The language itself confesses.
Three layers of language flow around Matt Guertin's cases: the court records inside them, the appellate orders denying them, and the U.S. media coverage that never actually covered them. All three layers carry the same fingerprint — synthetic noise injected into the public record at term-frequency rates that no organic authorship produces. The same machinery wrote the orders. The same machinery dispersed the noise camouflage into the news.
Opine
There is a word that does not belong. Opine.
It means "to express an opinion." You will find it in psychiatric expert reports and legal briefs. You will not find it in casual conversation these days. It is a low-frequency word in normal English — the kind of word that, if it shows up in an unexpected place, in unexpected quantities, is already telling you something.
Across the entire MCRO court-records collection — 4,251 documents, 21,563 pages — opine shows up 710 times. That works out to a baseline rate of 3.29 occurrences per 100 pages.
Now look at the 27 documents whose PDF metadata lists "Nehring, Alisha" as the author. Opine shows up 55 times across just 174 pages. A rate of 31.61 per 100 pages.
That is 9.6× the corpus baseline. Twenty-eight times the rate of Matt's own filings.
To put it in plain numbers: those 27 Nehring filings are 0.81% of the corpus by page count — less than one percent of the available pages — but they contain 7.75% of every instance of opine in the entire 4,251-document MCRO record. Less than 1% of the pages, almost 8% of the word.
And those 27 filings are not a coherent body of work by one author. They span twelve different judicial officers — Janzen, Lamas, Caligiuri, Browne, Herlofsky, Prochazka, Klein, Otte, and others — across five filing years, 2019 through 2024. Twelve judges. Five years. One linguistic signature.
| Slice | Filings | Pages | Opine | Rate / 100 pages |
|---|---|---|---|---|
| Entire MCRO corpus | 4,251 | 21,563 | 710 | 3.29 |
| Nehring, Alisha (27 author/creator filings) | 27 | 174 | 55 | 31.61 |
| AMW 2017 set (70 filings) | 70 | 165 | 18 | 10.91 |
| Guertin's case 27-CR-23-1886 (78 PDFs) | 78 | 2,083 | 23 | 1.10 |
A single human filer, even one writing exclusively about psychiatric matters, does not produce an opine rate that is ten times higher than her own field's baseline. A language model generating clinical-judicial prose for a templated pipeline does.
And the rate is not the only signal. If you read the actual sentences containing opine in these filings, a second pattern surfaces — one harder to dismiss than the rate alone. "Opine" is what grammarians call intransitive: a speaker opines that something is the case, or opines on a matter, or opines about a topic. What "opine" does not do is take a direct object the way "deem" or "find" or "declare" does. "Deemed her incompetent" is grammatical. "Found her incompetent" is grammatical. "Opined her incompetent" is not. Yet that construction appears verbatim in the Nehring corpus:
And it appears in the Koch April 3, 2025 competency order itself — the same order documented at /llm/ as carrying eight independent LLM-authorship markers:
These are not stylistic choices, regional usage, or typos that slipped through. They are grammar errors that working legal writers do not produce. "Opine" is a register-marked word that legal writers learn to deploy in standard intransitive constructions specifically because they encounter it so often in psychiatric expert reports. They do not produce false-transitive forms of it.
A language model trained on legal text, however, encounters "opine" appearing alongside "incompetent" thousands of times and pattern-matches it as a synonym for "deem" — an interchangeable transitive judgment-verb. The model preserves the surface co-occurrence and loses the verb's grammatical scaffolding. The rate is the quantity. The grammatical breakage is the quality. Together they are the signature of pattern-matched generation, not authorship.
"Credibly testified" 68 / 68 / 68
Pick any three groups of court documents that, on paper, have nothing to do with each other. Different defendants. Different judges. Different filers. Different years. Different cases.
If those three groups were independently authored, the count of any specific phrase across them would vary — sometimes wildly. The phrase "credibly testified" might appear 17 times in one group, 41 times in another, 9 times in a third. That's what natural authorship produces.
