Threema is analyzed more than any other messenger.
2024: Audit by Cure53 of the new desktop app, see blog post and audit report
2023: Security analysis of the “Ibex” communication protocol by security researchers from the Chair of Applied Cryptography at the University of Erlangen-Nuremberg, see blog post and analysis
2020: Audit by Cure53, see blog post and audit report
2019: Audit by Lab for IT Security of the Münster University of Applied Sciences, see blog post and audit report
All the reports can be found here:
https://threema.com/en/faq/code-audit
older
2016 = The german Chaos Computer Club decompiles Threema
https://media.ccc.de/v/33c3-8062-a_look_into_the_mobile_messaging_black_box#t=3225
2015 = External Security Audit
2012 = Threema Code-Analyses from the University of Amsterdam
