finds.dev← search

// the find

permissionlesstech/bitchat

★ 36,455 · Swift · Unlicense · updated Oct 2026

bluetooth mesh chat, IRC vibes

bitchat is an iOS and macOS messenger that routes messages over a Bluetooth LE mesh when peers are physically nearby and over Nostr relays when they are not, with geohash-based location channels for public chat. There are no accounts or phone numbers. It is aimed at people who need messaging to keep working without carrier or internet infrastructure, such as at protests or after a disaster.

The threat model is written down rather than implied: WHITEPAPER.md and the README state what a nearby radio can observe and that store-and-forward mail is sealed without forward secrecy, which is more candor than most privacy-focused apps offer. Live direct messages use Noise Protocol sessions with forward secrecy, the right primitive for mesh chat. The BLE layer is split into many small single-purpose files, such as the fanout selector, fragment assembly buffer, relay spool, and link state store, which keeps each piece readable on its own. The build and CI setup is more than a demo would bother with: a Justfile, a SwiftPM test target, an iOS simulator test scheme, periphery and swiftlint configs, and workflows that include a source manifest and provenance check.

The Nostr private-envelope format is proprietary. The README says it is not NIP-17, NIP-44, or NIP-59 compatible and uses a custom XChaCha20-Poly1305 construction, so it interoperates only with bitchat clients and needs its own cryptographic review instead of inheriting the Nostr ecosystem's scrutiny. The mesh uses a persistent per-device identifier derived from the identity key, and the README concedes that a nearby radio can observe it, so this is not anonymity against a local adversary. Mesh reach stops at multi-hop BLE range (7 hops at most), so a sparse crowd means no delivery, and the Nostr fallback depends on a list of 440+ third-party relays that each see metadata. Verification is left to the user: the README admits a build from anywhere but the App Store or the release manifest cannot be verified, the Android client is distributed separately with no build path described here, and the repo has already faced takedown demands, so the source may not stay where you found it.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →