Kryptos

Kryptos

You encrypt right inside the chat with the Kryptos keyboard, and what arrives is read right on your screen. Only your contact can make sense of the code, in any messenger, even SMS.

iPhone and Android understand each other. No accounts, no servers, no setup, and the keys never leave your phone.

Download for iOS .ipa file or repository
Through the repository No certificate, just your Apple ID. Updates come on their own.
https://datakeeper.pages.dev/altstore.json
Download for Android .apk file or F-Droid

iOS: the .ipa is unsigned, you sign it on the device. Android: allow installs from unknown sources.

Open source github.com/swisslite/Kryptos Support the project
SHA-256 checksums

.ipa  8c95a263b3d2d88e8b9b94df05ae7d0e360dc4ba9f9c98f3a28e96387c33a43b
.apk  66c6fbf2f38013d6a2020e4324d4cc80e71559299f74fe66a8577bef68340f77

Version history

2.3.2
2.3.2 August 17, 2026 Latest

What is new

  • Chinese.
  • Profanity, insults and potentially dangerous words are out of all three text steganography modes, in English, Russian and German.
  • 197 such words were removed from the dictionaries and the same number of neutral ones added, so each language still holds 4,096 words.
  • The smart-sentence grammar had 11 words replaced.
  • In the random-letter mode the text is now picked so that no forbidden letter combination appears in it.
  • The Paste and Clear buttons in the keyboard message field are bigger and sit in one row under the field.
  • The size of the keyboard message field is adjustable: small, medium or large.
  • The Kryptos badge on the keyboard can be hidden, and the space it frees goes to the profile and contact labels.
  • Send after encrypting now works in messengers that send with their own button, VK for one.
  • That kind of sending needs the Kryptos on-screen decryption service switched on. Android turns the service off when the app is updated, so switch it on again.
  • A profile can be renamed, any one from the list and not only the current one.
  • A contact can be renamed from the chat list and from the chat menu.
  • A long press on a message in a chat opens a menu with copy and delete.
  • A deleted message is wiped completely: its text no longer shows up in on-screen decryption or in the keyboard.
  • If the storage of one profile cannot be read, the app opens on a working profile and says which profile is unavailable.
  • A failed attempt to open a profile no longer offers to erase all data.
  • Other changes.
  • Covers made by the ordinary-words and smart-sentences modes cannot be read by versions before 2.3.2, so both sides have to update.

Fixes

  • Send after encrypting did not send the message in messengers with their own send button: the text was encrypted and pasted but stayed in the field.
  • The keyboard closed after an encrypted message was sent and had to be called up again.
  • The Paste button did nothing with an empty clipboard and said nothing about it.
  • The area under the keyboard was filled with black instead of the keyboard colour.
  • Switching to a profile with damaged storage closed the app, after which it would only open on the erase-everything screen, even though the keys and the chats were intact.
  • Switching to such a profile from the keyboard silently substituted the contacts and chats of the previous profile and wrote them into the storage of the new one.
  • Storage failures while creating, deleting or renaming a profile, regenerating its key or working with PGP keys closed the app instead of reporting an error.
  • The app could create a new encryption key over existing data and make it unreadable for good.
  • The password stayed in memory after the key had been derived.
  • A copied message was marked as shown even when the keyboard could not open it because of the lock screen, and after unlocking it never appeared.
  • Send after encrypting could press the send button while the app was locked.
  • Words learned by the keyboard were lost for good if they could not be saved.
  • The first send of a message hidden in text froze the interface for about 0.1 seconds.
  • The emoji panel read from storage as it opened and could stutter.
  • Hiding a message in a photo used 80 MB more memory than it needs.
  • Saving a photo with a hidden message could silently do nothing.
  • Settings could open straight on the panic-password screen after the app was restarted.
  • Regenerating a key did not show which profile it was being done for.
  • Other changes.
2.3.1 August 9, 2026

What is new

  • The app is fully translated into German.
  • Keyboard: a QWERTZ layout with ä ö ü ß and its own dictionaries (40,000 frequent words, 177,000 word forms, 640 bigrams), with suggestions and autocorrect at the same level as Russian and English. Nouns are suggested capitalised, the case taken from a corpus that preserves it.
  • Steganography in all three modes: a 4,096-word list, smart-sentence grammar with German word order and cases, and the random-letter mode.
  • The suggestion engine went from two languages to an arbitrary number.
  • The keyboard declares three layouts in the system input-language switcher, and picking one there switches the layout inside the keyboard.
  • Length masking now works in steganography too, in all three modes and all languages. Before this the switch did nothing once steganography was on, and the length of the text could be read straight off the length of the cover.
  • A new keyboard mode on Android: the padlock encrypts the message and sends it in the messenger right away, and a paper-plane badge appears on the padlock. Off by default, switched on in Settings → Keyboard.
  • Other changes.

Fixes

  • Confirmation popups ("Erase all" and ten more dialogs) no longer appear off to one side, they are anchored to the button that opened them.
  • On-screen stego decryption: a sender name that matched a dictionary word (Weber, Richter, Koch) broke parsing and the message would not decrypt. A second bug: a stray word at the end of the node (a timestamp, "Heute") threw away a message that had already been parsed. Added limited resynchronisation and anchoring on the sentence boundary. Affects every language, not only German.
  • The key preview was not covered by the screenshot block and showed even in password fields: on a screen recording of a "protected" keyboard the typed text could be read character by character.
  • An oversized photo or an oversized backup file crashed the app out of memory instead of returning a clear error.
  • The app stalled on launch once every two days, which is when the Signal keys were being rotated.
  • Opening the app with a long text in the clipboard made the interface lag.
  • Holding backspace with two fingers did not stop the deletion.
  • Switching a PGP key and deleting a recipient froze the screen.
  • The illustrated guide loaded every image at once, now they load as you scroll.
  • The keyboard held twice the memory it needed while loading dictionaries.
  • After a profile switch the keyboard showed the decryption from the previous profile.
  • A corrupted backup file wiped the working PGP keys instead of being rejected.
  • Length masking ate up to half the capacity of a photo while hiding nothing: the size of the shot does not depend on the length of the message. It has been removed from photos.
  • App launch waited for the whole message history to be parsed.
  • The message history was re-encrypted and written again on every launch, even when nothing had changed.
  • Picking a photo decoded the whole shot just for a thumbnail, and hiding and extracting ran on the main thread.
  • Key export and import and PGP operations froze with no progress indicator.
  • Regenerating a PGP key took the algorithm from the new-key form.
  • Deleting a PGP recipient happened without confirmation.
  • The pressed-key highlight disappeared from under the finger after the very first letter.
  • A message you had already read stopped opening again after the next 64 arrived.
  • The wording about being offline in the help was made precise: the app opens no network connections.
  • The green clipboard dot on the decrypt button in the keyboard could swallow the tap instead of the button.
  • Other changes.
  • The stego format has changed: messages with length masking on will not open in older builds.
2.3 August 4, 2026

What is new

  • Panic password. A second password that, instead of unlocking Kryptos, wipes everything for good: profiles and private keys, chats, contact keys, PGP keys, the words the keyboard has learned, caches and settings. Afterwards the app opens empty, as if freshly installed. Set it in Privacy. It replaces the old panic PIN and can now be any password, not only digits.
  • App passcode. An ordinary code to unlock the app when you would rather not use biometrics. Both codes are typed into the same field, so the field itself tells nobody whether a panic password exists.
  • Key backup. Your own keys, your contacts' keys and your PGP keys go into a single password protected file that restores on another phone. The file is encrypted with Argon2id and AES-256-GCM and looks like random data from the outside. Chats are not included.
  • A button on the keyboard itself turns the compose field on and off. It sits on the left of the bar, well away from the encrypt button, stays in sync with Settings both ways and can be hidden.
  • About now has a Source code section linking to the repository, and the contacts moved into a separate Developer section.

