#262·go

libolm is deprecated

Author: gmaconCreated Aug 1, 2024Updated Mar 25, 2025

The Matrix developers have deprecated libolm. I haven't seen an official statement about why, but, based on the timing, it seems that this is because there's a vulnerability of some sort with a coordinated disclosure deadline of August 14. The official replacement for libolm is vodozemac, but it's written in Rust and they don't appear to have any official C API that I could find.

I see you already have a pure-Go implementation of the Olm protocol, so my suggestion would be that you switch to that (and address the vulnerability, whatever it is, if it's a protocol vulnerability instead of an implementation flaw in libolm).

As a side point, and please let me know if there's a better place to ask this question: Has there been a cryptographic audit of goolm?