HushThreads is a Morphe patch bundle for Android that takes the ads out of Threads, cleans the links you share and cuts down what the app reports back to Meta.
The latest release is v0.0.3, with 6 patches.
Add to Morphe | Download a release | Browse the patches
- A feed without ads. Sponsored posts come out of each page of the feed as it arrives, before Threads saves or shows it.
- Links that don't point back at you. The code Threads adds to a shared link to tie it to your account comes off, along with the other tracking tags.
- Less sent home. Matched analytics upload addresses go nowhere, and Threads gets zeros instead of your phone's advertising ID. Other telemetry may remain.
- Controls that recover. Every runtime feature has a switch, and a pause, an automatic safe mode, settings backups and privacy-filtered diagnostics help when Threads changes.
HushThreads is the Threads member of a small family of patch bundles. Its settings screen, diagnostics and release checks come from its Facebook sibling, Hushfacebook. The Threads patches are written here. See Where the patches come from.
This project has no connection to Meta or to the Morphe project. Neither endorses it, and neither wrote it.
- Install Morphe Manager 1.32.0 or newer.
- Add HushThreads as a patch source: https://morphe.software/add-source?github=SysAdminDoc%2FHushThreads
- Get Threads 449.0.0.54.82 (
com.instagram.barcelona) for arm64-v8a, version code 511908382 (120-640dpi, Android 9+). That's the build these patches are checked against. Morphe Manager warns about other builds of the same version. - In Morphe Manager, pick that file, keep the default patch selection or change it, and patch.
Source builds on main declare both of these arm64-v8a variants. The published v0.0.3 bundle declares only 449.
| Threads version | Version code | Android floor |
|---|---|---|
| 449.0.0.54.82 | 511908382 | Android 9 |
| 448.0.0.54.85 | 511808302 | Android 9 |
Threads releases a new version about once a week, and each one renames most of its code. Every patch here finds what it changes by names Threads keeps (its post model, the feed cache, JSON parser names, strings and manifest components) rather than by the names that change. When one can't find what it needs, patching stops with a message naming it, instead of producing an app that quietly does nothing. Disable analytics checks three address kinds: PIGEON (the logger's URL builder), DEFAULT (direct event-log URL returns) and MQTT (the analytics endpoint setting). It stops when none match. The patch log, Privacy settings and exported diagnostics identify matched and missing kinds. Both declared builds match all three. This doesn't establish that every telemetry path is covered.
Hide ads and Sanitize sharing links also stop on competing inner targets. The failure lists the candidates so a changed build can be checked before installing it.
Morphe Manager signs the patched Threads with a key it makes on your phone. Android installs an update over your patched Threads only when the update carries that same key, so the key is what lets you update without losing Threads' data.
- Back it up right after your first patch. In Morphe Manager, open Settings, then System, then Import & export, then Signing key, and tap Export. Keep the
Morphe.keystorefile somewhere private, because anyone who has it can sign an APK your phone will accept as an update. - On a new phone, import it before you patch anything. Reinstalling Morphe Manager or clearing its storage makes a new key, and without your exported copy nothing you patched earlier can be updated in place.
- A different key means starting over. Android refuses an update signed with another key, so the only way forward is to uninstall the patched Threads and sign in again.
The same goes for the Threads you have now. A patched Threads can't install over the stock app, so uninstall the stock Threads first.
