36-min capture · 6 outbound filings · 3 federal + 3 state channels

Now They Know You Know They Know

Six fraud reports filed simultaneously to the FBI IC3, the FTC, the US Postal Inspection Service, the Minnesota Attorney General, the Minnesota Office of the Legislative Auditor, and the Minnesota House Republicans Whistleblower Portal — every outbound POST captured at the wire, every form body preserved, every submission cryptographically locked into a hash chain anchored to the Bitcoin blockchain and signed by the Roughtime ensemble. All six destinations are now on the record.

6Destinations Looped In
279Hash-Chained Bundles
559OTS + RT Receipts
100%Validation Pass

Cryptographic receipt, not a complaint.

The fraud is documented across 33 forensic packets totaling hundreds of exhibits, a 2.9-million-row Postgres database built from the actual court PDFs, and a federal record sitting in front of three judges and an Eighth Circuit panel. None of which the Minnesota state-court machinery has acknowledged — by design.

So on the evening of 2026-05-13, the entire corpus was filed at the wire to six separate oversight channels — three federal, three Minnesota state — that each individually claim a mandate over precisely this kind of evidence. Filed live, on screen, every byte captured. Filed not because anyone is expected to act on it — but because once the receipts are cryptographically locked, they cannot be retroactively un-received.

The point of this page is the loop itself. The agencies now have the evidence. The receipt is on the Bitcoin blockchain. What they do with it is their problem.

The master packet (00) is what was attached to every submission. Read it. Read 33.

Loading viewer…

Six POSTs, six destinations, one 36-minute window.

MN House Republicans — Whistleblower Portal
Form: mnhouserepublicans.com/whistleblower-portal
POST: submit.jotform.com/submit/250440900874050
05:07 · HTTP 200 · primary statement
Minnesota Attorney General — Consumer Assistance
Form: ag.state.mn.us/Office/Forms/ConsumerAssistanceRequest.asp
POST: mnago.jotform.com/submit/91345668832163
10:35 · HTTP 200 · DKIM-verified auto-reply within 30s
US Postal Inspection Service — Cybercrime
Form: fcsexternal.uspis.gov/fcsexternal/externalcybercrime
POST: ExternalCybercrime?handler=PrintForm → handler=Save
15:52 + 16:50 · two-step (print + save) · HTTP 200 / 302
MN Office of the Legislative Auditor
Form: auditor.leg.state.mn.us/allegation.htm
POST: mnofficeofthelegislativeauditor.formstack.com/forms/index.php
20:10 · HTTP 200
FTC — ReportFraud
Form: reportfraud.ftc.gov/form/main
Confirmation PDF saved during session
~21–25 min · confirmation PDF at 25:06
FBI IC3 — Internet Crime Complaint Center
Form & POST: complaint.ic3.gov
34:39 · HTTP 302 · confirmation PDF at 35:05

Toggle the FORM SUBMIT VIEWER in DELIVERED to read the full parsed POST body of each submission as the recording reaches its capture moment — including the verbatim statement that landed in each intake queue.

What came back — confirmation PDFs captured live and sealed.

Loading viewer…

Hash-chain + dual independent timestamps.

OneWayVideo bundle hash-chain + dual-timestamp architecture
Click image to enlarge · zoom & pan · source: github.com/matt1up/one-way-video

The capture pipeline is OneWayVideo — a controller that runs Firefox routed through mitmproxy, records frames via the OBS virtual camera, and writes a numbered JSON "bundle" every ~7 seconds. Each bundle carries:

The First-Link Nonce

Bundle 0000 opens with a 1000 ms dump of system-time nanoseconds — ~100 rows of consecutive monotonic-clock readings used as the chain's seed nonce. Nothing is guessable about the seed; it is the machine's own clock at the moment the recording began.

The Hash Chain

Each bundle includes the SHA-256 of the previous bundle. That same prior-bundle hash is also printed in a narrow OBS overlay window — so the chain is baked into the video pixels as well as into the bundle JSON. Both must agree or the chain visibly breaks on screen.

OpenTimestamps · Bitcoin

Each bundle hash gets an .ots proof. After the recording, those proofs upgrade against the Bitcoin blockchain. The Fraud-Reports session is anchored to block 949,319 — header timestamp 2026-05-14 00:06:03 CDT. 559 / 559 OTS receipts validate.