Cryptography

  • A password is turned into a key with Argon2id (64 MiB, t=3, p=1, the RFC 9106 profile). PBKDF2 is gone from the project entirely. This covers password mode, photo steganography and the lock screen codes.
  • The two Argon2id implementations, the PHC reference library on iOS and BouncyCastle on Android, are checked against all seven official test vectors and give byte-identical results, so a message crosses between the platforms unchanged.
  • Messages encrypted with a password by an older version can no longer be opened: the password token format has changed.

Steganography in photos

  • The container no longer carries a visible signature or the length at fixed positions. Without the password there is nothing in the photo to test against.
  • Bits go only into textured parts of the picture, roughly its noisiest quarter, and nudge brightness by one instead of replacing the lowest bit. That breaks the classic statistical attacks on LSB.
  • Positions are spread by a keyed stream and the length is masked. A wrong password and a photo with nothing in it are now indistinguishable.
  • Photos made by older versions can no longer be opened: the container format has changed completely.

On-screen decryption and the keyboard

  • The main fix: in real messengers on-screen decryption often found no messages at all, because their text is marked as unimportant for screen readers. It finds them now.
  • The decrypted text appears exactly where the ciphertext is, centred on it and as wide as it. It used to be a small window pinned to the top left corner.
  • The panel no longer flickers or rebuilds itself in a loop, it disappears a fraction of a second after you leave a chat, and it does not show up for a message that has scrolled off the screen.
  • The expand button was redone and now appears when the text is really cut off rather than when it is long, so a long message can no longer be trimmed silently.
  • The decryption window on the keyboard was rebuilt: the contact's name in the title, even padding and corners, and long text scrolls inside the window without closing it.

Security

  • Erasing data and the panic password really do clear the settings now. The settings file used to survive untouched.
  • Code hashes live in encrypted storage and are destroyed by the wipe itself, so nothing is left to show that a code was ever set.
  • Checking a code on the lock screen takes the same time whatever codes exist, so the response time cannot reveal whether a panic password is set. After a few wrong tries the delay grows to 30 seconds.
  • The wipe destroys the storage key first, so a wipe interrupted halfway leaves data that nothing can decrypt any more.
  • The clipboard now clears itself in the background. It used to work only while the app was open, which is not when it is needed.
  • Key backup refuses to export at all if any part of the keys cannot be read, instead of quietly writing an incomplete file, and identifiers from an imported file are validated before they become names in storage.
  • The app signature check now fails closed, and strict biometrics is requested where the system supports it.

Fixes and performance

  • Critical: after a screen lock was removed the app could fail to start at all, because the system destroys the hardware key. It now shows a recovery screen with an explanation and a reset button.
  • Disappearing messages: the chosen interval showed up only after reopening the chat, and messages did not vanish while you watched. There is a live timer now, and expired messages are cleared from the keyboard and on-screen caches too.
  • Fixed a memory leak in the screen scanner and a race during the wipe, and a hardware storage failure during a wipe no longer crashes the app.
  • Typing no longer redraws the whole chat screen, the background stopped allocating memory on every frame, and the device integrity check moved off the main thread.
  • On-screen decryption got lighter: cards are reused and invisible areas are skipped.
  • The design has not changed, verified with screenshots.
2.1.1 July 17, 2026

Fixes

  • On-screen decryption (Android) works again. After the move to the new ciphertext format the detector only recognized a message when it was the only content of a screen element — timestamps, read marks or a sender name glued on by the messenger broke recognition. The token is now found inside any surrounding text.
  • Hidden text (steganography) is more robust on screen and when pasting: stray words next to the message ("edited", "PM", a sender name) no longer break decoding — the decoder ignores them, and integrity is still protected by the checksum.
  • The Back button in a chat now closes the chat instead of the whole app (Android).

Performance

  • The screen scanner is heavily optimized: no extra allocations or repeated pattern compilation in the hot path, dictionaries warm up in the background — less load on the phone and battery while you scroll.
  • Clipboard scanning is capped at a sensible size — a giant copied text can no longer freeze the interface (both platforms).

Design (Android)

  • New floating bottom bar: the active tab expands into a labeled pill, with smooth color transitions.
  • Animated chat open and close with an iOS-style parallax.
  • Live touch feedback: buttons, cards and tabs respond with a springy press.
  • Smooth appearance of messages and banners, animated tab switching.
2.1 July 16, 2026

Security & audit

  • Full security audit of both platforms: crypto core, key storage, keyboards, on-screen decryption, PGP, untrusted input handling.
  • Legacy message formats removed (KX1:, BEGIN KRYPTOS MESSAGE and the old password format). Only the new compact format is read and sent — update Kryptos on both sides, messages from older versions can no longer be read.
  • Less code — smaller attack surface: all dead legacy code stripped, no traces of the old formats left in the binaries.

New ciphertext format

  • Ciphertext is now a single line with no predictable prefixes, indistinguishable from random noise: AES-256-CTR whitening over the real Signal cipher, different output every time, even the message type is hidden.
  • DEFLATE compression before encryption — long messages get noticeably shorter.
  • Password mode: compact token without BEGIN/END, the PBKDF2 iteration count is no longer stored in the ciphertext.
  • Messages are detected by token shape instead of a prefix — everywhere: auto-decrypt, chat, keyboards, on-screen decryption.

Length masking — new

  • A toggle in Settings → Privacy → Metadata (off by default): the ciphertext is padded to fixed buckets (64/128/256…), so its length no longer reveals the size of the message. Works for chat and password mode.
  • The format is self-describing — the recipient strips the padding regardless of their own settings; the token length is exactly the bucket size, and the handshake is masked too.

Reliability

  • Fixed a rare decompression mismatch between iOS and Android; full cross-platform compatibility verified byte-for-byte with test vectors.
  • Bounds checks when stripping padding and decompressing — protection against hangs and corrupted data; minor fixes on both platforms.
  • Expanded test suites: 39 iOS + 47 Android + 10 built-in self-checks — all passing.
2.0 July 15, 2026

What's new

  • Smart text steganography: the hidden message is woven into real, grammatically coherent sentences (EN/RU) instead of a run of words. Enabled with a separate toggle in Settings → Steganography and works alongside the regular mode.
  • The sample output right in Settings now updates to match the selected mode and language.

Security & reliability

  • iOS: the profile index and PGP store are no longer overwritten when the keychain is temporarily unavailable — protects profiles and keys if the app launches before the device is unlocked.
  • Android: data that decrypts but fails to parse now raises an error instead of silently regenerating keys — protects identity, metadata, indexes and PGP.
  • Android: closed a tapjacking vector in the on-screen decryption window — the copy and close buttons are now protected from overlay attacks.
  • Internal cleanup: dead code removed, a hidden defect fixed in the Android keyboard source, faster steganography settings handling.
1.1.1 July 13, 2026

Android

  • Fixed a crash on launch on Android 12 when the device has no screen lock (PIN, pattern or password).
  • The master key protection level is now picked automatically: on devices with a screen lock the key still requires the device to be unlocked, on devices without one the app works instead of crashing.
1.1 July 13, 2026

Android

  • Screenshot blocking for on-screen decryption is now a separate toggle in Settings, off by default — it used to block screenshots system-wide while the service was running.

Keyboard (Android & iOS)

  • Autocorrect and suggestions rebuilt from scratch: up to 2–3 typos per word are fixed as you type, accounting for near-key misses, swapped and doubled letters.
  • The correction dictionary grew from ~8,000 words to the full lexicon — about 360,000 word forms for Russian and 110,000 for English; autocomplete now suggests word forms too.
  • Common misspellings removed from the dictionaries — they used to count as real words and block correction; real words, slang and learned words are still never touched.

Text steganography (Android & iOS)

  • New encoding format — hidden text is ~30–36% shorter for the same message.
  • New dictionaries of 4,096 short natural words replace the recognizable BIP39 list; every message now looks different — random masking and sentences of varying length with real punctuation.
  • Added a checksum: plain text and damaged or truncated copies are no longer mistaken for a hidden message. Dictionaries cleaned of crude words.
  • The old steganography format is removed: messages created in version 1.0 cannot be read by 1.1 — make sure everyone you write to updates.

How it works

1

Write & encrypt

Type a message in Kryptos or straight on its keyboard — one tap turns it into code.

2

Send it anywhere

Paste the code into any chat: WhatsApp, Telegram, iMessage, SMS. To everyone else it's just random characters.

3

It decrypts on screen

Your friend's Kryptos shows the real text right over the code — or decrypts it in the keyboard or with one tap in the app.

Features

Signal Protocol

The same encryption Signal itself uses — its own libsignal library: a fresh key for every message, secure even against future quantum computers.

Any messenger

Encrypt in Kryptos, paste the code into WhatsApp, Telegram, iMessage or SMS — the messenger only ever sees gibberish.

Fully offline

Zero internet: the app has no networking code at all, and your keys never leave the device.

iPhone and Android

It is the same app on both platforms, and the two are fully compatible: messages, keys and anything hidden inside a photo or a piece of text work in both directions. It does not matter which phone your contact carries.

Decryption right on your screen

On Android, Kryptos plugs into the system and works over any app: it finds its own messages and lays the decrypted text right over the ciphertext, live, while you scroll the chat. Nothing to copy and nothing to open, you read the conversation like an ordinary one. It works only for your contacts, and it does not work at all while Kryptos is locked. On iPhone a copied message is decrypted by the keyboard right above the keys, or by the app itself when you open it.

A keyboard for every app

The Kryptos keyboard installs like any ordinary system one: enable it once and it is there everywhere you type. Type, tap the lock, and the field holds the ciphertext, ready to send. It decrypts an incoming message by itself and shows it above the keys. It is a full keyboard as well: suggestions, autocorrect for Russian, English, German and Chinese, emoji, all of it offline, so you can happily keep it as your main one.

Steganography

Hide a secret message inside an ordinary photo, or disguise it as a harmless run of words — nobody will even know it's there.

Password mode and PGP

You do not always need a full conversation. There is a simple mode on a single shared password: agree on a word with someone and you can write straight away. And for people who live on PGP, that is built in too.

App lock & clipboard

Face ID / biometrics, content hidden in the app switcher, clipboard auto-clear.

Panic PIN

A separate PIN that, instead of unlocking, instantly wipes all keys, chats and contacts (Android).

Questions and answers

Do I have to switch to Kryptos to write or read a message?

No. You stay in your own messenger: type the message, tap the lock on the Kryptos keyboard, and only the ciphertext is left in the field. An incoming message is shown decrypted right over the ciphertext on Android, and read by that same keyboard on iPhone. You open the app itself only to add a contact or change a setting.

How does the Kryptos keyboard work?

You enable it once in the system list of keyboards, and it is then available in any app. Pick a contact, type, tap the lock: the plain text in the field turns into ciphertext. Incoming messages are read in the same place: you copy the message and the keyboard shows the decrypted text above the keys with the sender's name. You can also type in a field inside the keyboard itself, and then the messenger never sees the plain text at all. The rest of the time it is an ordinary keyboard, with suggestions and autocorrect for Russian, English, German and Chinese, fully offline.

What is on-screen decryption?

It is an Android feature. You switch the Kryptos service on once in the accessibility settings, and the app then finds its own ciphertext on screen and lays the decrypted text over it while you scroll the conversation. Nothing to copy, nothing to open. The service reads only text that is already on the screen, works only for your contacts, and never while Kryptos is locked. A separate switch blocks screenshots while it runs. The iPhone gives no app that kind of access to the screen, so there the keyboard does the reading.

What do I set up once?

Enable the Kryptos keyboard in the system list of keyboards: on iPhone you also allow it full access, without which it cannot reach the keys. On Android, if you want on-screen decryption, switch the service on in the accessibility settings. And exchange keys with your contact: let them scan your QR code, or just copy your key as text and send it any way you like, through that same messenger if you want. Their key is pasted as text in the same way, no camera needed. That key is the public one and it is safe to show; the private key never leaves the device. After that there is nothing to configure and nowhere to register.

Does my contact need Kryptos too?

