FORENSIC RESEARCH ARCHIVE
Sources and evidence
Primary artifacts, verification records, technical reports, and the evidence hierarchy behind this dossier.
How this dossier is sourced
Claims are linked to preserved artifacts, contemporary captures, cryptographic verification, or reproducible analysis. A signature authenticates bytes and publication identity; it does not make the statement inside those bytes true. The links below point to the public research corpus and its exact working records.
Core source notes
- Book archives, timestamps, and page hashes. The artifact register records source grades, hashes, timestamps, and surviving variants. Artifact register ↗ — source note retained in this edition
- Pages 1-16. Independent verification of the Orkhon-style substitution readings and page-level variants. Verification record ↗ — source note retained in this edition
- Pages 17-22. Reproduction of the repeating-decimal, atomic-number, and element-initial method. Verification record ↗ — source note retained in this edition
- Page 23. Canonical matrix, arithmetic, repunit construction, Turkish-prefix model, controls, and stated limits. Page-23 report ↗ — source note retained in this edition
- Audio and onion route. Reconstruction of the MP3, beep transcript, base-9 correction, A/x block, and historical Tor address. Route verification ↗ — source note retained in this edition
themessage.txt. Exact input hash, bitmap-derived key, direct Hill convention, modular-inverse check, plaintext hash, and reproduction command. Cipher report ↗ — source note retained in this editionnothingisrandom.txt. Exact digit-to-bit rule and the four bitmap-coordinate groups that supply the 4-by-4 key. Bitmap report ↗ — source note retained in this edition- PGP publication trail. Verification status for clearsigned messages, detached signatures, binary artifacts, and damaged copies. PGP audit ↗ — source note retained in this edition
- Attribution. Public profile material and contextual overlap are kept circumstantial because no authenticated identity bridge exists. Evidence ledger ↗ — source note retained in this edition
- Later activity. Signed and unsigned post-2017 images, statements, documents, and continuity assessments. Later-activity record ↗ — source note retained in this edition
- Community and archive coverage. The corpus map describes the harvest, reconstructions, independent topic dossiers, and gaps. Master index ↗ — source note retained in this edition
- Current consolidated findings. The maintained summary separates proven, derived, rejected, blocked, and lost claims. Findings ↗ — source note retained in this edition
- Rendezvous path. The two-path timeline, signed-image provenance, rune reading, exact 2037 conversion, complete 2,816-bit kolam transcription, and negative transform audit. Rendezvous report →
- @666ab731 account archive. Ninety-five recovered normalized tweet bodies, four known tombstones, fifteen locally preserved Twitter media files, exact UTC timestamps, and a machine-readable index. Three later public-syndication recoveries, two screenshot-backed April-2017 replies, and one Wayback-restored 2021 BitClout pointer are explicitly separated from the immutable original discovery index. Tweet archive → · April-2017 recovery audit →
Source hierarchy
| Tier | What it means here |
|---|---|
| PRIMARY / CRYPTOGRAPHIC | Original or contemporaneous bytes, with a verified author signature where stated. |
| PRIMARY-DERIVED | A deterministic transformation directly from preserved primary material. |
| INVESTIGATOR-DERIVED | A reproducible analysis whose interpretation was not signed by the author. |
| CONTEMPORARY | Reporting or community evidence created during the original events. |
| CIRCUMSTANTIAL | A contextual association that does not establish identity or authorship. |
| REJECTED / BLOCKED / LOST | A failed controlled hypothesis, a question requiring absent evidence, or an artifact no longer preserved. |
2018 “I am the method” video
The saved platform metadata, original MP4 hash, stream inventory, frame/LSB/contrast checks, mono and L-minus-R audio checks, and the linked PGP-signed companion text are preserved as a reproducible evidence bundle. The PGP verification authenticates the Pastebin text under the Tengri key; it does not authenticate a real-world identity or promote the negative first-pass media result into proof that no hidden method exists.
Original YouTube video ↗ · Linked signed Pastebin ↗ · Local audit JSON →
2018 video: public-comment lead and score baseline
A 27 July 2026 snapshot of the current YouTube comments includes a reply that the platform labels as from the uploader account. It names Bach's Contrapunctus I and says a hidden video key explains a next message. The reply is an important platform record but is neither PGP-signed nor an identity bridge; comments are mutable and its visible date label is relative. The score baseline uses a documented public-domain MIDI edition from Mutopia ↗.