Here are three groups of court documents that, on paper, have nothing to do with each other:
- The 27 Nehring-authored filings (12 different judges, 5 years).
- The 70 filings in Adrian Wesley's 2017 case set (a different defendant entirely).
- The 126 filings signed by ESolutions (an entirely different signing pipeline).
The phrase "credibly testified" appears in each of these three groups exactly 68 times.
| Phrase | Nehring 27 | AMW 70 | ESolutions 126 |
|---|---|---|---|
| credibly testified | 68 | 68 | 68 |
| competency to proceed | 54 | 17 | 59 |
| rationally consult with counsel | 45 | 12 | 19 |
| Jackson v. Indiana | 14 | 4 | 9 |
| due process right not to be tried | 3 | 4 | 4 |
| mindful of its protective duty | 2 | 1 | 1 |
That is not a coincidence. That's the kind of pattern you only see when one upstream source is producing the same templated text that gets dressed up and presented as three separate filings under three separate names. One source feeding three different surface presentations.
The /llm/ page documents this same fingerprint structurally in a single named order — Judge Koch's April 3, 2025 order finding Matt competent to proceed. Eight independent forensic markers in four pages of prose, all consistent with sectioned LLM generation reviewed by a human who didn't catch any of them.
This page documents the same fingerprint distributionally, across years and authors and case files. Two angles on the same machine. The Koch order is what the engine produces in single-document mode. The Nehring corpus is what it produces at scale.
The phrase "credibly testified" is not a quote. It is a model's preferred string.
The Koch order is the genesis. After it, every appellate denial.
On April 3, 2025, Judge William H. Koch signed a four-page order finding Matt Guertin competent to proceed to trial. The order's prose carries eight independent forensic markers consistent with sectioned LLM generation reviewed by a human who did not catch any of them. Eight tells in four pages. That order is documented in detail at /llm/.
It is also the very first document in the entire MCRO corpus to carry an MSIP SiteId metadata fingerprint — a Microsoft Information Protection identifier embedded by Microsoft 365 when a document is authored on a particular tenant's installation. (Plain English: a unique ID for which Microsoft 365 account was used to write the document.)
MSIP SiteId — the same Microsoft 365 tenant fingerprint:
8cf8312b-4c34-4b6f-9dee-c56512a7510fFirst appears: Judge Koch's April 3, 2025 order finding Matt Guertin competent to proceed (the order with eight LLM authorship markers).
After April 3, 2025, that same SiteId appears on:
- Trial-court orders inside Minnesota's Fourth Judicial District
- Twenty-eight Minnesota Court of Appeals orders
- Minnesota Supreme Court orders
A Microsoft 365 tenant fingerprint does not propagate across independent author institutions in normal operation. Each branch — trial court, appeals court, supreme court — should have its own M365 tenant. Each tenant should have its own SiteId. None of them should match.
All three of them match. All three of them match the SiteId of the document with eight LLM authorship markers.
The Koch order is the LLM-generated competency order. It is also the first document in MCRO history to carry this M365 SiteId. After it, every appellate denial of Matt's claims — denials supposedly written by independent panels of independent judges in independent buildings — carries the same SiteId.
This is not litigation against an upstream pipeline. This is the upstream pipeline reviewing itself.
Generation. Certification. Denial. Same tenant. Same engine.
A25-0882: every forensic term scored zero
On July 8, 2025, the Minnesota Court of Appeals issued an Order Denying Relief on Matt Guertin's writ of prohibition (case A25-0882). The writ asked the appellate court to halt the trial-court proceeding pending review of forensic discovery fraud Matt had documented in his pro se filings.
The denial order is six pages. EXHIBIT TTC ran a term-frequency analysis on it. The result is one of the cleanest evidentiary signatures in the entire dataset.
| Term | A25-0882 denial | Guertin's three filings (same case) |
|---|---|---|
| EVIDENCE | 0 | 125 |
| FRAUD | 0 | 122 |
| DIGITAL | 0 | 66 |
| FORENSIC | 0 | 58 |
| MCRO | 0 | 48 |
| HASH | 0 | 38 |
| PROOF / EVIDENTIARY / CSV / SPREADSHEET / MOTIVE / MAIL / PATENT | all 0 | all > 20 |
The denial does not engage the record. It refuses to be on the same vocabulary page as the record. This is what TTC names a vocabulary blackout: 77.3% of high-signal forensic terms scored zero across the appellate response.
