Being careless with your Apple ID credentials, having malware on your outdated iOS device or the computer you sync your iPhone to (note: they can sync wirelessly and in the background now, so it doesn't have to be an explicit action) can result in the same outcome - your messages silently going to an attacker.
Either way, it should be up to the user to decide what they want to do with their messages and how much security they attach to them. After all, even in case of a fully bulletproof solution that would even prevent screenshots, the user is still free to read their messages out loud in a public place or in reach of a recording device.
Also, again, Beeper Mini (different from Beeper Cloud, which is not E2E compatible) operates entirely on-device - no message data transits through Beeper's infrastructure. There's an optional cloud component to enable real-time push notifications but even in that case I believe their server merely relays data and doesn't have the decryption keys.