A security researcher reported 15 findings in Internxt, an encrypted storage firm, in a 3 October post on schaerli.org. In desktop versions up to 2.6.12, a malicious link can run code, because the app passes internxt:// links to the operating system unchecked. A crafted login link opened in any browser can also leak a user's encryption key and login token. No desktop app is needed.
Every file key comes from one 24-word secret, the mnemonic, that never changes. The researcher says sharing a folder hands that secret over, and Internxt's server can intercept it, so the firm could read or change data. Three MD5 rounds turn the password into the key protecting it. On his graphics card, a billion guesses took about four seconds. Internxt told him version 2.7, with the code fix, is due next week. His web fix is merged; the post does not say if it is live. He says the key design cannot be patched quickly, and it is not tied to any version.
"Zero-knowledge" and "audited" are claims, not proof of key design. Internxt says its 2025 audit found no severe flaws, but the report is unpublished. Buyers can ask: is the full report available, can the vendor read keys, are update signatures checked? The post says Internxt turns that check off.