The biggest is definitely the fact that a vast majority of its relays are run by the company, which is a for profit company that kinda just showed up out of nowhere. The tech itself seems solid but it's concening to me that the relays are overwhelmingly run by the company.
Also, unlike Session, itd be incredibly easy for governments to set up honeypot relays. If I'm not mistaken, there isn't any onion routing in SimpleX, meaning they wouldn't even need to do a sybil attack to know metadata like your IP.