On 23 July 2026, India's Cyber Crime Coordination Centre — a unit of the Union Home Ministry — ordered GitHub to remove three repositories hosting Bitchat, and gave GitHub three hours to do it. Bitchat is the Bluetooth-mesh messenger Jack Dorsey open-sourced in 2025: no servers, no accounts, no phone numbers. The order arrived days after authorities shut down mobile internet in parts of central Delhi following a protest march. Dorsey's response, in full: "the government of india does not like technologies like bitchat and wants it taken down." He's right — and the attempt tells you more about the limits of censorship than about Bitchat.
The one-sentence version: India didn't order Bitchat's network shut down, because there's nothing to shut down — a Bluetooth mesh has no central server, company, or phone-number registry a government can reach. So it went after the next-best chokepoint, the source code on GitHub. That gap — between the thing they want to stop and the only thing they can actually touch — is the entire case for decentralized messaging.
Why this is a privacy story, not just an India story
Because it's the cleanest real-world demonstration of a principle we come back to constantly on this show: centralization is the attack surface. Every messenger most people use — WhatsApp, Signal, Telegram, iMessage — has a company behind it, servers somewhere, and usually a phone number tied to your account. Those are conveniences, and they're also levers. A government that wants to stop the conversation has something concrete to grab: block the servers, subpoena the company, cut the network, demand the registry. Bitchat was built specifically so that none of those levers exist. Watching a state actually try to censor it, and reach for a code repository because that's all that's within reach, is the argument making itself.
What actually happened
The order came from the Indian Cyber Crime Coordination Centre (I4C), citing Section 79(3)(b) of the IT Act — the provision that lets the government require an intermediary to take down content. The target was three GitHub repositories associated with Bitchat, with a three-hour compliance window.
The stated reasoning is worth quoting closely, because officials were unusually candid about what bothered them. The order objected that Bitchat's design enables "anonymous communication without registration, phone numbers or centralized logging," and that this architecture "significantly impedes lawful interception, attribution, and investigation by law enforcement agencies." It warned that "such decentralized communication platforms are capable of being exploited for coordinating unlawful assemblies, violent protests, dissemination of misinformation, radicalization, criminal conspiracies."
Read that again. The complaint isn't that Bitchat did something — it's that Bitchat can't be wiretapped. The objection is to the property, not to any specific abuse of it. And the timing matters: the notice followed mobile-internet shutdowns in central Delhi after a protest march on 20 July. An app whose entire selling point is that it works when the internet is off is, unsurprisingly, the app a government reaches for when it has just turned the internet off.
For the record: as of the reporting, Bitchat remained available on the Apple and Google app stores, and GitHub's compliance was unclear. Even a "successful" takedown of a few repositories doesn't unpublish an open-source project that has already been cloned, forked, and mirrored thousands of times. Which is the point.
How Bitchat actually works
To see why the takedown is aimed where it is, you have to understand what there is — and isn't — to censor.
Bitchat relays encrypted messages phone-to-phone over Bluetooth mesh, hopping through nearby devices (up to seven hops) to reach people out of direct range. No internet connection is required, no servers are involved, and there are no accounts, no phone numbers, and no persistent identifiers. Messages on the mesh are encrypted with the Noise Protocol with forward secrecy; your cryptographic identity rotates by location, so there's no stable handle to track. There's an emergency wipe — triple-tap to clear everything — for the moment a device is about to be taken. When the internet is available, it can fall back to Nostr, a decentralized relay protocol spread across hundreds of independent servers worldwide, with its own layer of encryption.

Put those pieces together and the censorship problem becomes obvious. There is no company headquarters to serve, no server farm to null-route, no account database to compel, and no phone-number list to cross-reference. If two phones are in Bluetooth range, they can talk, and no third party is in the loop to stop them or even to know it happened. The only points a state can touch are the places the software is distributed from — the app stores and the code host. So that's exactly where the order landed.