There are 6 patches, and every one of them is selected by default.
| Patch | What it does |
|---|---|
Disable analytics |
Redirects matched Pigeon, default event-log and MQTT analytics addresses. Settings show which address kinds were patched. Other telemetry may remain. |
Hide ads |
Takes sponsored posts out of your Threads feed before they're shown. |
HushThreads settings |
Adds HushThreads settings to Threads. Long-press Threads' launcher icon, or open Additional settings in the app on Threads' App info page, to turn features on or off, pause HushThreads, save your switches to a file or load them, and export diagnostics. The licenses are there too. |
Remove the advertising ID |
Stops Threads getting your phone's advertising ID from Google Play services. Threads gets a string of zeros in its place. |
Restore screens on re-signed builds |
Lets Threads trust itself again on a re-signed build, the way it trusts its Meta-signed self, and lets an Instagram you patch with this build's own key call into it the same as the real Instagram would. A Root Mount install doesn't need this patch. |
Sanitize sharing links |
Takes Threads' tracking tags, such as xmt, off the links you share or copy. The post a link opens stays the same. |
Long-press the Threads icon and tap HushThreads. You can also open Threads' App info page and tap Additional settings in the app, which Samsung phones call Configure in Threads.
Diagnostics list hook calls separately from removed ad posts and shared links that changed. Unchanged, disabled, paused or failed operations add no removal or change count. Reports keep these totals without saving the posts or URLs.
Tap Log in with Instagram and enter your Instagram username and password. On 2026-10-01, this reached a live feed for one account on Threads 449.0.0.54.82 with the published 0.0.2 bundle and all six tested source 0.0.3 configurations. The source checks covered settings plus Restore screens, each privacy patch added separately, and the full bundle. These checks ran on Android 16 beside signed-in stock Instagram 449.0.0.52.84.
Stock Threads and the full 0.0.2 and source 0.0.3 bundles also reached the feed through manual sign-in with Instagram absent.
On 2026-10-02, source builds declared both 448.0.0.54.85 and 449.0.0.54.82. Same-key updates between them preserved the signed-in account and switches on Android 16. Settings and live feeds passed on both. This checks a retained session; fresh password entry on 448 wasn't tested.
Threads can show Save your login info twice. Tap Not now on each prompt if you don't want to save it.
Stock Threads recovered that Instagram session automatically after its data was cleared. The patched builds offered the manual form, with no Continue as option. The same-key patched Instagram check on 2026-09-29 also offered only the manual form.
The password-login failure reported on 2026-10-01 remains unresolved. These successful checks haven't identified its cause or established login for every account.
Can Meta tell? Assume it can. A patched Threads is signed with your key rather than Meta's, and Threads' own code checks that signature in places, which is why Restore screens on re-signed builds exists. Disable analytics prevents uploads through matched address paths, and Meta could notice those missing events too.
What stays the same? Your feed still comes from Meta's servers, ads included, and HushThreads takes the ads out on your phone after they arrive. It doesn't post, like, follow or message on your behalf, and it doesn't change how you sign in.
Could my account be suspended? Nobody can promise it won't be. Meta's terms ask for its permission before anyone modifies its apps. We haven't heard of an account suspended over a patched Threads, but this is a young project, so that doesn't prove much. If you'd rather not risk the account you care about, try HushThreads with a test account first.
HushThreads doesn't collect anything and has no server. The patched app goes online on HushThreads' behalf for one thing only: the release check, and it's off until you turn it on. Once it's on, HushThreads asks api.github.com for its latest release at most once a day, when Threads starts, and again whenever you tap Check now. That's a plain HTTPS request with HushThreads/<version> as its User-Agent, and it carries no cookies and nothing about you or your phone. It only follows a redirect that stays on api.github.com, and it reads at most 256 KB of the answer. GitHub sees your IP address, as any site you visit does. From the answer, HushThreads keeps the version number and, if the notes name one, the Threads version the release targets. Nothing else is kept.
The About and Licenses screens link to github.com, gitlab.com and www.gnu.org. Those open in your browser, and only when you tap one.
Disable analytics replaces matched Pigeon, default event-log and MQTT analytics addresses with 127.0.0.1, on a port nothing listens on. Those uploads fail locally. Missing address kinds and other telemetry aren't covered by this claim. Turning the switch off, Pause or safe mode restores the original addresses.
