The federation API isn't using E2E either. It makes no difference if you use your mobile client to contact the mobile API or if you're hosting your own instance to use the federation API in safety regards. You should always be aware that every message / post / image you publish (even in a closed group) in the internet could be traced back to you and with enough afford be available to anybody with the right skills.
Only end to end encryption can help you there - this is the way.
Crypto, shouldn't make a such a big wave compared to receiving 1M on am anonymous source and quickly buying stock exchange with it