Comment evidence JSON → · Timing audit JSON → · Strict score baseline JSON →
2018 video: archive continuity
Two exact-URL Wayback captures, from 2021 and 2025, preserve the same title, channel ID, displayed 2018 publication date, and Pastebin-linked description. Neither capture includes an early comment thread, original media bytes, or a target for “the next message.” This is a metadata-continuity check, not an authentication of the uploader reply or a solution.
Read the archive-continuity audit → · Machine-readable record →
2024 Hack Liberty repost: context, not primary evidence
The Hack Liberty thread was created on 4 March 2024 by a third-party user who says they are reposting older material. Its first post reproduces the FLOOD campaign wording and the later readable instruction-sheet image used in this dossier; its 2025 reply points to an older, unrelated sunlight-pipeline proposal. This establishes a surviving public rehost and its context, not original instructions.pdf bytes, a signed Tengri statement, or a demonstrated provenance chain for the energy concept.
Hack Liberty thread ↗ · Instruction-sheet provenance boundary →
2018 PGP poem: exact respacings, bounded conclusion
The signed seven-line poem has 23 alphabetic words. Removing whitespace and punctuation from its first two lines yields JUSTINSUN and TORUNIX. The second result may be losslessly respaced as TOR UNIX, which is compatible with the earlier onion/Tor story but supplies no address or executable instruction. A different mixed outer-letter reading can manufacture TRONIX, but it changes letter order and leaves the middle U unused; the author provides no rule for it. A fixed recovered-timeline window contains only the bare Pastebin pointer, while the same-day Reddit Tor-browser comment is clearly marked as community evidence. The nearby January 2018 press context makes the Justin Sun/Tronix vocabulary historically real, not author-confirmed.
A second finite control fixes thirteen whole source-visible readings before inspection. None is a directly formatted URL, domain, onion address, Bitcoin address, hexadecimal byte string, or a previously documented route handle; TRONIX also fails a left-to-right single-endpoint-per-word control. This is deliberately narrow negative evidence, not a claim that every possible cipher has been tried.
Structure audit → · Finite-control audit → · Machine-readable controls → · Contemporary 4 January 2018 context ↗ · TRON’s TRX / TRONIX terminology ↗
2017 public-key certifiers: context, not attribution
The older Tengri (137) OpenPGP UID carries four third-party certifications. Two public certifier keys are preserved and their signatures verify: their public UIDs are Noah Mercitalis and Varol Tepecik. The latter key was created on the same day it made the certification. Packet records place all four certifications on the older UID, not the later Tengri 137 UID; the two remaining issuer keys have no recovered public material. This documents a small contemporaneous key-user milieu, but it does not identify Tengri’s operator, prove an offline relationship, or turn Turkish context into authorship evidence.
Contemporary 2018 community record for the video
A contemporaneous Reddit post preserves the YouTube link, the claimed uploader reply, and an Imgur spectrogram lead. The Imgur album is no longer useful as a live page, but a direct-image memento survives in Wayback Machine. This is classified as contemporary secondary evidence: it corroborates when the lead circulated and that a community MP3 retained the two audio gaps, not authorship or a hidden-code claim.
Reddit post ↗ · Original Imgur album URL ↗ · Saved Spek image → · Provenance manifest →
2018 video: temporal-stack visual control
The globe image is unusually stable across the preserved lossy transcode, so a finite visual control averages 149 decoded one-second frames and takes a per-pixel median of 15 ten-second samples. Gamma, local-contrast, high-pass, and temporal-variance derivatives still yield no decoded QR text or usable four-corner QR geometry. One gamma derivative makes the detector return a three-corner degenerate shape; the recorded corners are a false-positive geometry, not a QR finding. This narrows a fixed-overlay theory for this upload without claiming to rule out arbitrary encoding or an unavailable original.
Inspectable composite → · Method and measurements → · Machine-readable result →
2018 video stereo / voice controls
The first score-conditioned stereo audit looks for complementary allocations of the four reference-MIDI voices. Its best broad-chroma partition is unusual relative to score time shifts (p = 0.0050, 200 controls), but the test does not extract stems. A stricter, pitch-matched event-level test then uses 886 collision-filtered note events and 2,000 within-pitch voice-label permutations; it finds no corroborated voice-specific panning effect (p = 0.3143). These artifacts close the simple “one voice per channel” route without claiming to prove the soundtrack has no other hidden method.