On 2026-10-02, repeated enabled, off and paused feed sessions on Android 16 and Threads 449 showed failed local connections only when blocking was enabled. Short worker traces found no sustained analytics CPU retry storm. This doesn't establish long-term battery cost or queue behavior, so the interception stays unchanged.
HushThreads' build, settings, diagnostics and safety checks came from Hushfacebook at c15d4f79. That code carries the notices from Hushfeed, Andrew Liang's patches, FroggoMorphePatches and the Morphe/ReVanced chain recorded in NOTICE and provenance.json.
sources/threads-sources.json records 12 external sources across seven lineages, with forks and file mirrors grouped under their origins. Branch pins follow commits touching watched paths; separate head fields record inspected branch tips. No external Threads code is adopted. Hide ads uses the feed-cache merge location identified by zeldrisho, with an implementation written here.
| Source | What we found |
|---|---|
| ReVanced and Aunali321/ReVancedExperiments | GPL candidates for ad filtering. |
| chiggi_morphe_patches and zeldrisho/morphe-patches | GPL candidates with ad filtering, AD_ID permission removal and app/package renaming. |
| MrxSiN/ThreadsHideAds | GPL candidate using modern Xposed, DexKit and a compiled filtering policy. |
| NexAlloy and joel122002/ReVancedXposed | GPL candidates for Xposed ad filtering. |
| kareemlukitomo/morphe-patches | GPL candidate that changes the Threads share domain. |
| chirag127/morphe-patches | Rejected. Its Threads patches are stubs. |
| revanced-troubleshooting-guide | Rejected. It stores catalogs without an independent patch body. |
| yt-revanced-icon and rvmm-config-gen | Catalogs recorded as behavior-only. The former lacks a license; the latter uses AGPL-3.0, outside the ledger's accepted license list. |
The census remains dated 2026-09-29. Repository entries and all five discovery indexes were checked on 2026-10-02. All five list HushThreads. GitLab code search wasn't run.
Keep copyright, author, license and source notices when editing or moving files. Remove a notice only when its covered code is gone. Carry the GPL section 7 notices in NOTICE and make them available to users. Keep blocked original source URLs in notices, with a working GitLab mirror beside them.
Copied code keeps its headers and gets a Forked from line naming the repository and commit. Every shipped file needs one applicable provenance rule, its license and matching header links. A file rule takes precedence over a folder rule. Code written here must not claim an upstream origin. ProvenanceTest checks these requirements.
Before external code ships, mark its source adopted with the exact commit, compatible license URL/hash, NOTICE entry and provenance rule. A release receipt must prove patching on at least two real Threads fixtures and every declared build. Missing or incompatible licenses, and code derived from them, remain behavior-only. Mirrors inherit the original's disposition. Use the original repository URL and commit in notices and provenance.
Use JDK 21, the Android SDK and PowerShell. Set JAVA_HOME and ANDROID_HOME, or configure the SDK in local.properties. GitHub Packages requires GITHUB_ACTOR and GITHUB_TOKEN with read:packages.
Declared arm64 builds: 449.0.0.54.82 / 511908382 and 448.0.0.54.85 / 511808302.
$env:HUSHTHREADS_FIXTURE_DIR = '<fixture folder>'
$env:HUSHTHREADS_DESKTOP_JAR = '<Morphe desktop JAR>'
./gradlew.bat :patches:generatePatchesList
./gradlew.bat :patches:buildAndroid
./gradlew.bat :patches:test :extensions:threads:testDebugUnitTest
./gradlew.bat :extensions:threads:lintRelease :extensions:shared:library:lintRelease
./scripts/verify-all-patches.ps1 -Apk '<Threads bundle>' -DesktopJar '<Morphe desktop JAR>' -WorkDir '<scratch folder>'Generate the patch list before building. The bundle, SHA-256 and CycloneDX SBOM land in patches/build/release. Tests rebuild the jar in patches/build/libs. Keep private fixtures outside tracked files. Without HUSHTHREADS_FIXTURE_DIR, real-build tests skip.
