Maybe because tox is developed by people who don't know what they're doing.
Money quote from a tox dev:
"Tox provides some strong security guarantees. We haven't got to the point where we can enumerate them properly, given the general lack of understanding of the code and specification."
I once tried to read their "protocol documentation" and realised that it was effectively non-existant and the only way to understand what was going on was to read the toxcore code which was written by 4chan.
I'm not a crypto expert, but I also personally wouldn't put much stock in the security of their protocol or implementation.
Money quote from a tox dev: "Tox provides some strong security guarantees. We haven't got to the point where we can enumerate them properly, given the general lack of understanding of the code and specification."
https://github.com/TokTok/c-toxcore/issues/426