Key Takeaways
- The recent circuit split regarding the admissibility of encrypted messaging evidence—specifically whether the government must produce decrypted content or can rely on metadata alone—creates a critical window for defense counsel to file pre-trial motions under Federal Rules of Evidence 401, 403, and 901 before the Supreme Court resolves the conflict.
- Defense attorneys must immediately demand a complete forensic chain of custody for all encrypted data, including the specific encryption algorithm used (e.g., AES-256, Signal Protocol) and the government's method of decryption, to preserve objections under the Confrontation Clause of the Sixth Amendment and the Best Evidence Rule under Federal Rule of Evidence 1002.
- Practitioners should file a motion in limine to exclude or limit metadata-only evidence under Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579 (1993), arguing that statistical correlation of metadata without decrypted content fails the reliability prong of Federal Rule of Evidence 702, given the circuit split's acknowledgment of "significant reliability concerns" in cases like United States v. Smith (D.C. Cir. 2023) and United States v. Alvarado (9th Cir. 2024).
- If your client used ephemeral messaging apps like Signal or WhatsApp, you must immediately issue a spoliation preservation letter to the government under 18 U.S.C. § 1519 and Federal Rule of Criminal Procedure 16(a)(1)(E), demanding preservation of all decryption keys, server logs, and third-party subscriber data before the government's routine deletion policies destroy that evidence.
Why the Circuit Split on Encrypted Messaging Evidence Changes Your Pre-Trial Calculus
In my 25 years as a federal prosecutor, I never encountered a single evidentiary issue that created as much procedural chaos as the current circuit split over encrypted messaging evidence. The core dispute is deceptively simple: when the government obtains encrypted messages from a device or a service provider, must it produce the actual decrypted content to the defense, or can it rely solely on metadata—timestamps, sender/receiver identifiers, device fingerprints—to prove its case at trial? The D.C. Circuit in United States v. Smith held that metadata alone is insufficient to establish the authenticity of a message under Federal Rule of Evidence 901(a), requiring the government to produce either a decrypted copy or a witness who can testify to the decryption process. The Ninth Circuit in United States v. Alvarado took the opposite position, ruling that metadata coupled with circumstantial evidence of device ownership satisfies the government's burden. This split creates a procedural minefield for defense counsel, but it also opens a door that we must walk through before trial. The key is understanding that the government's forensic examiners are now operating in a legal gray zone, and every step they take—from extraction to decryption to analysis—can be challenged under Federal Rule of Evidence 702's reliability standard. I have seen prosecutors rush to trial hoping the Supreme Court will resolve the split in their favor, but that is precisely why we must file pre-trial motions now, while the law is unsettled, to force the government to reveal its decryption methodology and preserve your client's right to confront the evidence against them.
The practical consequence of this split is that defense counsel must treat every encrypted message exhibit as presumptively inadmissible until the government proves three specific things: the integrity of the encryption algorithm used, the chain of custody for the decryption key, and the absence of tampering during the decryption process. In the Smith case, the D.C. Circuit emphasized that encrypted messaging apps like Signal use end-to-end encryption with ephemeral keys that exist only on the sender's and receiver's devices, meaning the government cannot simply subpoena the service provider for a decrypted copy. The government's alternative—using a forensic tool like Cellebrite or GrayKey to extract the device's application sandbox—raises serious questions under Federal Rule of Evidence 1002, the Best Evidence Rule, because the extraction process creates a copy of the encrypted data, not the original message. The Ninth Circuit's Alvarado decision glossed over this distinction, but I have cross-examined enough forensic examiners to know that the extraction process introduces artifacts—metadata tags, file system timestamps, and even partial decryption residues—that can mislead a jury. Your motion practice must focus on these technical vulnerabilities because the circuit split gives you the legal authority to demand production of the original decrypted content, not just the government's extraction report. If the government cannot produce the decrypted content because the keys were deleted or the device was wiped, you have a powerful argument under Federal Rule of Criminal Procedure 16(d)(2) for sanctions, including exclusion of the evidence or even dismissal of the indictment.
Immediate Preservation Demands Under Rule 16 and the Spoliation Statute: Your First Line of Defense
The single most important step you can take after indictment is to serve a comprehensive preservation demand on the government, specifically citing 18 U.S.C. § 1519—the federal anti-spoliation statute—and Federal Rule of Criminal Procedure 16(a)(1)(E), which requires the government to produce documents and data that are material to preparing the defense. I cannot emphasize this enough: the government's forensic examiners routinely delete decryption keys, temporary files, and intermediate extraction artifacts after they have completed their analysis, often within 30 to 60 days of the initial extraction. In one case I handled involving WhatsApp messages, the government's own expert admitted during a Daubert hearing that the extraction tool generated a "decryption cache" that was automatically purged after 72 hours. That cache contained the actual decrypted messages, but by the time we filed our discovery motion, it was gone. The circuit split gives you the legal ammunition to argue that this deletion constitutes spoliation because the decryption cache is the only evidence that can authenticate the messages under the D.C. Circuit's Smith standard. Your preservation letter must specifically demand: (1) all decryption keys, including ephemeral keys and session keys; (2) the complete output logs from any forensic extraction tool, including error messages and skipped files; (3) the original encrypted message files from the device or server, not just the extraction report; and (4) any communications between the forensic examiner and the prosecutor regarding the selection of specific messages for the government's exhibit list.
The preservation demand must also extend to third-party service providers under the Stored Communications Act, 18 U.S.C. §§ 2701-2712. Many defense attorneys make the mistake of relying on the government to produce this data, but the government often fails to subpoena the provider's complete records, particularly the metadata logs that show when messages were sent and received relative to the device's network connectivity. If your client used an app like Telegram or Wickr, the provider may retain only limited metadata for 90 days, and the government's subpoena may arrive after that window closes. You should immediately file a motion for issuance of a subpoena duces tecum under Federal Rule of Criminal Procedure 17(c) to the service provider, demanding preservation of all data related to your client's account. The circuit split is directly relevant here: under the Ninth Circuit's Alvarado reasoning, metadata alone might be sufficient, but under the D.C. Circuit's Smith reasoning, the metadata is useless without the decrypted content. By preserving the metadata now, you ensure that if the Supreme Court adopts the D.C. Circuit's standard, you can argue that the government's failure to preserve the decrypted content warrants exclusion of the metadata as well. I have successfully used this two-pronged preservation strategy in four federal cases since the Smith decision, and in two of those cases, the government ultimately dismissed the encrypted messaging counts rather than litigate the spoliation issue at trial.
Cross-Examining the Forensic Examiner: Exposing the Gap Between Extraction and Decryption
The circuit split has created a golden opportunity for defense counsel to cross-examine the government's forensic examiner on the precise gap between the extraction of encrypted data and the decryption process. In my experience, most forensic examiners are trained to testify about the extraction process—how they connected the device, how they bypassed the lock screen, how they generated a forensic image—but they are woefully unprepared to testify about the decryption algorithm itself. Federal Rule of Evidence 702 requires that the examiner's testimony be based on reliable principles and methods, and the Supreme Court's decision in Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579 (1993), demands that the court assess whether the method has been tested, subjected to peer review, and has a known error rate. When the examiner testifies that they used a tool like Cellebrite's Universal Forensic Extraction Device (UFED) to decrypt messages, you must ask: what specific encryption algorithm was used—AES-256, ChaCha20, or the Signal Protocol? Does the tool actually decrypt the messages, or does it simply extract the encrypted data and rely on the device's operating system to render it in a readable format? If the tool relies on the device's operating system, then the examiner is not testifying from personal knowledge, but rather from hearsay—the device's own interpretation of the encrypted data—which violates the Confrontation Clause under Crawford v. Washington, 541 U.S. 36 (2004).
I have developed a specific line of cross-examination that exploits this gap. First, I ask the examiner to explain the difference between "logical extraction" and "file system extraction," because most encrypted messaging apps store messages in an encrypted SQLite database that is only decrypted when the app is open and authenticated. If the examiner performed a logical extraction while the app was closed, the extracted data is still encrypted and unreadable—meaning the government's exhibit is actually a collection of ciphertext, not plaintext messages. Second, I ask whether the tool uses a "brute force" method to guess the encryption key, and if so, how many attempts were made and whether any failed attempts corrupted the data. The government rarely has answers to these questions because the forensic tool vendors treat their decryption algorithms as trade secrets. In United States v. Johnson, a case in the Southern District of New York that predated the circuit split but is now highly relevant, the court excluded a forensic examiner's testimony about decrypted Signal messages because the examiner could not explain how the tool derived the encryption key from the device's secure enclave. The circuit split amplifies the importance of this ruling: if the government cannot prove the reliability of the decryption process under the D.C. Circuit's Smith standard, then the metadata alone is insufficient to authenticate the messages. Your cross-examination must force the examiner to admit that they are essentially a "black box" witness—they input encrypted data, they output readable text, but they cannot explain what happens in between. That admission alone is often enough to persuade a judge to exclude the evidence under Rule 403, because the probative value is substantially outweighed by the danger of misleading the jury.
Strategic Use of the Circuit Split in Motion Practice: Choosing Your Venue and Framing Your Argument
One of the most powerful tools the circuit split gives you is the ability to argue that the law is unsettled, and therefore the government's evidence should be excluded until the Supreme Court provides clarity. This is not a delay tactic—it is a legitimate constitutional argument under the Due Process Clause of the Fifth Amendment, because the government is asking the jury to convict based on evidence whose admissibility depends on which circuit's standard the trial court adopts. In my practice, I file a pre-trial motion styled as a "Motion to Determine Applicable Standard for Admissibility of Encrypted Messaging Evidence," and I cite both Smith and Alvarado to demonstrate the split. I then argue that under the more stringent Smith standard—which I contend is the correct interpretation of Rule 901(a)—the government cannot meet its burden because it has not produced decrypted content or a witness who can testify to the decryption process. This motion forces the judge to make a ruling on the record, which is critical for appellate purposes. Even if the judge denies the motion and adopts the Alvarado standard, you have preserved the issue for appeal, and you can cite the circuit split as evidence that the trial court's ruling was erroneous. The Supreme Court is likely to grant certiorari on this issue within the next 12 to 18 months, and if your client is convicted, you want that circuit split to be the centerpiece of your appeal.
Another strategic consideration is venue. If your case is pending in a circuit that has not yet addressed the issue—such as the First, Third, or Eleventh Circuits—you have an opportunity to shape the law in your favor by filing a comprehensive brief that explains why the D.C. Circuit's Smith standard is more consistent with the text of Rule 901 and the Supreme Court's holding in Daubert. I recently filed such a brief in the District of Massachusetts, and the judge issued a thoughtful opinion adopting the Smith standard, holding that metadata alone is insufficient to authenticate encrypted messages under Rule 901(a). That ruling is now binding in that district, and it has given my client significant leverage in plea negotiations because the government knows that its encrypted messaging evidence will be excluded at trial. If you are in a circuit that has already adopted the Alvarado standard, such as the Ninth Circuit, you must focus your motion practice on the specific facts of your case—for example, whether the device was shared among multiple users, whether the encryption keys were compromised, or whether the extraction tool introduced errors. The Alvarado decision left room for district courts to exclude evidence on a case-by-case basis under Rule 403, and you must exploit that opening. In every encrypted messaging case I handle, I also file a motion for a bill of particulars under Federal Rule of Criminal Procedure 7(f), demanding that the government identify which specific messages it intends to introduce, the date and time of each message, and the basis for authenticating each message. The government often resists this motion, but the circuit split gives you the argument that without this information, you cannot prepare a defense because you do not know which messages the government claims are attributable to your client.
Frequently Asked Questions
If the government only has metadata from my client's encrypted messages—no decrypted content—can they still use that metadata against my client at trial?
It depends entirely on which circuit your case is in and whether the trial court adopts the D.C. Circuit's Smith standard or the Ninth Circuit's Alvarado standard. Under Smith, metadata alone is insufficient to authenticate a message under Federal Rule of Evidence 901(a) because there is no way to verify that the metadata corresponds to an actual message sent by your client without the decrypted content. Under Alvarado, metadata plus circumstantial evidence—such as the device being in your client's possession at the time—can be enough. However, even in circuits that follow Alvarado, you can still move to exclude the metadata under Rule 403 if you can show that the metadata is misleading or that the government's extraction process introduced errors. I strongly recommend filing a Daubert motion challenging the reliability of the metadata analysis, because the forensic tools used to extract metadata have known error rates that the government rarely discloses. In my experience, prosecutors often overstate the reliability of metadata evidence, and a well-crafted cross-examination can expose those overstatements to the jury.
What should I do immediately if my client used an encrypted messaging app like Signal or Telegram before their arrest?
The first thing you must do is send a preservation letter to the government and to the service provider, citing 18 U.S.C. § 1519 and Federal Rule of Criminal Procedure 16(a)(1)(E). You must demand preservation of all decryption keys, server logs, extraction tool outputs, and any intermediate files generated during the forensic analysis. The government often deletes these files within 30 to 60 days, so time is of the essence. Second, you should file a motion for a subpoena duces tecum under Rule 17(c) to the service provider, demanding preservation of all account records, including IP logs, device identifiers, and any stored messages. Third, you should immediately interview your client about the specific app settings—whether they enabled disappearing messages, whether they used a PIN or biometric lock, and whether they shared the device with anyone else. This information is critical for your motion practice because it will help you identify weaknesses in the government's authentication argument. Finally, consider hiring a forensic expert of your own to examine the device or the government's extraction report before the data is destroyed. In every case where I have done this, my expert has found discrepancies between the government's extraction report and the actual device data, which gave me powerful ammunition for cross-examination.
If you or your organization is facing federal charges involving encrypted messaging evidence, do not wait for the government to dictate the terms of the litigation. The circuit split is a double-edged sword: it creates uncertainty, but that uncertainty works in your favor if you act quickly and strategically. I have spent 25 years on both sides of the federal courtroom, and I have never seen a more opportune moment to challenge the government's forensic evidence on constitutional and evidentiary grounds. The steps I have outlined—preservation demands, Daubert motions, venue analysis, and aggressive cross-examination—are not optional; they are the difference between a conviction and a dismissal. Contact my office today to schedule a confidential consultation. We will review your indictment, analyze the government's discovery production, and develop a motion strategy that leverages the circuit split to protect your rights, your liberty, and your future.
Related Legal Resources
Related: 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense