Earlier quoted context omitted.
Even if it's decentralized there's only one client and they can always push updates to male it send keys/messages back for targeted users. Smartphones in their current form cannot have secure messaging.
>Smartphones in their current form cannot have secure messaging. What about self-hosted matrix/element, used from the browser?
Unless you also ensure proper certificate pining, if someone can get a court order for any accepted CA to give them a valid certificate for your domain you won't notice a thing while that someone gets your browser to run any code and e.g. dump keys, certificates or messages.