There is a pattern I keep seeing when a peer-to-peer communication tool crosses a certain visibility threshold in a jurisdiction under stress. First the protesters find it. Then the screenshots go viral. Then the cybercrime unit sends a notice. Then a coverage cycle argues about whether the app "defied" the regulator, as if a Bluetooth mesh with no server has the corporate machinery to defy anything. The bitchat episode in India is the latest instance, not a novel event. What is novel — and this is where I want to spend the piece — is how badly the framing maps onto the actual technical and legal reality of what a serverless mesh app is.
The Pattern: Every Mesh App Eventually Gets a Letter
The pattern, stated plainly: when a national network is throttled or partially shuttered during a period of civil unrest, some portion of the population reaches for whatever piece of software still moves packets between two nearby phones, and within roughly seven to fourteen days the cybercrime cell in whatever jurisdiction is under stress publishes a notice about that piece of software.
This is not a bitchat-specific event. This is the third or fourth time the same script has run in the last decade. FireChat in Hong Kong. Bridgefy in Belarus. Briar in various theatres. The names change. The genre is stable. A protest happens, a network gets constrained, an app that runs over Bluetooth Low Energy or over a Wi-Fi mesh gets found by the crowd, downloads spike from single-digit thousands into six figures inside a weekend, and the cybercrime unit — whose job is to send letters — sends a letter.
I want to be careful about the word "notice" here. In the Indian regulatory vocabulary, a notice under the Information Technology Act's intermediary sections has a very specific meaning. It presumes the addressed party is an intermediary. It presumes there is a party at all. The whole framework was built for a world where messages traverse a corporate server owned by an entity with a registered office and a nodal officer. That model covers WhatsApp. Covers Telegram. Covers Signal. It does not cover a protocol where two phones in the same coffee shop exchange bytes over BLE without either device asking permission from any server in the middle.
So why does the notice keep going out anyway? Three reasons, and none of them are technical. The first is attribution reflex — the cybercrime cell needs an addressable target and the maintainer of the reference build is the closest available proxy. The second is optics — being seen to act is, for most regulators, indistinguishable from acting. The third is the framework itself — the IT Act does not have a section for "protocol we cannot address because the packets do not touch a server we can subpoena." The taxonomy fails, and when the taxonomy fails, the paperwork defaults to whatever category is nearest.
Why "Defies" Is the Wrong Verb for What Bitchat Actually Did
The verb "defies" implies four things in sequence: that a request was made, that a legal entity received it, that a technical mechanism existed for the entity to comply, and that the entity considered compliance and refused it. For a corporate messaging app, all four of those clauses are usually true, and "defies" is a fair verb.
For bitchat, only the first clause survives contact with reality.
The request exists — some notice was sent to some address associated with the project. Fine. But the legal entity is a maintainer of an open-source codebase, not an intermediary in the IT Act's technical sense of the term. The reference build is one artifact; the network is thousands of copies of that artifact running on phones that already have it installed. If the maintainer took down the GitHub repository tomorrow morning, the mesh would continue to work tomorrow afternoon. Every device that already has the app is a node. No node calls home. There is no "home" to call.
The mechanism clause is where the framing really breaks. In a normal takedown, the intermediary either removes content from its server or blocks a set of user accounts. In a mesh, "removing content" is meaningless because content lives ephemerally on the two endpoints of any given hop and possibly on one intermediate relay that already forgot the payload before the notice arrived. Blocking accounts is meaningless because there are no accounts. The identifiers are ephemeral, generated on-device, unbound from any registration.
And the decision clause — that a party considered compliance and refused — is the one that reads most wrong to me in the coverage. A protocol running over Bluetooth Low Energy on your phone does not consider notices. It has no decision surface. The maintainer of the reference build has a decision surface, but the decision available to them is "keep publishing the reference build" or "stop." Neither of those is "defiance" in the moral-agency sense the verb implies. Both are technical acts about a specific artifact. The network keeps running either way.
I am not making a moral argument that regulators should not send notices. Regulators will send notices — that is what the job description says. I am making a linguistic argument that the coverage is describing a corporate refusal-to-comply story when the underlying event is a category mismatch between the regulatory tool and the technical thing it is aimed at.
A mesh protocol does not defy a cybercrime notice any more than a paper airplane defies air traffic control — the addressed party lacks the surface area to comply or refuse.