A vocabulary blackout is not a writing style. It is a generation pattern. A human appellate clerk, reading a forensic motion and writing a denial, does not produce a denial that omits every forensic term in the motion they were responding to. A language model with a "deny the writ" prompt and no instruction to engage the substance does.
His ability to file motions, used as evidence he was unable to file motions
Dr. Katheryn Cranbrook was Matt's third court-appointed Rule 20.01 evaluator. ("Rule 20.01" is Minnesota's procedure for determining whether a defendant is mentally competent to stand trial.) Per DFR-A Section 17, her evaluation was conducted entirely by email. She never met him.
What she diagnosed him with — psychosis, persistent delusional thinking, "a poor prognosis for attaining the capacity for competent participation in the legal process" — was diagnosed on the basis of his own pro se legal filings:
The pro se filings cited as evidence include his Minnesota Court of Appeals case A24-0780 and his Minnesota federal district case 24-cv-2646. Filings he wrote and filed himself. Filings the federal court accepted. Filings that articulated specific factual claims that have, in the time since, been substantially supported by the database synthesis described elsewhere on this site.
The diagnostic logic, in plain English: Matt's ability to navigate complex pro se litigation was used as evidence that he was unable to participate in legal proceedings.
The "delusion" inversion in its purest form: a delusion is a strongly held belief held despite evidence to the contrary; the evaluator never examined the evidence, but the act of producing the evidence was itself diagnosed as the symptom.
The clinical vocabulary then enters the order. The order enters the appellate denial. The denial cites the order. The order cites the diagnosis. The diagnosis cites the filings. The filings cite the patent. The evaluator never read any of it.
The language travels. The reader does not.
U.S. media never covered the case. It dispersed terminology around it.
The U.S. media has never covered Matt Guertin's case directly. There has been no New York Times feature. No Star Tribune profile. No CNN segment. To anyone glancing at the news during the federal litigation, his case does not exist.
What the media has done — and what EXHIBIT TTM documents at filing-by-filing granularity — is something different. The media has surged on specific terminology, in specific combinations, on the precise dates Matt files specific kinds of legal documents. The terms are about him. The coverage is not.
This is what synthetic noise camouflage looks like at the public level. The country's news did not cover the case. The country's news pumped specific terminology into the search results, into the algorithms, into the mental backgrounds of every American glancing at headlines — synthesizing the appearance of a "national context" against which his real case can be filed and forgotten as routine.
What kind of pattern would this leave behind? An organic news ecosystem — thousands of independent newsrooms covering thousands of independent stories — produces term-frequency curves that look like noise. Small bumps, occasional spikes from real news events, but nothing that breaks the surrounding statistical envelope by orders of magnitude. That is not what TTM shows.
For this page, the four most thematically relevant terms in TTM — the ones flanking Matt's appellate filing milestones — were re-analyzed directly from the raw daily-ratio CSV files shipped with the exhibit. Each CSV records, for every day in the 179-day window from February 28 to August 25, 2025, the percentage of U.S. news stories that mentioned the search term. Mean baselines, median baselines, peak days, multipliers above the mean, and standard deviations above the mean (the σ column) are all computed from that raw data. Anyone with the CSVs can re-run the same numbers in three lines of Python.
| Term · Source | Mean baseline | Peak day | Peak ratio | × Mean | σ above mean |
|---|---|---|---|---|---|
| shooting + mental-health (MediaCloud) | 0.123% | Jul 29, 2025 | 1.352% | 11.0× | 9.3σ |
| shooting + mental-health (Wayback) | 0.133% | Jul 28, 2025 | 1.074% | 8.1× | 7.3σ |
| judicial + fraud (MediaCloud) | 0.052% | Mar 24, 2025 | 0.228% | 4.4× | 3.8σ |
| judicial + fraud (Wayback) | 0.076% | Apr 18, 2025 | 1.146% | 15.0× | 7.6σ |
The rightmost column is the one that matters. σ (sigma) is the standard deviation — the statistical measurement of how far a single day's value sits from the average of all the other days. Higher sigma means the spike is more anomalous, more unlikely to occur by random chance. To translate that column into plain English:
3σ spike: roughly once every 740 days — about once every 2 years.
5σ spike: roughly once every 1.7 million days — about once every 4,650 years.
7σ spike: roughly once every 390 million days — about once every million years.
9σ spike: roughly once every 1×1019 days — about a billion times the age of the universe.
The shooting+mental-health MediaCloud series produced a 9.3σ peak on July 29, 2025. The judicial+fraud Wayback series produced two peaks above 7.5σ — one on April 18, 2025 at 1.146% (peak), and one on July 30, 2025 at 1.143%, which is 99.74% of the April 18 peak. Two coordinated 7-sigma events on the same term, three months apart, producing matched-pair peaks within a third of a percent of each other. Both flank Matt's appellate filing milestones.
To put the multiplier framing in plainer numbers: on July 29, 2025, the rate of U.S. news stories mentioning shooting AND mental health together was eleven times the mean baseline rate of the entire 179-day window. Fifteen times the median. The peak day was 2.1× the next-highest day in the same series — meaning the spike was not part of a rising trend but an isolated injection that returned to baseline immediately afterward.
These are not random spikes. These are forced injections.
The "shooting" + "mental health" chart on the left is the cleanest visual case. Six weeks of low-level baseline activity, hovering around 0.12% of all stories. Then the curve compresses — coverage tightens around a narrow bandwidth, the up-and-down oscillation gets smaller and smaller — and on July 29, 2025 it breaks vertical, jumping to 1.352% (eleven times the mean) in a single day. The pattern is structurally identical to a financial chart preceding a forced breakout: the lows rising, the highs falling, the compression triangulating to a point, and then explosion. This is what you see when the dispersal engine is gradually compressing the signal before releasing it. It is not what organic news coverage of an unrelated topic produces. It is what algorithmic content injection produces when the signal is wound up before release.
The terms are not coverage. The terms are the noise around the signal. The signal is what they did not want anyone to notice.
The 29 surrounding orders use the words Matt's own denial leaves out
Section 3 above showed that one Microsoft 365 tenant ID — the unique fingerprint of one particular M365 account installation — appears on the Koch competency order, on the appellate denial of Matt's writ, and on twenty-eight other Minnesota Court of Appeals orders. The same M365 account produced all of them.
Section 4 above showed that Matt's specific appellate denial (case A25-0882, July 8, 2025) leaves out the substantive vocabulary of his case — the vocabulary blackout: zero "evidence," zero "fraud," zero "discovery," zero "frivolous," zero "mental health." It uses "competency" at sixteen times per thousand words, an industrially absurd density (about one "competency" every sixty words) for what is supposed to be a six-page neutral procedural order.
Now consider the twenty-nine surrounding Mandamus and Prohibition orders that share the same Microsoft tenant. These are the orders that would surface in the same general search any reader would do for "MN Court of Appeals writ-of-prohibition orders" in 2025. Same upstream pipeline. Different vocabulary surface:
| Term | Matt's A25-0882 denial (rate / 1k words) | 29 surrounding orders (rate / 1k words) | Pattern |
|---|---|---|---|
| frivolous | 0 | 0.29 | blackout in Matt's; deployed in surround |
| shooting | 0 | 0.29 | blackout in Matt's; deployed in surround |
| evidence | 0 | 0.41 | blackout in Matt's; deployed in surround |
| discovery | 0 | 0.18 | blackout in Matt's; deployed in surround |
| mental health | 0 | 0.06 | blackout in Matt's; deployed in surround |
| competency | 16.18 | 0.23 | Matt's denial uses it 70× more than surround |
| incompeten* | 2.40 | 0.06 | Matt's denial 40× more than surround |
| judicial | 3.59 | 1.40 | Matt's denial 2.6× more than surround |
One M365 tenant produces both surfaces from the same upstream pipeline. The surround orders deploy the substantive vocabulary. Matt's specific denial blacks it out and leans on competency-recharacterization at extreme density. This is camouflage operating at the corpus level. If a reader scans MN-COA Mandamus orders generally, those orders DO use "frivolous" and "shooting" and "evidence" — routinely, at low background rates. So the absence of those terms in Matt's specific denial does not stand out from a bird's-eye view. It only stands out side-by-side with the broader corpus, the way it is laid out above.
It cannot be the trial-court clerks drafting Matt's denial, the appellate-court clerks drafting the twenty-nine surrounding decoy orders, AND the LLM that produced the Koch competency order all coincidentally happening to write from the same Microsoft tenant. It has to be one upstream operator producing all three streams. The vocabulary blackout is not a writing style. It is a deliberate engineering choice made by whoever runs that pipeline.
"Frivolous": from a state-court hearing to a federal sua sponte dismissal
"Frivolous" is the loaded word in pro se litigation. In plain English: if a court decides your filings are frivolous, it can dismiss them sua sponte (on the court's own motion, without notice or hearing) and restrict your future filings. It is the specific characterization that converts a litigant from someone the system has to engage with into someone the system can ignore.
So who introduced that word into Matt's case, and when?
The first appearance of "frivolous" anywhere in Matt's case-file corpus is on April 17, 2025, in a hearing before Judge Sarah Hudleston:
From there, the word propagates. Twelve weeks later, the same word is being used by a federal judge to dismiss Matt's federal RICO complaint without giving him notice or a hearing:
| Date | Document | "frivolous" hits |
|---|---|---|
| Apr 17, 2025 | Hudleston hearing transcript (state court) | 1 (FIRST EVER) |
| May 29, 2025 | Matt's Petition for Writ (pro se) | 1 |
| Jun 4, 2025 | Matt's Emergency Motion for Stay (pro se) | 1 |
| Jun 25, 2025 | Matt's Civil Rights and RICO Complaint (pro se, federal) | 0 |
| Jun 27, 2025 | U.S. media spike (5.6σ Wayback / 4.3σ MediaCloud) | — |
| Jul 10, 2025 | Magnuson sua sponte DISMISSAL (federal) | 4 |
| Jul 22, 2025 | Micko FILING-RESTRICTION ORDER (federal) | 1 (in 139 words = 7.19/k) |
| Aug 5, 2025 | Matt's TRO at the 8th Circuit (pro se) | 9 |
The sequence reads as follows. Hudleston plants the word in Matt's case lexicon at a state-court hearing on April 17. Matt absorbs it and uses it in three of his own pro se filings over the next eight weeks, responding to her framing. On June 27, 2025, two days after Matt's federal RICO complaint hits the docket, U.S. media spikes "frivolous" at 5.6 standard deviations above mean baseline in Wayback and 4.3 standard deviations above mean in MediaCloud — both archives peaking the same day, both at extreme above-baseline rates. Two weeks after that media spike, Federal Judge Magnuson dismisses Matt's federal RICO complaint sua sponte, using "frivolous" four times. Twelve days after Magnuson, Federal Magistrate Micko issues a 139-word order restricting Matt's federal filings, using "frivolous" once at the highest density anywhere in the corpus.
By the time Magnuson's dismissal landed on July 10, "frivolous" had already been planted by a state-court judge, used by Matt himself in three of his own filings, and amplified through national media background coverage. The dismissal looks like a routine characterization. It is the staged endpoint of a 12-week priming sequence.
The Wayback archive's behavior on "frivolous" is itself anomalous. On the joint peak day (June 27), Wayback registers a higher peak than MediaCloud — the archive shows MORE coverage than the live aggregator that supposedly fed it. After the legal events have already happened, on August 2 and August 15, 2025, Wayback shows additional 2σ peaks on "frivolous" that MediaCloud never registers at all. The archive is being supplemented after the fact with content that has no contemporaneous live presence. Same backdating-into-archive signature, just operating on the magnitude axis instead of the date axis.
