India removes Bitchat code under IT law, developers are affected.

CN
4 hours ago

Recently, a formal notice from India’s Ministry of Home Affairs’ cybercrime agency quietly passed through the regulatory system and landed on the desktop of GitHub, one of the world's largest code hosting platforms. The notice explicitly referenced Article 79(3)(b) of the IT Act, directly naming Bitchat, an offline communication and Bitcoin transaction tool supported by Jack Dorsey, requiring the platform to remove three code repositories of the project within three hours. Bitchat establishes peer-to-peer links between devices using a Bluetooth mesh network, allowing users to interact through encrypted messages and Bitcoin transactions without traditional account registration. This technological path of “disconnecting from the internet, accounts, and visible identity” was summarized by Indian authorities in the notice as a tool type that “hinders lawful interception and tracing,” thus falling under items subject to review or even removal. Previously, Article 79 of the IT Act was more often applied in the context of combating misinformation, hate speech, and illegal content, serving to delineate the deletion obligations and liability exemptions of intermediary platforms. Now, the same provision is being used to require code hosting platforms to process the source code of an encrypted communication and Bitcoin tool within a very short time frame, clearly classifying GitHub in India as a subject that must comply with removal orders to maintain its intermediary immunity. Against the backdrop of frequent network and data control measures in India in recent years, this enforcement action targeting source code has directly collided offline encrypted tools with sovereign regulation and lawful interception demands, sounding an alarm for all code hosting platforms and privacy-focused encryption projects operating in or accessed from India: they are entering a new regulatory phase that imposes higher compliance thresholds, faster review windows, and easier inclusion in security assessments.

India invokes Article 79 of the IT Act: from misinformation to encrypted communication

Before the recent action against Bitchat’s code, Article 79 of the IT Act had been a “safety valve” for India in handling intermediary platform responsibilities. On one hand, the provision acknowledges that social networks, video platforms, and even code hosting services are merely “intermediaries,” and as long as they fulfill the due diligence obligations required by the government, they can enjoy liability exemptions. On the other hand, Article 79(3)(b) embeds a mandatory switch: as long as the competent authority issues a notice, intermediaries must delete specified content within a limited timeframe, or else the exemption becomes invalid and liability is assumed. In the past, this mechanism was primarily used in traditional internet contexts—combating hate speech, illegal content, and the spread of misinformation. Intermediaries only needed to rapidly cooperate with post deletions and account suspensions to remain on the “legitimate service” side.

The notice regarding Bitchat marked the first time Article 79(3)(b) was clearly extended to “the encrypted communication tool itself.” The cybercrime agency under the Ministry of Home Affairs directly identified GitHub as an intermediary in the context of the IT Act, demanding that it remove three Bitchat code repositories within three hours and citing “hindering lawful interception and tracing” as the reason in the notice. The regulatory logic shifted from “removing problematic information” to “removing tools that carry information”: Bitchat utilizes a Bluetooth mesh network to achieve offline device communication without requiring traditional account registration, allowing users to interact via encrypted messages and Bitcoin transactions. This design, which disconnects from the internet and weakens identity binding, perfectly strikes against the red line that India has continuously reinforced regarding network and data control, emphasizing that everything must be interceptable and traceable. Under such reasoning, choosing Bitchat, supported by Jack Dorsey and focused on offline communication and transactions, as the subject of technological review sends a clear signal from regulators: any tool perceived as undermining the state’s capacity to monitor information and financial flows, even if still at the source code stage, will be included in the rapid delisting chain under Article 79(3)(b).

Bitchat’s offline Bitcoin communication crosses regulatory red lines

Bitchat’s design effectively dismantles the regulatory checklist in reverse: users do not need traditional account registration to enter the system, and there are none of the common identity anchors such as phone numbers, emails, or real name information. Devices create an offline mesh network via Bluetooth, with messages able to hop between “human-based stations” without touching any operator base stations or internet service nodes. More critically, it combines encrypted message delivery with Bitcoin transactions, meaning the chat interface itself serves as the gateway for financial interactions, completing a synchronous flow of information and value through a unified channel. This combination of “offline + no accounts + bundling of information and transactions” makes the project appear, on a technological level, as merely an experimental tool supported by Jack Dorsey, yet inherently possesses the capability to bypass traditional communication and payment systems.

For Indian regulators, this capability directly targets three “security pillars” they care most about: identity verification, traffic monitoring, and transaction tracing. Without a registration process, it becomes difficult to pin specific actors to accountable accounts; the Bluetooth mesh network bypasses telecom and internet infrastructure, which weakens traditional traffic evidence collection and situational awareness reliant on operators and ISP logs; and the combination of encrypted messages and Bitcoin transactions intertwines information content and fund flows within the same channel, complicating the dissection and tracing of individual dimension evidence. In this narrative of risk, the Indian authorities categorized offline encrypted tools like Bitchat as high-risk targets under Article 79(3)(b) for “hindering lawful interception and tracing,” shifting focus from what content is being disseminated to delineating new regulatory red lines against technological forms that naturally weaken state monitoring capabilities.

