A low-severity key confusion vulnerability in Megolm version 3, an AES-based encryption system used in Matrix's encrypted messaging, was discovered and fixed in vodozemac 0.3.0 (September 2022) but remained undocumented until publicly disclosed in September 2026. The vulnerability relates to potential key confusion in the cryptographic ratchet mechanism, though the author does not believe the construction to be fundamentally insecure.