Open-source project
mollyim/mollyim-android avatar
mollyim/mollyim-android

Molly for Android: a hardened Signal fork with passphrase encryption and UnifiedPush

Enhanced and security-focused fork of Signal.

3,746 stars212 forksKotlinAGPL-3.0

At a glance

What is it?
Molly is an AGPL-3.0 Android fork of Signal that restores passphrase encryption for the local database and adds UnifiedPush, Tor, and a secure RAM wiper. It is for Signal users who want those controls and accept that the app still talks to Signal's servers.
Who is it for?
Adopt Molly if you use Android, want passphrase encryption for the local database, and are willing to run a MollySocket server for UnifiedPush. Do not adopt it if you need iOS, or if you want to leave Signal's servers.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Molly adds to Signal, and who it is for

Molly is a fork of Signal-Android maintained under the mollyim organization and licensed AGPL-3.0. The README frames the project's origin narrowly: Signal once let users set a passphrase to secure the local message database, and that option disappeared when Android moved to file-based encryption. Molly brings it back and layers other controls on top.

The audience is therefore not "anyone who wants a messenger." It is an Android user who already trusts Signal's protocol and server model but wants more control over the device side: encryption at rest for the app database, a secure RAM wiper, automatic lock, custom backup scheduling, SOCKS proxy and Tor support through Orbot, and the ability to block messages and calls from unknown senders. Molly also adds disappearing call history and optional debug logs, meaning Android logging can be turned off.

One point is easy to misread. Molly connects to Signal's servers, so conversations still route through Signal's infrastructure and the Signal Terms and Privacy Policy apply. This is a client-side hardening fork, not a different network.

How the fork tracks upstream Signal

The README states that Molly is updated every two weeks to include the latest Signal features and fixes, with security patches applied as soon as they are available. That cadence is the core architectural fact about the project: Molly is a downstream fork that rebases onto upstream Signal-Android rather than a rewrite.

That choice shapes everything else. The repository layout mirrors an Android app rather than a library: app/, core/, core-gms/, feature/, lib/, build-logic/, buildSrc/, lintchecks/, fast-lint/, baseline-profile/, plus build.gradle.kts and settings.gradle.kts at the root. The two product flavors that the README describes, Molly and Molly-FOSS, are the visible consequence of the split between builds that include proprietary Google blobs and builds that do not. The core-gms/ module name reflects the same divide.

The features that make Molly distinct are not a rewrite of Signal's messaging layer. Passphrase encryption, the RAM wiper, automatic lock, and the proxy and Tor options are additions on top of an inherited codebase. That is why the project can claim full backup compatibility and why a Signal user can migrate without re-registering.

Installing Molly on Android from F-Droid or GitHub Releases

The README gives two supported distribution routes: the GitHub Releases page and the Molly F-Droid repository at molly.im/fdroid. Molly-FOSS is additionally available from Accrescent. There is no Play Store listing in the README.

Before installing anything, decide which flavor you want. Molly-FOSS ships without proprietary blobs and uses OpenStreetMap for location sharing; the standard Molly build uses Google Maps. Both support WebSocket and UnifiedPush push notifications, while standard Molly also supports FCM.

To install from the F-Droid repository, add the repo URL in the F-Droid client:

bash
https://molly.im/fdroid/

After refreshing the repository index, search for Molly and pick the flavor you decided on. Installing one flavor replaces the other; the README says data and settings are preserved so you do not have to re-register.

The README also publishes signing certificate fingerprints for APK verification, using the Android apksigner verify command:

bash
SHA-256: 6aa80fdf4a8cc13737cfb434fc0cde486f09cf8fcda21a67bea5ee1ca2700886
SHA-1:   49ce310cdd0c09c8c34eb31a8005c6bf13f5a4f1

Compare the output of apksigner against those values before you trust a downloaded APK. For a first real use, install Molly alongside Signal, register it as a linked device if you want to keep the same phone number, then open the data encryption at rest settings and set a passphrase. The README links a wiki page, Data-Encryption-At-Rest, for that step; the README itself does not document what happens if you forget the passphrase.

Two builds, two trade-offs: Molly versus Molly-FOSS

The feature table in the README is short and worth reading literally. On push notifications, Molly-FOSS offers WebSocket and UnifiedPush, while Molly offers FCM as well as WebSocket and UnifiedPush. The warning marker next to FCM indicates a dependency on Google's proprietary service, not a missing capability. On location sharing, Molly-FOSS uses OpenStreetMap and Molly uses Google Maps, again marked as proprietary.

The practical consequence is that Molly-FOSS is the auditable build and the standard Molly build is the convenience build. If your phone has no Google services, Molly-FOSS is the only coherent option. If you want Google Maps inside the app, you are choosing the build with proprietary components, which is the thing the project set out to avoid in its FOSS flavor.