Roughtime — Tightens the Window

A Bitcoin block alone gives a ~2-hour trustless time window (block MTP rules). The Roughtime ensemble (Cloudflare, Google, INT2, and independent NIST-style servers) signs the .ots file itself with a ±1-second midpoint window — timestamping the timestamp. 559 / 559 RT tickets pass cert + srep + merkle + window validation.

The Vault

Every downloaded file (here: 6 form-confirmation PDFs) is wrapped into a digitally-signed PDF using a self-issued X.509 certificate with subject CN=Matthew David Guertin, OU=Minnesota Judicial Fraud Exposed, O=CourtListener Docket 70633540. pdfsig reports Signature is Valid on every vault.

Multiple Independent Chains

Live network packet capture, HTTP stream metadata, OBS PNG hashes, bundle JSON chain, OTS Bitcoin anchoring, Roughtime ensemble, on-screen hash overlay, and self-signed vault PDFs — eight independent provenance layers. Tampering with one is exposed by the others.

Everything that was submitted, plus the back-end that proves it.

Each of the buttons below opens an in-page viewer with the actual PDFs. The first three hold infrastructure exhibits — the full Postgres database export, its source files, the authentication chain, and the project-pipeline documentation. PACKETS & FILES contains the 35 "stuffed" packets with their entire zipped evidence folders embedded directly inside each PDF. PACKETS is the same 35 as a lightweight read-only set.

Loading viewer…

One stream is contaminated. It doesn't change anything.

The session's streams.http_events field contains data captured by a mitmproxy log ~8 hours before the recording began — a source-file misconfiguration in the bundle writer pulled from the wrong file. The contaminated content is hash-locked into the bundle chain, so it remains cryptographically authentic — it just isn't from this session.

It doesn't matter. Seven other independent provenance layers (live streams.net, live streams.http, OBS PNG hash chain, bundle SHA-256 hash chain, on-screen hash overlay, OpenTimestamps Bitcoin anchoring, and the Roughtime ensemble) all line up perfectly to the same recording timeline. Any tampering with the recording itself would break all of them at once. The http_events miss is acknowledged precisely because the redundancy makes it acknowledgeable — the rest of the record holds independently.

The Attorney General's office sealed it for us.

Roughly 30 seconds after the JotForm POST to mnago.jotform.com landed at 10:35 in the recording, the Office of the Minnesota Attorney General's auto-reply landed in the inbox at 2026-05-13 23:52:33 EDT (= 03:52:33 UTC) — inside the same 36-minute capture window, with submission ID 6545399494205897880 embedded in the subject line.

The State of Minnesota Attorney General's official mail server, running through Microsoft's outbound.protection.outlook.com, sent a DKIM-signed message to the address:

[email protected]

The literal email address branded with the URL of this exact site documenting the fraud. Receipt was confirmed on their domain, to ours, with a 2048-bit cryptographic signature. That is on the public record now.

The reply passed DKIM (2048-bit RSA-SHA256, key selector2.ag.state.mn.us), SPF (smtp.mailfrom=ag.state.mn.us), DMARC (p=none), and ARC on the Microsoft outbound route. The full source — every header, every signature blob, every Authentication-Results line — is preserved below for direct inspection:

Download original .eml DKIM-signed source · 13.3 KB · SHA-256: ac952dd3…40d73

That email is the State of Minnesota's own cryptographic signature on a piece of paper that says we received this. It is in our possession. It will not be going anywhere. The same loop closes individually with each of the other five destinations via their respective confirmation pages, all captured and hash-locked.

The reply itself is a textbook artifact of bureaucratic administrative Newspeak"thank you for your submission... while this Office can not respond to every complaint... appropriate staff." No commitment. No timeline. No acknowledgement of the actual content. The form letter does precisely what form letters do. The cryptographic signature on it, however, is real — and that is what we needed.

The receipts are signed.
The hashes are chained.
Now they know you know they know.
Speed 1.00x 0:00 / 0:00 🔊
OBS Screenshot
---
---
HTTP ---
NETWORK ---
POST ---
DOWNLOADS ---