Signal forks: the real ones, and the fakes to avoid

Published: October 7, 2026 · Updated: October 8, 2026

Signal's open-source license means anyone can fork it, and a small number of community forks exist beyond Molly. Molly is the established one we can describe with confidence; the rest of the landscape is small projects that come and go. The bigger story on this page is the fakes: malware-laden clones calling themselves "Signal Pro," "Signal Plus," or similar, which are not forks at all. This page maps the real landscape, teaches you to tell a genuine fork from a fake, and gives you a checklist for evaluating any fork you encounter.

Illustration of one Signal chat bubble splitting into branches, with a warning sign on the fake branches

The real fork landscape

Signal's Android client is published under the AGPLv3 license, which explicitly permits forking. So forks are legal and normal. What is unusual is how few serious ones exist. Messaging forks are hard to maintain: every upstream Signal release has to be merged, built, tested, and shipped, which is a treadmill of work for a volunteer team. Most fork attempts stall within a year or two.

The landscape, honestly described: Molly is the established, maintained fork, and it is the only one we describe in detail on this site. Beyond it, there are small community experiments that appear, get a few releases, and fade. We do not name them here, deliberately: a fork that was alive last year may be dead now, and recommending software we cannot verify today would be irresponsible. The right way to think about the landscape is not a catalog of names but a skill: knowing how to evaluate whatever fork you find. That skill is the core of this page.

Why so few? Because a fork has to justify its own existence. Molly exists for a clear reason: Google-free notifications and extra at-rest encryption for de-Googled phones. A fork that changes nothing meaningful is not a project, it is a rebrand. When you find a fork, the first question is always: what does this change, and is that change worth the fork's costs? Our honest case for and against using a fork works through that question for the strongest candidate.

Key points: The real fork landscape
Key points: Signal's Android client is published under the AGPLv3 license; So forks are legal and normal.; What is unusual is how few serious ones exist..

Why Molly is the reference fork

Molly earns its position as the reference fork on structure, not hype. Its source code is public. Its builds are reproducible, meaning you can verify the distributed APK was built from the published code. It publishes its own signing keys and release notes. It is distributed from its own site, molly.im, and its own F-Droid repository. These are the structural markers of a genuine fork, and they are also the checklist we apply to everything else.

Molly is also honest about what it is: an independent project, not official Signal, not affiliated with Signal Foundation. That honesty is itself a trust signal. Forks that blur the line, that let users believe they are "the real Signal" or "Signal, improved by the company," are telling you something about their ethics before you install anything.

None of this makes Molly perfect. It trails Signal's releases, it has a smaller team, and it has no official support. But those are disclosed tradeoffs of a real project, not hidden risks. The what-is-Molly explainer and Molly vs Signal comparison cover the project in full.

The fakes: "Signal Pro" and friends

Now the dangerous part. Search for Signal on shady corners of the internet and you will find "Signal Pro," "Signal Plus," "Signal Premium," and similar names. These are not forks. They are scams. There is no Pro version of Signal. There is no Plus, no Premium, no unlocked edition. Signal is free and open-source, and Signal Foundation ships exactly one Android app. Anything else wearing the name is either malware or a lure for it.

How the scam works: the fake app looks like Signal, asks for the same permissions a messenger needs (contacts, microphone, storage), and then does whatever its maker wants. That can mean stealing messages, harvesting contacts, enrolling your phone in fraud, or simply showing ads while doing nothing. Because a messenger legitimately needs deep permissions, a fake messenger is one of the most dangerous apps you can install. The permissions are the payload's cover story.

The fakes also borrow the fork's language. "Based on the official source," "open source," "no ads," "extra features": the words are cheap and the claims are unverifiable. A real fork proves its claims with published code and reproducible builds. A fake asserts them on a download page with no repository link. That difference, provable versus asserted, is the whole game. Our Signal Pro scam breakdown and fake Signal APK guide document the scam patterns in detail.

How to evaluate any fork: the checklist

When you encounter a fork, run it through this checklist before it touches your phone. Every row is a question with a right answer. A real fork answers all of them; a fake fails at the first one.

QuestionWhat a real fork showsWhat a fake shows
Is the source code published?A public repository you can read todayNo repository, or a dead link, or "coming soon"
Are builds reproducible?Documented process to verify the APK matches the codeNo mention of it, or vague claims
Who signs the releases?Published signing keys belonging to the projectUnknown signer, or keys that change without notice
Where is it distributed from?The project's own site and its own channelsRandom mirrors, file hosts, Telegram channels
Is it honest about not being official?Clearly labeled independent, no affiliation claimedImplies it is official, "improved," or endorsed
Does it promise a "Pro" version?Never; forks of a free app have no Pro tier"Pro/Plus/Premium" is the product
Is it maintained?Recent releases tracking upstream SignalMonths or years stale, or version numbers that make no sense

A fork that passes this table is worth considering on its merits. A fork that fails any single row is not worth your messages. Note how the table never asks about features: features are the last thing to evaluate, because a malicious app can promise any feature list it wants. Structure first, features last.

Comparison chart: How to evaluate any fork: the checklist
What a real fork s vs What a fake shows.

Red flags that mean "walk away"

Some signals are so strong they end the evaluation immediately. If you see any of these, close the tab.

Trust the red flags over your curiosity. The upside of a random fork is a slightly different app; the downside is a compromised phone. That asymmetry means the correct error direction is caution, always.

Checklist graphic: Red flags that mean "walk away"
Checklist: The name includes Pro, Plus, Premium, Unlocked, or Mod., It is only on a mirror site., No source code anywhere., It asks for money., Reviews or ratings that look bought..

Where to get a real fork

The rule is boring and absolute: get a fork from the fork's own site, and nowhere else. Molly comes from molly.im and its F-Droid repository. Any other fork worth using will have an equivalent home: its own domain, its own repository, its own release notes. If you cannot find the project's home, you have not found a project.

Never get a fork from an APK mirror, a file host, a forum attachment, or a messaging channel forward. Mirrors are where fakes live and where real builds get trojaned. This is not paranoia; it is the threat model. A privacy app is the worst possible thing to install from an untrusted source, because the permissions it needs are exactly the permissions malware wants.

And if the fork question is really "should I just use the official app," the answer for most people is yes. Official Signal from signal.org is the simplest, fastest-updated, best-supported option. Forks exist for specific needs; if you do not have those needs, the official app is not the boring choice, it is the right one.

Get Molly from molly.im

from the fork's own site (file hosted there, not by us)

Frequently asked questions

Are there Signal forks besides Molly?

A few small community forks exist, but Molly is the established, maintained one we can describe with confidence. Smaller forks come and go; evaluate any fork you find with the checklist on this page rather than trusting a name.

Is 'Signal Pro' real?

No. There is no Pro, Plus, or Premium version of Signal. Those names belong to fake apps, often carrying malware. Signal is free and Signal Foundation ships one Android app.

How can I tell a real fork from a fake?

A real fork publishes its source code, offers reproducible builds, signs releases with published keys, distributes from its own site, and is honest about not being official. A fake fails these checks and usually promises a 'Pro' version.

Where should I download a Signal fork?

Only from the fork's own site and its own distribution channels (for Molly: molly.im and its F-Droid repository). Never from mirrors, file hosts, or forwarded files.

Is using a fork legal?

Yes. Signal's open-source license explicitly permits forking. What is not legal is a fake pretending to be official or bundling malware, which is a different thing entirely.

Keep reading