There's almost no overlap among people finding security holes in software and finding flaws in an encryption scheme. The fact that Signal does its own thing and has no documentation means that almost no one qualified will be looking. Even these guys essentially punted on the question, since they didn't do an in-depth analysis.

But if terrorists are using it, you can be sure the NSA has people doing such a deep dive, and if they find flaws they aren't going to tell anyone about them.

