I wasn't going to post this, but I had the same feeling at a conference. Also, if I remember correctly, the first version that got audited turned out to be extremely insecure as well, with their own custom crypto protocols? I haven't recommended CryptoCat to anyone since, and still wouldn't.
This audit report is another fascinating read to see all the mistakes I would probably have made as well. Secure crypto is so incredibly difficult to get right...