http://yw7nc56v4nsudvwewhmhhwltxpncedfuc43qbubj4nmwhdhwtiu4o6yd.onion/t/why-we-abandoned-matrix-the-dark-truth-about-user-security-and-safety/224
They specify which users are part of the room, which users are banned, the power levels of users, the name and the topic of the room, etc. These events aren’t e2ee and so, a malicious admin can both read them and send their own events by impersonating a user of their homeserver.