Yes, nothing but Kryptos can decrypt the message. Which phone each of you carries does not matter though: the iPhone and Android versions are fully compatible, and keys and messages work in both directions.

Does it need an internet connection?

No. Kryptos has no servers and no accounts, and there is not a single line of networking code in the app. On Android it does not even ask for permission to reach the network. Encryption happens entirely on the device, and delivery is handled by whatever messenger you already use.

Can the messenger read my messages?

No, it only ever gets text that is already encrypted. It does still see that you sent something, to whom, and roughly how much. That is metadata, and Kryptos does not hide it, but you can at least mask the length in Settings → Privacy.

How strong is the encryption?

Chats use Signal's own libsignal library, the same protocol as Signal itself, post-quantum handshake included. Password mode and photos use Argon2id and AES-256-GCM. Kryptos contains no home-made cryptography.

Why is the first message so long?

It carries the post-quantum handshake (PQXDH with Kyber), which is about two kilobytes. It is sent once: as soon as your contact replies, messages become many times shorter.

Why will a message not decrypt a second time?

That is not a fault but forward secrecy: the key for each message is destroyed the moment it is read, so old correspondence cannot be recovered even by someone who takes your phone. Messages you have already opened remain in the chat history.

It says it could not decrypt. What now?

Usually the wrong contact or the wrong profile is selected. If every new message from one person fails, the session has gone out of sync: send them your key again and have them add you a second time.

What is the safety number for?

It is a fingerprint of the key. Compare it with your contact over some other channel, read it out loud for instance. If the numbers match, there is definitely nobody in the middle.

What are profiles for?

A profile is a separate identity with its own key and its own contacts. You can keep several and switch between them, to keep work and private life apart for example.

Can I use one key on two phones?

No. A conversation runs from one device: its key chain cannot advance in two places at once. Move your keys to the new phone with a key backup and then use only that phone.

What happens if I delete the app or lose my phone?

The keys live on the device and nowhere else, so deleting the app destroys them for good and there is nothing left to decrypt with. The only insurance is to make a key backup in Settings beforehand. The flip side of the same property: whoever finds the phone gets nothing either.

Does the key backup restore my messages too?

No, and that is deliberate. The file carries only your keys, your contacts and your PGP keys, message history is never written into it. After restoring on a new phone you carry on with the same people, but the old messages do not come back.

I forgot the password to my key backup

There is no way to recover it. The file is encrypted with that password and Kryptos keeps no copy of it anywhere. Make a fresh backup with a password you will not forget.

What do disappearing messages actually do?

They erase the conversation inside Kryptos after the time you pick, on your device, and on your contact's if they set the same thing themselves. What they cannot touch is the ciphertext already sitting in the messenger: only the messenger itself can remove that.

Can I send a photo or a file through Kryptos?

No, Kryptos encrypts text only. The Photo tab does something different: it hides a text message inside a picture, rather than sending the picture itself securely.

I hid a message in a photo and it will not open

The photo has to be sent as a file (a document). Sent as an ordinary picture it is recompressed by the messenger, and recompression destroys the hidden data.

What is the panic password?

It is a second password for the lock screen. Type it instead of your normal passcode and the app silently and irreversibly destroys every key, message and setting, then opens as if it had just been installed. You set it up in Settings → Privacy.

Why does the app ask for the camera?

Only to scan a contact key from a QR code. The camera is used nowhere else, and refusing access breaks nothing: you can always paste the key as text instead.

Do my keys and messages end up in the phone's cloud backup?

No. On iPhone the keys sit in the Keychain marked as this-device-only, so they never go into an iCloud or computer backup. On Android the app is excluded from cloud backup and from device-to-device transfer entirely. Everything else is encrypted with exactly those keys, so a stray copy would be unreadable anywhere else.

Requirements

iOS

iOS 17 or later. The .ipa is unsigned and is signed on the device.

Android

Android 8.0 or later. Self-signed .apk — allow installs from unknown sources.

Network

Not used. The app works fully offline.

Languages

Russian, English, German and Chinese — follows the system language.