The problem is DMs. Having what appears to be a “private” communication mechanism that isn’t private at all might mislead users into divulging information that could put them at risk.
When you type up a DM on Mastodon, there’s a little popup notice that appears next to the text box that says:
Posts on Mastodon are not end-to-end encrypted. Do not share any sensitive information over Mastodon.
IMO the platform handles informing users about this responsibly.