The thing worth sitting with
Here's the asymmetry that makes this important. Blocking a distribution channel is a one-time, leaky, easily-routed-around action. Blocking a network — the way a government blocks a cellular carrier or a website — requires a central thing to block. Decentralized protocols delete the central thing on purpose. That doesn't make them un-censorable; it moves the censorship upstream to distribution, where it's far weaker, and it raises the cost of stopping the conversation from "one order to one company" to "find and neutralize every copy, everywhere, forever."
This is not a new lesson, it's a recurring one. During the 2019 Hong Kong protests, demonstrators leaned on Bridgefy and other Bluetooth-mesh tools precisely because the authorities could throttle the mobile network but not the air between two phones. Meshtastic does the same thing over long-range radio. Briar routes over Tor and can fall back to Bluetooth and Wi-Fi when the internet is cut. The through-line is always the same: when the network has an off switch, someone will eventually flip it — so the resilient designs are the ones that don't have one.
And it's worth being honest about the flip side, because the Indian order leans on it. Yes, a tool nobody can wiretap can be used by people you'd rather it weren't. That's true of every strong-privacy technology ever built, including the encryption protecting your bank login. The question is never whether a capability can be misused — everything can — but whether the answer to potential misuse is to engineer a surveillance chokepoint into the tools everyone else depends on. We've watched that argument play out with the EU's Chat Control fight and the UK's Online Safety Act. India just made the same argument in its bluntest possible form: we don't like that we can't listen.
Why it matters more now than ever — and what to actually do
The reason to care about decentralized messaging isn't that centralized apps are bad. Signal is excellent, and for most people, most of the time, it's the right tool. The reason is that resilience is a property you have to build before you need it. The moment you actually need a mesh messenger — the network's down, the app store's been leaned on, the servers are blocked — is precisely the moment you can no longer download one. Diversity in how we can communicate is like any other kind of preparedness: worthless if you start assembling it during the emergency.
So, concretely: if you care about this, the useful moves are the unglamorous ones. Install and actually try a mesh or serverless messenger now — Bitchat, Briar, Meshtastic if you're willing to carry the hardware — so it's on your device and you know how it works before it matters. Mirror and fork the open-source projects you value; a takedown of three repositories is meaningless against ten thousand copies, and every clone is a small act of preservation. Support the protocols, not just the apps — Nostr, Matrix, and the like — because a protocol with many independent implementations has no single door to kick in. And keep the distinction that this whole story turns on close at hand: a company can be compelled, a server can be seized, a network can be switched off, but a protocol that lives on everyone's devices at once has no one address for a takedown notice.
India didn't ban a network this week. It filed paperwork against a copy of some source code and told the world it wished the mesh had an off switch. It doesn't. That's the good news, and it's worth defending.
Sources & further reading
- CoinDesk — India orders takedown of Jack Dorsey's bitcoin-linked messaging app Bitchat: https://www.coindesk.com/tech/2026/07/24/india-orders-takedown-of-jack-dorsey-s-bitcoin-linked-messaging-app-bitchat
- The Wire — Government asks GitHub to remove Bluetooth messaging app Bitchat over concerns of 'misuse': https://m.thewire.in/article/government/government-asks-github-to-remove-bluetooth-messaging-app-bitchat-over-concerns-of-misuse
- ANI — Govt orders GitHub to disable access to Bluetooth mesh messaging app Bitchat: https://www.aninews.in/news/business/govt-orders-github-to-disable-access-to-bluetooth-mesh-messaging-app-bitchat20260724164955/
- Bitchat — project README and whitepaper (permissionlesstech): https://github.com/permissionlesstech/bitchat
- Access Now — #KeepItOn internet shutdown tracker (India context): https://www.accessnow.org/campaign/keepiton/
If you want the fast version in your ears, this'll be a segment on an upcoming episode of Closed Network.
— Simon