Run verification on every retained build. It checks every selected patch, approved manifest changes, merged stock resources and injected DEX structure and feature contracts. Split merges use private input directories. Concurrent runs need separate outputs. Plain APKs are used directly.
Run scripts/build-release-receipt.ps1 and scripts/validate-release-facts.ps1 after the tests, lints and fixture verification. OSV checks every bundled library. HIGH/CRITICAL labels, CVSS 3 scores of 7.0 or higher, and unrated advisories stop release. Exceptions in scripts/advisory-exceptions.txt need a package, advisory, reason and expiry within 90 days. Expired or unmatched exceptions fail.
Run scripts/audit-threads-sources.ps1 when sources change. It stamps a clean census. Releases require a census no more than 14 days old. scripts/test-threads-sources.ps1 checks the ledger and source documentation.
scripts/install-hooks.ps1 installs the push checks. HUSHTHREADS_WORKDIR or build/morphe-tools can locate the desktop JAR. HUSHTHREADS_BUILD_WRAPPER optionally runs Gradle as <wrapper> -ProjectDir <repository> -Tasks <task>....
Device scripts require HUSHTHREADS_DEVICE_SERIAL and an exclusive lease. Set HUSHTHREADS_DEVICE_LEASE_DIR, HUSHTHREADS_DEVICE_LEASE_TOKEN and HUSHTHREADS_DEVICE_IDENTITY. Release the lease after testing. Signing conflicts require the installed key. Replacement installs are refused to preserve apps and accounts.
Local APK verification inspects every ELF's load segments and checks uncompressed native ZIP entries with the SDK's 16 KB alignment check. ZIP alignment determines load compatibility when Android loads libraries directly from the APK; extracted libraries still have their ZIP verdict recorded. Builds remove stale ZIP alignment declarations, align the unsigned APK, then sign and check the final APK. No native payload is rewritten. Receipts separate unchanged vendor ELF incompatibilities from packaging defects. These static checks don't establish runtime support on a 16 KB-page device.
scripts/patch-for-device.ps1 reads existing BKS, JKS and PKCS12 keys without converting them. HUSHTHREADS_SIDELOAD_KEYSTORE_PASSWORD supplies the store password; an explicitly empty value in PowerShell 7 selects an unprotected store. Set HUSHTHREADS_SIDELOAD_KEY_PASSWORD when the private entry uses a different password. Both travel through the process environment. The documented local test-key fallback applies only when the store password variable is unset.
Use Issues for bugs and Discussions for questions. Include the Threads version, version code and ABI, Morphe Manager and HushThreads versions, selected patches, reproduction steps and expected/actual behavior. Attach diagnostics or relevant screenshots after removing private messages and account details. Reports stay open until you or another user confirms the fix works.
Retain the new stable arm64 bundle and verify its identity and publisher signatures. Explore an undeclared build with:
./scripts/verify-all-patches.ps1 -Apk '<new bundle>' -Force -DesktopJar '<Morphe desktop JAR>' -WorkDir '<scratch folder>'
./scripts/fingerprint-candidates.ps1 -OldApk '<old bundle>' -Method '<method descriptor>' -NewApk '<new bundle>'Candidate ranking suggests methods to inspect. It changes nothing. Fix anchors and inner-target guards against the new and declared builds. Use kept names, strings, Pando fields or method shapes. ObfuscatedIdentityTest rejects hardcoded obfuscated identities.
Before declaring support, check every selected patch, settings, login and live feeds on the new and declared builds. Record the exact version name and arm64 version code in AppCompatibilities.kt, regenerate, rebuild and rerun the real-fixture checks and verification without -Force on every retained build.
GPL-3.0, with the Morphe section 7 notices carried in NOTICE. Threads, Instagram and Meta are trademarks of Meta Platforms, Inc.