There is a footnote on push notifications: you may need to turn off system-level battery restrictions for the app to receive messages when it is not open. That is a general Android behavior rather than a Molly defect, but it is the kind of thing that produces "messages arrive late" reports.

UnifiedPush needs a MollySocket server, and that is the real cost

UnifiedPush is the most interesting feature here and the one with the clearest operational burden. The README describes it as an open standard for push notifications and a privacy-friendly alternative to Google's FCM, letting users choose their own notification distributor.

It does not work on its own. The README states that using UnifiedPush requires access to a MollySocket server to link your Signal account to UnifiedPush, and that you can either run MollySocket on a server you control, which the project strongly advises, or use a public instance. So the honest description of the feature is: Molly gives you the client side, and you supply the infrastructure.

There is a second constraint. The README says UnifiedPush is currently unavailable for linked devices. If you registered Molly as a linked device to share a phone number with Signal, you cannot use UnifiedPush on that install. That combination, linked device plus UnifiedPush, is the case where Molly is the wrong tool, and the README does not offer a workaround.

Backups, migration and what the README leaves open

Backups are fully compatible in both directions. Signal backups can be restored in Molly and Molly backups in Signal, by choosing the backup folder and file. One condition applies: to import a backup from Signal, you must use a matching or newer version of Molly. That version rule is the single most likely source of a failed restore, and it is stated plainly.

Migration for an existing Signal user goes through a wiki page, Migrating From Signal, which the README points to rather than summarizing. This is where the documentation is thinnest relative to the risk. The README does not document rollback, does not describe what happens to an existing Signal installation if a migration step fails, and does not explain the passphrase recovery story for data encryption at rest. Those are the questions a cautious user asks first, and the README is silent on them.

What the README does cover is coexistence. Molly and Signal can be installed on the same device. If you need a second number, register Molly with a different number while Signal stays active; any number that can receive SMS or calls works. If you want the same number on both, register Molly as a linked device, because registering the same number independently on both apps leaves only the most recently registered app active and the other offline.

Building Molly yourself and the licence you inherit

For engineers who want to verify the binary, the repository is set up for reproducible builds. The README advertises a reproducible build badge, and the repository contains a reproducible-builds/ directory, a Dockerfile, a Makefile, a BUILDING.md, and a .tool-versions file.

The Dockerfile pins its base image by digest and installs the Android toolchain from a checksummed SDK archive: the command line tools zip is verified with sha256sum before extraction, and the build uses NDK 28.0.13004108, build-tools 36.0.0, and compile SDK android-36.1. The Makefile is the entry point for the Docker builder image and exposes four targets: help, assemble, test, publish, clean, with TARGET_PLATFORM defaulting to android and platform logic in mk/android.mk.

bash
make help
make assemble

On licensing, Molly is AGPL-3.0, the same family as Signal-Android. If you fork Molly or run a modified version as a network service, the AGPL's source-availability obligations are the thing to read, and LEGAL.md and NOTICE are the files in this repository to read them in. This is a description of what the repository contains, not legal advice.

Editorial conclusion

Adopt Molly if you use Android, want passphrase encryption for the local database, and are willing to run a MollySocket server for UnifiedPush. Do not adopt it if you need iOS, or if you want to leave Signal's servers. Verify the APK signature fingerprint and confirm that your Signal backup version is not newer than the Molly build you install.

Frequently asked questions

How safe is Molly Signal?

Molly adds client-side hardening to Signal: passphrase encryption for the local database, a secure RAM wiper, automatic lock, and optional disabling of Android debug logs. It still connects to Signal's servers, so the Signal Terms and Privacy Policy apply. The README does not document passphrase recovery, so treat the passphrase as unrecoverable.

What is the Molly app used for?

It is an Android messaging app used to chat with Signal contacts while adding security features Signal no longer offers, such as passphrase encryption of the local message database. It also supports UnifiedPush notifications, Tor and SOCKS proxying, and blocking unknown contacts.

How do I install Molly on Android?

Download the APK from the GitHub Releases page or add the Molly F-Droid repository at https://molly.im/fdroid/ and install from there. Molly-FOSS is also available from Accrescent. Verify the APK against the SHA-256 and SHA-1 signing certificate fingerprints published in the README.

What is the difference between Molly and Molly-FOSS?

Molly-FOSS ships without proprietary Google blobs and uses OpenStreetMap for location sharing; standard Molly includes FCM push notifications and Google Maps. Both flavors support WebSocket and UnifiedPush notifications. You can switch flavors and keep your data and settings without re-registering.

Can I use Molly and Signal with the same phone number?

Yes, but only by registering Molly as a linked device. Registering the same number independently in both apps leaves only the most recently registered app active and the other offline. UnifiedPush is not available for linked devices.

Official sources

  1. Issues
  2. License: AGPL-3.0
  3. mollyim/mollyim-android on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mollyim-mollyim-android.svg)](https://hysenlabs.com/projects/mollyim-mollyim-android)