GitHub’s neutrality torn into a regulatory frontline

Within the context of India’s IT Act, GitHub was originally viewed as a typical technical intermediary service provider: merely hosting code without making value judgments about the specific uses of the projects, relying on Article 79’s liability exemption to maintain a “technically neutral” status. However, when the cybercrime agency under the Ministry of Home Affairs explicitly cited Article 79(3)(b) in their notice, demanding GitHub to remove three Bitchat-related code repositories within three hours, this neutral space was rapidly compressed. If the intermediary platform fails to comply with the removal request, it risks losing its immunity status and could face potential legal liability. The legal provision was initially used primarily to address misinformation and illegal content but is now directly operating against a type of technology perceived as “undermining interception and tracing capabilities,” forcing GitHub in India to shift from a passive host to a frontline node executing regulatory orders.

The three-hour removal deadline itself is a signal reconstructing the rhythm of global open-source collaboration. For cross-timezone maintained encryption and privacy projects, this means regulatory notices are no longer “compliance work orders” that can be negotiated and assessed slowly, but rather like an emergency shut-off switch that could be triggered at any moment: the platform finds it extremely challenging to verify technical details of the project within such a short window, let alone organize sufficient legal defenses, and can only prioritize protecting its liability exemption. The outcome is a new tension between code platforms’ compliance with local laws and their maintenance of code freedom—if they merely cooperate rapidly in deletions, it will erode developers’ trust in the platform’s “hosting-only, not adjudicating” role; however, if they choose to delay execution or openly resist, they must confront the risk of being deemed non-compliant intermediaries. This dilemma will carve a fissure between platforms and developers with each similar notice, forcing both parties to redefine the boundary of “to what extent can open-source code be hosted.”

New compliance thresholds for Indian developers and Bitcoin projects

In India, where there is both a large developer community and an active crypto user market, the Home Ministry’s cybercrime agency’s invocation of Article 79(3)(b) specifically targeting Bitchat and requiring GitHub to remove the relevant repositories in a very short time frame sends a clear signal to the local tech community: decentralized, privacy-enhancing Bitcoin tools are no longer merely “neutral code,” but may be seen as objects of scrutiny that “hinder lawful interception and tracing.” In the past, Article 79 was more often used to handle traditional content risks like misinformation and hate speech; now it has directly extended to open-source projects involving offline communication and Bitcoin transactions, making it essential for Indian developers to preemptively assume that “once code is deemed to affect law enforcement capabilities, it may be demanded for takedown,” significantly raising uncertainties around compliance.

At the project level, this means that every technical choice surrounding code visibility, node distribution, and how much anonymity to preserve for users must be weighed against risks: continuing to host repositories on centralized platforms like GitHub can exchange collaboration efficiency and global contributors but also makes it easier to fall directly into the intermediary deletion pathways under the IT Act; if communication and transaction logic is made more dispersed and reliance on a single hosting platform minimized, while improving anti-blocking capabilities, developers must also consider whether this structuring will be viewed by regulators as intentionally "evading intermediary responsibilities." For end users, seeing an open-source project supported by Jack Dorsey, providing offline Bitcoin transaction and communication features, being officially named, might prompt them to consider migrating to other tools sooner or to shift towards more decentralized distribution methods when acquiring and updating code, in order to mitigate the risk of suddenly losing access due to the platform receiving a takedown notice. This preventive migration is the new reality faced by developers and users following the tightening regulatory boundaries in India.

A protracted battle between offline encrypted communication and sovereign regulation

India's recent issuance of a takedown notice to GitHub under Article 79(3)(b) of the IT Act, targeting tools primarily used for offline encrypted communication that “hinder lawful interception and tracing,” represents the first targeted application of intermediary responsibility clauses previously applied majorly to addressing misinformation and illegal content. This action has involved code hosting platforms in the front lines of technological review, in fact bringing offline mesh networks, end-to-end encryption, and Bitcoin interaction tools into the priority issues list for sovereign regulation. The incident occurred following multiple internet shutdowns and a consistent strengthening of data and information control, sending a signal to global developers and the privacy tech community: as long as platforms and tool developers are deemed to affect the state’s control over information flows, they may be required to cooperate with takedown requests or restrictions on dissemination within a very short time frame. How other jurisdictions respond to this platform responsibility model will be a crucial variable in the next round of competition—some countries may follow India’s approach and view code hosting providers as required to actively filter “unmonitorable” tools, while others may intentionally maintain distance to protect the open boundaries of source code and communication technology. Regardless of the path taken, there will be cascading effects on the offline payment and communication ecology associated with Bitcoin, compelling reevaluation of compliance exposure from project location, code hosting to user acquisition methods. To date, no detailed official responses from GitHub or the Bitchat team have been reported, and whether India will expand similar notices or accept challenges on the applicability of the IT Act and boundaries of intermediary responsibility at the court level remain ambiguous points. Until these timelines and variables clarify, the tug-of-war between offline encrypted communication and sovereign regulation will only continue to persist in uncertainty.

Join our community, let's discuss and grow stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink