I've seen lots of "experts" write really insecure code. While it is certainly possible someone did this maliciously. Devs often don't understand the code they write and repeat until they get something that "works" and call it good. With an app that touts security I would hope for better.
That's not the point.
Around security you have to assume "malicious until proven otherwise", unlike in law.
While that's true, products from Telegram, Cisco, Dell etc etc are targeted by nation states with infinite budgets who employ the best coders and cryptographers in the world. They have track records of selling bogus/backdoored products via fake companies, hacking companies to plant malware, planting/bribing employees etc. That changes the balance pf probabilities between stupidity and malice a lot for me.