Combined method note → · Aggregate stereo JSON → · Pitch-matched JSON → · Aggregate chart → · Control chart →
2018 video: linear, logarithmic, and residual audio views
The preserved audio can be inspected in matched mid/side linear and logarithmic frequency views, then after per-frequency median subtraction and a mid-minus-side energy comparison. The fixed-scale transforms retain musical structure and the known silence intervals; they do not produce readable text, a barcode, FSK/RTTY traces, or a channel-exclusive graphic. This is a finite negative control on the lossy copy, not a claim that every possible transform is exhausted.
Linear/log spectrogram → · Residual and channel comparison → · Method and limits → · Rendering parameters →
2018 video: final-cadence control
The timing alignment maps the reference MIDI end to video 136.842 s, while literal PCM silence starts at 143.089 s. The final four audible seconds are spectrally stationary; all eight strongest narrowband peaks are D, F#, or A, matching the score's final D-major/Picardy-third chord. This bounds the apparent six-second tail as a prolonged rendered cadence, not a separate melodic payload. It does not test arbitrary keyed transforms or unavailable pre-YouTube audio.
2018 video: score-note presence control
Using the already fixed score-to-video alignment, collision-filtered harmonic energy at expected MIDI notes exceeds nearby wrong-pitch controls in 808 of 885 eligible events (91.3%). The 77 low/tied events are not a stable selected subset: their rate is 24.5% in the high register versus 3.6% in the low, and 35.3% in the terminal cadence versus 6.5% in the body. The audit therefore supports ordinary score rendering while rejecting an unqualified missing-note binary reading. It cannot rule out an author-specified keyed transformation or unavailable original media.
2018 video: candidate-performance control
The public Kimiko Ishizaka Contrapunctus I OGG is a verified, pre-upload candidate, but it is not identified as the Tengri video source. A broad chroma match measures shared score material: the same-work Mutopia-derived synthesized control scores at least as highly. Fixed-window direct linear-retiming comparisons are low for Ishizaka I, the synthesized control, and Ishizaka IV. This rules out only an unsupported direct-clone attribution, not a pitch-preserving transformation, remix, separate MIDI rendering, or unrecovered original media.
2018 video: next-message chronology
The phrase next message
is a platform-labelled YouTube reply, not a source-selected URL. Between the video upload date (25 January 2018) and the earliest retained community copy of that reply (8 April), the canonical recovered timeline contains only two non-reply posts: S. H. (a plausible same-day Stephen Hawking allusion) and a two-stage hexadecimal/Base64 decode to Bennu. Both are legitimate records; neither names the video or is identified as its sequel. The archive also has known tweet-coverage gaps, so this is a boundary on the known corpus rather than a proof that no missing message exists.
2017 WAV residual and magic-number audits
The beep-WAV audit starts from the preserved contemporaneous transcript and table, not a reconstructed sound file. It verifies the full token route and quantifies the unmapped tail rather than inventing plaintext. The magic-number audit preserves the exact six author-printed values, distinguishes the later 126 association, and limits matrix indexing to predeclared variants.
WAV transcript audit → · WAV audit JSON → · Magic-number audit → · Magic-number audit JSON →
Baatar Kerei and Vumarii status records
The 2017 baatarkerei pointer and the 2019 Vumarii image are important later artifacts, but neither should be inflated into a solved extra endpoint. The Baatar record identifies a third-party 2013 YouTube video from preserved platform metadata while preserving the fact that its media bytes are lost. Its retained 2022 storyboard URL template has now been checked as a separate recovery route: six sampled sheets return HTTP 403 and no Wayback copy exists. The Vumarii record gives a pixel-exact 2019 glyph transcription while preserving the fact that no language translation has been verified. Its shared 154-slot count with Page 23 has also failed a matched direct-alignment control, so it cannot currently support a Page-23 decode claim. The upper diagram's crop, components, and enclosed circles are catalogued reproducibly. It is now strongly attributable to a cleaned, re-inked north-polar detail of the Dunhuang Star Map, while the missing source-selected traversal remains an open question.
