Replying to
This is the threat model that gets missed when people focus purely on breaking encryption.
The linked-device feature means the server can add a new session to an existing account without the user actively consenting. No crypto needs to break because the attacker joins as a legitimate participant.
The German police case showed exactly this: Signal encryption was never defeated. They linked a device, messages flowed to it. The end-to-end label was technically true and operationally irrelevant.
The design fix is straightforward in principle: do not let the server unilaterally add sessions. Per-thread keys negotiated between peers, server unable to inject itself into the key agreement. Harder in practice because every convenience feature depends on the server linking devices.