The Exchange Parallel Nobody Is Drawing
Here is where the crypto reader who ended up on this page should recognize the shape of the argument. Because we have watched exactly this movie in the exchange space, in India specifically, and nobody drew the parallel then either.
When India's Financial Intelligence Unit published its December 2023 notice against offshore crypto exchanges operating without local registration, the headlines used the same verb. "Binance defies FIU." "MEXC defies compliance directive." Same category mistake, different technical stack. The exchanges in question sat across a spectrum of licensing postures that the word "defies" flattened into a single narrative.
Look at what the actual license map looks like. Binance is licensed at tier 2 in Dubai (VARA), France (AMF) and Italy (OAM); its most recent proof-of-reserves audit was published 2025-03-01. Bybit holds full-tier VARA in Dubai and CySEC full-tier registration in Cyprus; POR last audited 2025-03-12. OKX carries a provisional VARA license in Dubai plus a full SCB tier-3 license in the Bahamas; POR 2025-03-01. Bitget operates on Lithuania FCIS and Poland KNF full-tier registrations; POR 2025-02-20. And MEXC — the outlier of the set — runs on a single Seychelles FSA offshore license classified tier 3, with a partial reserve-verification status last audited 2024-12-10.
Every one of those exchanges offers a fiat onramp into India. Binance and Bybit both route INR via UPI at zero fees, instant settlement; Bitget the same. Binance is also configured for bank transfer, one-to-two day settlement. Every one of those onramps was live during the FIU episode. The retail behavior did not change based on the corporate-office response to the notice. It changed based on whether the specific app remained installable and the specific rail remained routable.
The receipt-grade point is that these are structurally different postures the coverage compressed into one verb. Binance eventually registered as a Reporting Entity — a corporate act by a corporate entity holding tier-2 licenses across three jurisdictions. MEXC did not — and MEXC's fee schedule tells you why: 0.00% maker and 0.02% taker fees against a category norm of flat 0.10% / 0.10% at the other four exchanges in this dataset. That fee spread is unusual and worth naming. It is not a promotion. It is the standing schedule for an exchange whose entire economic architecture is built on running lean out of Seychelles, offering 200x leverage on futures against Bybit's 100x and Binance's 125x, and accepting the regulatory posture that follows from that architecture. To describe that as "defying" is to miss that the whole business model is the answer to why the license map looks the way it does.
Bitchat sits at the far end of the same spectrum that MEXC anchors — no corporate registration in India, no local licensed presence, but with the additional property that there is no server component at all. If MEXC is a "you cannot easily reach it through Indian courts without an MLAT process" story, bitchat is a "there is no it to reach" story. Two different technical realities, same verb misapplied to both.
So What Do You Actually Do
If you are a user in India who installed bitchat during the coverage cycle, understand what the notice actually changes for you. It changes the availability of the reference build on Indian app stores. It does not delete the app from your device. It does not change the legality of a private conversation between two people over a wireless personal-area network — that framework was never in the IT Act to begin with, because BLE mesh was not a mainstream user experience when the Act was drafted. Do not conflate a notice against a maintainer with a criminal exposure for a user. Two different legal facts.
If you are building anything in the peer-to-peer, mesh, or protocol space and you plan to ship it in a jurisdiction that experiences periodic network stress — that is most jurisdictions now — the notice will come. Not "might come." Will come. Write the policy document before the notice, not after. Have a written statement ready that describes, in plain technical language, what your stack can and cannot do in response to a takedown request. Have your maintainer identity structured so that the addressable party understands the constraints of the artifact they maintain. This is not legal advice — I am not a lawyer — this is engineering advice about how to reduce the ambient chaos when the letter arrives.
If you are a crypto reader who ended up here because the bitchat headline crossed your feed, treat this as a case study in how the "defies" narrative gets applied to any technical actor that lacks the corporate surface area to comply cleanly. You have watched the same story play out at MEXC, at various offshore Bitget-adjacent operators, at the entire class of tier-3 licensed venues offering UPI rails into India. The reflex to read those episodes as morality plays about compliance versus defiance is the reflex most likely to produce the wrong risk model for what you actually hold and where you actually hold it.
Whether India's intermediary framework can be adapted to a network topology that has no addressable center — or whether the concept of an "intermediary" simply does not apply once packets stop touching servers the regulator can subpoena — is the question the bitchat notice implicitly asks and does not answer. If the FIU-IND, or any of the cybercrime cells that will send the next letter to the next mesh app, has a published technical position on how they intend to bridge that gap, I have not seen it. If you have, write.