small team reinvented. The third question, the download, is where you do the work, and it gets its own section below.
Open-source does not mean "reviewed by thousands of experts", by the way. It means review is possible. That distinction matters, and anyone who tells you open code automatically equals secure code is selling something.
Who builds Molly, honestly
Molly is built and maintained by independent developers. It is not a product of Signal Foundation, it is not endorsed by Signal, and it has nothing like Signal's team size or funding. Saying that is not an insult; it is the central fact of the trust decision, and the developers themselves do not pretend otherwise.
What the small team means in practice: Molly's releases follow Signal's with a gap. When Signal ships a new version, the Molly developers have to review the changes, apply their modifications, and publish their own builds. That takes time, so Molly users wait longer for new features and, more importantly, for fixes. The gap is usually described in qualitative terms, days to weeks, not a fixed schedule, because it depends on how big each upstream change is. If you are the kind of person who wants security fixes the hour they ship, that lag is a genuine cost, and official Signal is the better fit for you.
The smaller team also means a narrower support surface: the fork's own issue tracker and documentation rather than Signal's support operation. For straightforward use this rarely matters. For weird bugs it can mean slower answers. Neither of these is a reason to call Molly unsafe; they are reasons to understand what you are choosing. For background on the fork itself, see what Molly is.
The real risk: who builds it, not the code
Here is the uncomfortable truth about every popular open-source app: the code being clean does not help you if the file you installed was not built from that code. Attackers know people search for "Molly APK download", and they build lookalike sites that serve modified installers, bundle the real app with spyware, or simply take you to an unrelated download. This is not theoretical. It is the standard playbook for every sought-after app distributed outside the Play Store.
The defense is simple and absolute: molly.im or its official F-Droid repository, and nothing else. The official site is Molly's official site; the F-Droid repository is at Molly's official F-Droid repository. If a site offers you a "Molly Pro", a "Molly Plus", a modded build with extra features, or any Molly download from a file mirror, close the tab. There is no pro version. There is no plus version. Those do not exist, and anything wearing those names is either a scam or malware. Our Molly install guide walks through the safe sources step by step, and the same warning applies to official Signal downloads, covered in our APK mirror warning.
One more supply-chain habit: be suspicious of any page that claims to be the "official Molly site" at a different domain. Molly's developers publish from molly.im. Anything else claiming official status is lying to you.
Molly is distributed by its own developers. The only safe sources are the official site and its official F-Droid repository.
Open molly.imF-Droid users: add molly.im/fdroid as a repository instead.
The encryption is the same Signal protocol
Molly connects to the same Signal network and speaks the same protocol as the official app. Your messages are end-to-end encrypted the same way, your calls use the same setup, and your contacts cannot tell which app you use. The fork changes the app around the protocol: notification plumbing, database encryption options, build configuration. It does not reimplement the cryptography.
That is worth understanding clearly, because it bounds both the praise and the criticism. Molly is not "more encrypted" than Signal; the encryption is identical. And the realistic attack surface a fork adds is in the surrounding code, the build process, and the update channel, not in the message encryption. If someone tells you Molly is safer because of its encryption, or less safe because of its encryption, they have misunderstood what a fork is. Compare the two apps directly in Molly vs Signal.
Can you trust Molly? It depends what you're protecting
"Is it safe?" is the wrong question without "safe for whom, against what?" Here is the honest version:
| Your situation | Verdict | Why |
|---|---|---|
| Everyday user who wants private messaging | Molly from molly.im is fine | Open code, same protocol, sane defaults. The fork lag is a minor cost. |
| Phone without Google services (Huawei, GrapheneOS) | Molly-FOSS is the natural pick | The FOSS build exists precisely for this case; see Molly on Huawei. |
| Journalist, activist, or anyone with real adversaries | Think carefully; official Signal may fit better | The release lag and smaller review surface matter more when the stakes are high. Consider your whole setup, not just the app. |
| Someone who wants fixes the day they ship | Use official Signal | No fork can beat upstream's release speed. This is structural, not a criticism. |
| Someone who downloaded Molly from a random mirror | Unsafe until proven otherwise | Uninstall it, get the real build from molly.im, and treat the old install as compromised. |
Notice what this table does not say: it does not say Molly spies on you, and it does not say Molly is magically safer than Signal. Both of those claims would be FUD or cheerleading. The truth is duller: it is a competent fork with a small team, and your experience of its safety will be dominated by where you downloaded it and whether its trade-offs match your situation.
Red flags to avoid
- Any "official" claim about Molly. Molly is independent and says so. A site calling itself the official Molly anything, at a domain other than molly.im, is not to be trusted.
- Modded or "enhanced" builds. Extra features, unlocked anything, themes bundled with the APK: these are the classic wrappers for malware.
- Paid versions. Molly is free and open-source. Anyone charging for the app is scamming you.
- Download buttons on tutorial blogs and forums. Read the tutorial, fine. But take the download link only from molly.im itself. Third-party mirrors are where tampered APKs live.
- Permission or behavior surprises after install. A messaging app has no business asking for accessibility access or device-admin rights. If your Molly install does, something is wrong with that install.
from Signal's official site (file hosted by Signal, not by us)
The bottom line: Molly's safety story is good but not magical. Open code you can inspect, the same proven protocol as Signal, a small honest team, and one non-negotiable rule about where you download it from. Match the tool to your threat model, keep the download source clean, and there is nothing to be afraid of. If any part of that feels like too many conditions, official Signal is right there, and there is no shame in choosing it. Read our safety guide for the official APK for the other half of the picture.
Frequently asked questions
Is Molly affiliated with Signal Foundation?
No. Molly is an independent fork built by third-party developers. It is not made by, endorsed by, or affiliated with Signal Foundation in any way.
Is it legal to use Molly?
Yes. Molly is open-source software that connects to the Signal network using the public protocol. Using an independent client is not illegal; it is simply unofficial.
Can Molly read my messages?
Molly uses the same Signal protocol with the same end-to-end encryption as the official app. Messages are encrypted on your device and can only be read by you and the recipient. The code is open-source, so this is verifiable rather than a promise.
Why does Android warn me when installing Molly?
Android warns about any app installed outside Google Play, including perfectly legitimate ones. The warning is about the install source, not a verdict on Molly. Verify you downloaded it from molly.im and proceed.
Is Molly on F-Droid safe?
Yes, provided you add the official Molly repository at molly.im/fdroid. F-Droid builds from published source, and using the developers' own repository removes mirror risk.
Should I use Molly or official Signal?
Use Molly if you have a specific reason: no Google services on your phone, or you want its extra features like database passphrase encryption. Otherwise official Signal is simpler, updates faster, and has full official support.
Keep reading
- What is Molly? The fork explained: who makes it and why it exists
- Molly vs Signal: head-to-head comparison
- Install Molly safely: the verified safe install path
- APK mirror warning: why third-party mirrors are dangerous
- Molly's source code: public, open, and checkable