not CPA-secure? Can an attacker ever obtain the sender's public keys or because the sender is from a channel with integrity (a private blockchain with known actors) the risk is nullified? are you possibly using some form of the more efficient and CPA-secure hybrid encryption techniques by encrypting the senders public key?