Six fraud reports filed simultaneously to the FBI IC3, the FTC, the US Postal Inspection Service, the Minnesota Attorney General, the Minnesota Office of the Legislative Auditor, and the Minnesota House Republicans Whistleblower Portal — every outbound POST captured at the wire, every form body preserved, every submission cryptographically locked into a hash chain anchored to the Bitcoin blockchain and signed by the Roughtime ensemble. All six destinations are now on the record.
The fraud is documented across 33 forensic packets totaling hundreds of exhibits, a 2.9-million-row Postgres database built from the actual court PDFs, and a federal record sitting in front of three judges and an Eighth Circuit panel. None of which the Minnesota state-court machinery has acknowledged — by design.
So on the evening of 2026-05-13, the entire corpus was filed at the wire to six separate oversight channels — three federal, three Minnesota state — that each individually claim a mandate over precisely this kind of evidence. Filed live, on screen, every byte captured. Filed not because anyone is expected to act on it — but because once the receipts are cryptographically locked, they cannot be retroactively un-received.
The point of this page is the loop itself. The agencies now have the evidence. The receipt is on the Bitcoin blockchain. What they do with it is their problem.
The master packet (00) is what was attached to every submission. Read it. Read 33.
Toggle the FORM SUBMIT VIEWER in DELIVERED to read the full parsed POST body of each submission as the recording reaches its capture moment — including the verbatim statement that landed in each intake queue.
What came back — confirmation PDFs captured live and sealed.
The capture pipeline is OneWayVideo — a controller that runs Firefox routed through mitmproxy, records frames via the OBS virtual camera, and writes a numbered JSON "bundle" every ~7 seconds. Each bundle carries:
Bundle 0000 opens with a 1000 ms dump of system-time
nanoseconds — ~100 rows of consecutive monotonic-clock readings used
as the chain's seed nonce. Nothing is guessable about the seed; it is the
machine's own clock at the moment the recording began.
Each bundle includes the SHA-256 of the previous bundle. That same prior-bundle hash is also printed in a narrow OBS overlay window — so the chain is baked into the video pixels as well as into the bundle JSON. Both must agree or the chain visibly breaks on screen.
Each bundle hash gets an .ots proof. After the recording, those
proofs upgrade against the Bitcoin blockchain. The Fraud-Reports session
is anchored to block 949,319 — header timestamp
2026-05-14 00:06:03 CDT. 559 / 559 OTS receipts validate.
A Bitcoin block alone gives a ~2-hour trustless time window
(block MTP rules). The Roughtime ensemble (Cloudflare, Google, INT2, and
independent NIST-style servers) signs the .ots file itself
with a ±1-second midpoint window — timestamping the
timestamp. 559 / 559 RT tickets pass cert + srep + merkle + window
validation.
Every downloaded file (here: 6 form-confirmation PDFs) is wrapped into a
digitally-signed PDF using a self-issued X.509 certificate
with subject
CN=Matthew David Guertin, OU=Minnesota Judicial Fraud Exposed,
O=CourtListener Docket 70633540. pdfsig reports
Signature is Valid on every vault.
Live network packet capture, HTTP stream metadata, OBS PNG hashes, bundle JSON chain, OTS Bitcoin anchoring, Roughtime ensemble, on-screen hash overlay, and self-signed vault PDFs — eight independent provenance layers. Tampering with one is exposed by the others.
Each of the buttons below opens an in-page viewer with the actual PDFs. The first three hold infrastructure exhibits — the full Postgres database export, its source files, the authentication chain, and the project-pipeline documentation. PACKETS & FILES contains the 35 "stuffed" packets with their entire zipped evidence folders embedded directly inside each PDF. PACKETS is the same 35 as a lightweight read-only set.
The session's streams.http_events field contains data captured by a
mitmproxy log ~8 hours before the recording began — a source-file
misconfiguration in the bundle writer pulled from the wrong file. The contaminated
content is hash-locked into the bundle chain, so it remains cryptographically
authentic — it just isn't from this session.
It doesn't matter. Seven other independent provenance layers (live
streams.net, live streams.http, OBS PNG hash chain,
bundle SHA-256 hash chain, on-screen hash overlay, OpenTimestamps Bitcoin anchoring,
and the Roughtime ensemble) all line up perfectly to the same recording timeline.
Any tampering with the recording itself would break all of them at once. The
http_events miss is acknowledged precisely because the redundancy
makes it acknowledgeable — the rest of the record holds independently.
Roughly 30 seconds after the JotForm POST to mnago.jotform.com landed
at 10:35 in the recording, the
Office of the Minnesota Attorney General's auto-reply landed in the inbox at
2026-05-13 23:52:33 EDT (= 03:52:33 UTC) —
inside the same 36-minute capture window, with submission ID
6545399494205897880 embedded in the subject line.
The State of Minnesota Attorney General's official mail server, running through
Microsoft's outbound.protection.outlook.com, sent a DKIM-signed
message to the address:
The literal email address branded with the URL of this exact site documenting the fraud. Receipt was confirmed on their domain, to ours, with a 2048-bit cryptographic signature. That is on the public record now.
The reply passed DKIM (2048-bit RSA-SHA256, key
selector2.ag.state.mn.us), SPF
(smtp.mailfrom=ag.state.mn.us), DMARC
(p=none), and ARC on the Microsoft outbound route.
The full source — every header, every signature blob, every
Authentication-Results line — is preserved below for direct inspection:
That email is the State of Minnesota's own cryptographic signature on a piece of paper that says we received this. It is in our possession. It will not be going anywhere. The same loop closes individually with each of the other five destinations via their respective confirmation pages, all captured and hash-locked.
The reply itself is a textbook artifact of bureaucratic administrative Newspeak — "thank you for your submission... while this Office can not respond to every complaint... appropriate staff." No commitment. No timeline. No acknowledgement of the actual content. The form letter does precisely what form letters do. The cryptographic signature on it, however, is real — and that is what we needed.