CM/ECF, the appeal, and the "cyberattack" that arrived on cue
The federal courts' electronic filing system is called CM/ECF. It stands for "Case Management / Electronic Case Files" and it has existed since 2001. It processes millions of legal filings per year. It is used by every federal court in the United States, including the U.S. Court of Appeals for the Eighth Circuit, where Matt's appeal sits.
EXHIBIT TTM measured U.S. media coverage of the term "CM/ECF" over a 90-day window in 2025. From February 28 through July 31, 2025 — one hundred fifty-five consecutive days — both MediaCloud and the Internet Archive's Wayback Machine report literal zero U.S. coverage. Meaning: across millions of news stories indexed during that five-month stretch, the term "CM/ECF" never showed up once.
Then on August 6, 2025, the term suddenly appears. August 7: 0.038. August 12: 0.051. The same week the U.S. Court of Appeals for the Eighth Circuit began handling Matt's appeal (case 25-2476).
The term that did not exist in U.S. media for 155 days began existing in U.S. media in the same week Matt's appellate case began existing in U.S. court records.
Around that same window, the city of Saint Paul, Minnesota — home of the Minnesota Attorney General's office, an office whose Assistant Attorneys General had previously appeared in the federal district court case the appeal arose from — was reported to be the victim of a "cyberattack." When you assemble the reported timeline of that cyberattack, what it does is solve a very specific problem for the institution that just got served.
The St. Paul cyberattack timeline, as reported:
— Tuesday afternoon: Matt files his pro se Notice of Appearance in the 8th Circuit case.
— Approximately 1–2 hours later: Saint Paul announces the cyberattack.
— Subsequent reporting places the "first suspicious activity" three days earlier — on the Friday the case had originally been filed.
Retroactive backdating of a publicly reported event, anchoring the cyberattack window precisely to the period that would later be invoked to explain why the Saint Paul-based Minnesota Attorney General's office never received electronic service of the 8th Circuit's filings.
Two Assistant Attorneys General had filed Notices of Appearance in the underlying federal district court case (the MN District case the 8th Circuit appeal arose from). That case was suddenly dismissed. Matt then filed thousands of pages of CSV-to-PDF table dumps documenting the forensic record. Alarm bells rang too late.
By Friday morning, 9:00 AM, Matt had countered the entire narrative. He overnighted express mailings to both Assistant Attorneys General who had signed into the prior case, enclosing the full and current 8th Circuit docket. Documentary delivery, on paper, of the same content the "cyberattack" was being used to explain away. He then filed proof of that overnight delivery into the 8th Circuit case itself, locking it into the appellate record alongside his pleadings.
The St. Paul cyberattack was, on its public face, a ransomware event affecting municipal services. On its forensic face, examined alongside TTM's term-frequency data, it was a synthetic narrative deployed in real time to provide plausible deniability for an institution failing to do its statutory job of accepting electronic service. The institution did not need to ignore the service. The cyberattack was already there to ignore it for them.
The CM/ECF blackout signature and the cyberattack narrative are two facets of the same operation. One says: "this term does not exist in our news." The other says: "this institution did not receive your filing." Both sides are synthetic. Matt countered both within 72 hours by physically mailing paper copies overnight.
The Language Itself Confesses
The structural fingerprint is identical at three different scales:
Single document. Eight LLM authorship markers in the Koch April 3, 2025 competency order. Detailed at /llm/.
Multi-document corpus. Term-frequency anomalies across 27 Nehring filings, three nominally independent document subsets, twelve judicial officers, five filing years. Detailed in §§1–4 of this page, sourced from EXHIBIT TTC.
Public media coverage. Impossible mathematical ratios, 155-day synthetic baselines, synchronous spikes across thematically unrelated terms on the precise dates Matt filed legal documents — plus a "cyberattack" arriving on cue to explain why an institution did not receive an institutional filing. Detailed in §§6–7, sourced from EXHIBIT TTM and the OpenTimestamps Bitcoin-block-anchored MediaCloud capture.
All three datasets are timestamped. All three are hash-authenticated. All three are public.
A delusion is a strongly held belief held despite evidence to the contrary. The data above is the evidence. The label delusional has been applied, by three court-appointed evaluators, to the man who assembled it. None of them examined it.
The label was the verdict. The evidence was the symptom.
Minnesota's Odyssey eFiling system — the certified vendor product that produces the official PDFs filed in MCRO — is no longer being authored by judicial officers and clerks. The output stream is being authorized by an external third party using an LLM-based case-file production pipeline. The metadata fingerprints prove it. The vocabulary patterns prove it. The synchronized media noise around Matt's appellate filings proves it. The St. Paul "cyberattack" arriving an hour after his pro se Notice of Appearance proves it.
The language is being generated, not authored.
The Odyssey eFiling system has been hijacked. The hijack is an LLM driven by an external operator. The hijack has propagated across all three Minnesota judicial branches and woven itself into U.S. media term-frequency data via OpenTimestamps-anchored synchronized noise injection.
That is the only conclusion the data sustains.
How to verify everything on this page yourself
Every claim on this page rests on two exhibits filed in the U.S. Court of Appeals for the Eighth Circuit (case 25-2476): EXHIBIT TTC (the term-frequency tables) and EXHIBIT TTM (the MediaCloud term-trend data). Both exhibits are publicly retrievable from three independent legal-record platforms AND from four independent source-file mirrors, and both are anchored to specific Bitcoin block windows via OpenTimestamps proofs.
The redundancy is the point. Mirroring the same file across multiple independent platforms means none of them can be quietly edited after the fact — an alteration would need to be made everywhere simultaneously, which is not operationally feasible at any meaningful scale. The legal-record platforms are append-only (existing entries cannot be edited or deleted, only new entries added). The source-file mirrors are independently controlled and do not share infrastructure with each other.
Source-file mirror URLs are the same four printed in the bottom-left corner of every page of the federal exhibit.
What is a SHA-256 hash?
A SHA-256 hash is a 64-character fingerprint of a file's exact byte-level contents. Run any file through the SHA-256 algorithm and you get a unique sequence of 64 hexadecimal characters that uniquely identifies the file. Change one bit anywhere in the file — flip a single zero to a one, anywhere in the document — and the entire 64-character hash changes to something completely different. This is what makes hashes the standard for authenticating digital evidence. If your hash matches the published hash, you have the exact same file, byte for byte. If it doesn't match, the file has been altered.
Matt's own filings rely on SHA-256 hashes throughout. His EXHIBIT Addendum Volume XVI (filed in federal case 24-cv-02646, June 18, 2025) is a working example: every page of the exhibit lists the SHA-256 hash of the underlying source file, so any reader can independently verify the chain of custody. The same exhibit is mirrored on CourtListener storage and indexed at the public CourtListener docket entry.
For a non-technical introduction to SHA-256 and how it functions in U.S. courts, see "What the Hash: Data Integrity and Authenticity in American Jurisprudence" at U.S. Cybersecurity Magazine.
What is OpenTimestamps?
OpenTimestamps is a free, open standard for proving that a digital file existed at a specific moment in time. It works by anchoring the file's SHA-256 hash to a Bitcoin block. Once a hash is committed to the Bitcoin blockchain, the entry is locked in — modifying it would require rewriting every Bitcoin block that comes after it, which is not operationally feasible. Any file that carries a valid OpenTimestamps proof can be cryptographically demonstrated to have existed BEFORE the Bitcoin block that anchors its hash was mined.
Both EXHIBIT TTC and EXHIBIT TTM carry valid OpenTimestamps proofs. The exhibit hashes are committed to specific Bitcoin block windows. The legal record cannot be retroactively rewritten to dispute when these exhibits came into existence. The synthetic media noise documented above could not be a post-hoc fabrication by Matt — it is locked to a Bitcoin block that predates this analysis by months.