Cryptographic software isn't something that you can improve by a process of gradual refinement.
Crypto can have small, subtle, bugs. Those bugs could mean that the product is worthless.
A skilled, knowledgeable researcher could audit the code closely, and report any bugs they find. Cryptocat could fix all of those bugs. Does that mean it's secure? No - because crypto is hard.
> What more can you ask of them?
I ask that they make the disclaimers much bolder and bigger. I ask that they emphasise the experimental, untested, unscrutinised nature of Cryptocat.
> "You there. Stop. You shouldn't be building this because we the superior internet community think you're a terrible person who will never learn anything, so we're putting our foot down."
That's a mischaracterisation of the criticism they've got.
"You there. Stop! Cryptography is very hard. Don't roll your own; or do but don't release it as a product for end users."
followed by
"You there. Stop! We suggested that you didn't release it for end users, but you did. Well, here's a list of bugs. Don't just fix these and think everything is good, there are probably other bugs and the whole thing is based on weird wrong ideas."
followed by
"You there. Stop! No, really, just stop. Here's a list of bugs. These are not subtle hard to find bugs. These are obvious bugs that anyone doing crypto really should have been aware of. The presence of these bugs demonstrates lack-of-clue. Please, stop hyping the product as secure, stop distributing as a tool for end users to use."
People get exasperated. It doesn't help that some of the responses from the developers were defensive and aggressive and dismissive.
tl;dr have fun with crypto and building stuff. Just don't think it's secure, and especially don't release it as secure. Especially don't release it as a browser plugin ready for naive end users.