Local status audit → · Machine-readable audit → · Baatar metadata → · Storyboard recovery audit → · Vumarii transcription → · RGB bit-plane audit → · 154-slot alignment controls → · Upper-diagram geometry →
Vumarii: Dunhuang Star Map attribution
The 2019 upper diagram is strongly attributable to a cleaned, re-inked north-polar detail of the Dunhuang Star Map (British Library Or.8210/S.3326). The local audit preserves the exact Vumarii crop, source-image hash, nine labelled matching regions, and bounded orientation comparison. Its normal-orientation result is supporting geometry, not a blind p-value: the historical source was discovered visually and its crop was inspected before the control family was run. The claim is therefore limited to visual provenance. It does not select individual star names, an ordering, a cipher key, a glyph mapping, or a plaintext.
Read the attribution audit → · Machine-readable record → · Labelled comparison → · Reference image on Wikimedia Commons ↗
Vumarii: 34-asterism count control
Table 5 of Bonnet-Bidaud, Praderie, and Whitfield's scholarly study of the Dunhuang map lists 34 asterisms in the matching north-circumpolar panel. Vumarii reaches the same group count only by treating its two visible signature groups as part of the body. A deliberately generous direct test compares the 34 group lengths with the published on-map star counts in the documented table order and its reverse, then applies the same best-of-two allowance to 100,000 fixed-seed randomized controls. Five exact matches, absolute correlation 0.2011, and total difference 85 are ordinary (p = 0.5315, 0.4615, and 0.3857). This closes that count/length correspondence as a decoder; it does not rule out every unprovided star-path or cipher hypothesis.
Read the count-control audit → · Machine-readable result → · Control chart → · Scholarly source PDF ↗
Vumarii: bounded English-substitution control
The contemporary Solver key itself lists possible alphabet/Caesar/Atbash-style directions, but it does not name a final language or key. A deliberately generous control therefore lets every one of the 23 body glyph classes map to any Latin letter, without forcing the image’s partial red-label mapping. The fixed-seed solver recovers two of three independently encrypted, 154-letter English controls exactly (and misses the third by one letter), yet returns no readable English for Vumarii. This is useful negative evidence against a simple English substitution layer—not proof against other languages, keyed ciphers, or non-letter encodings.
Vumarii: conditional Turkish-completion control
This is the strongest language-shaped Vumarii result so far, but it is deliberately not labelled a translation. Starting from the eleven red-label letters and accepting seven contemporary secondary readings only as a condition, the audit enumerates all 6,720 ways to assign the five remaining glyph classes. The best completion is more Turkish-like than both fixed null families: it beats every one of 512 glyph-position shuffles and all but three of 512 key-permuted controls. Yet it remains 8.70 standard deviations below held-out Turkish and cannot be segmented into a full Turkish sentence. That makes it a reproducible phonotactic lead, not a source-selected alphabet, plaintext, or solution. In particular, a nearby completion's local ETMEK does not validate ANLAMAK: the accepted C07=D reading yields ANDAMAK instead.
Read the conditional audit → · Machine-readable result → · Null-distribution plot →
Vumarii: affine Turkish control
The same conditional Turkish surface was tested against the whole 26-letter affine family: all 12 invertible multipliers and 26 offsets, including Caesar shifts and Atbash-like maps. With all 6,720 residual glyph completions per map, that is 2,096,640 scored candidates. The untransformed identity map is the global best; the best non-identity result is substantially worse and still has no Turkish segmentation. This closes a small, historically suggested classical-cipher family without claiming to solve the image or exclude other language and cipher models.
Vumarii: Defango-listed Esperanto and Swahili controls
The visible labels Esperanto and swahili on the community Solver key are specific enough to test, but not strong enough to treat as a key. With the image's red legend fixed, the same seven community readings accepted only conditionally, and every one of the 6,720 remaining completions checked, neither language yields natural prose: the best candidate is 18.05σ below held-out Esperanto and 13.91σ below held-out Swahili, both at the 0.00 held-out percentile. Esperanto's conditional surface is unusual relative to randomized reading keys but still not readable; Swahili's is equalled or exceeded by 13/256 randomized key controls. This is bounded negative evidence against precisely those two conditional monoalphabetic surfaces, not a claim that the image has no other layer.
Read the complete audit → · Machine-readable result → · Comparison chart →
Vumarii: 2018 Patreon context
The public link patreon.com/posts/vumarii-21229946 is preserved through a contemporary Reddit post, whose author calls it official and says a future puzzle may follow. A comment from the same author describes the Patreon purpose as charitable giving. Those claims make the URL relevant to chronology, but they are not recovered Patreon content or a creator-signed key. The accompanying archive audit keeps live bot blocking, empty responses, timeouts, and gateway failures separate from a real negative archive result. A separate unauthenticated post-API request returns ViewForbidden rather than a title or body, which documents present access control but does not authenticate the Reddit attribution.
Context and recovery audit → · API access audit → · Machine-readable archive observation →
Page 23 final-step and animal-name audits
The final-step audit reproduces BUNU YAZAN TOSUN OKUYANA KOSUN from both signed editions and distinguishes the six-number URUABZ diagnostic from the community-extended URUABZE. The companion substring audit preserves the account’s 2025 animal hint and the exact OKUZ/SNAKE locations. Together they distinguish the sentence’s semantic animal TOSUN from visually attractive substrings.
Final-step audit → · Animal-hint audit → · Animal-hint audit JSON →
2018 / 2025 factorization magic square
Two author-published images preserve the same 16×16 factorization table: the original 25 August 2018 post and a 23 April 2025 re-post. The later account reply naming 2222, 4444, 6666 and 8888 has a natural, reproducible referent in this table's block-sum ladder. The arithmetic is investigator-derived; the association is deliberately labelled as a strong inference because the captured parent replies do not explicitly say so. The audit also preserves the single R03C05 printing error instead of quietly changing the primary image.
2017 FLOOD campaign and Dropbox document audit
The May 2017 helper/countdown/FLOOD/document-release run is a distinct public-publication branch, not a hidden continuation of the MP3 cipher. Recovered account posts establish the chronology; a contemporaneous Reddit post names ENERGY.pdf and MANIFESTO.pdf; the current Dropbox ZIP has byte-identical copies of the two preserved 2017 PDFs. The same live folder also contains 2024–25 documents, which the audit prevents from being silently backdated.
A readable 2024 forum repost now supplies the visible content of the otherwise lost instructions.pdf: a three-channel plan to print, email and share the two documents on 1 June 2017. This is secondary visual evidence only: it does not recover the original PDF bytes, metadata, Dropbox object or signature status.
FLOOD provenance and PDF audit → · Instructions-repost audit → · Instructions repost image → · 19 May 2017 FLOOD post ↗ · 31 May document-release post ↗
2017 WAV public-recovery audit
The current S3 object does not contain audio: it returns an XML NoSuchBucket response. To test recoverability rather than repeat that fact, the audit uses only the original object/player URL family. Wayback CDX, all Common Crawl collections from the first post-upload crawl through the end of 2018, and Arquivo.pt contain no checked capture. The conclusion is intentionally narrow: the file was not recovered from these public routes, while private caches and unindexed mirrors remain possible.
Current download check and playback reconstruction
A file downloaded in July 2026 as 666ab731.wav proved to be a 4,210-byte HTML front-page response, not a corrupt audio container. A preserved 2017 Instaudio page still identifies the distinct 1:53.152 WAV object and its S3 URL; current S3 headers return 404. The site therefore offers a clearly labelled, duration-only synthetic listening aid built from the public 2,994-digit transcript, never an alleged restoration of the lost source.
Download classification audit → · Reconstruction receipt → · Timing reconstruction (WAV) →
Cross-branch evidence claim ledger
The public report has a compact, source-indexed register for eight junctions most often flattened in retellings: the Hill endpoint, the lost WAV, the nuclear numbers, the rendezvous payload, the MathEasySolutions exchange, the 2018 poem, the 2018 video, and Vumarii. It identifies both the positive result and the next unsupported inference for each row; the video row now also records the finite temporal-stack check as a control rather than a solve.
Read the ledger → · Machine-readable ledger → · Public ledger view →
Vumarii: later white-script alignment retracted
An earlier proposal connected two later white-script rasters to consecutive excerpts of Dani Leviss’s 15 January 2019 Scienceline article Anybody out there?. It is retained only as a falsified research record, not as source-text identification: its visual-letter probe achieved 7.4480% in-sample accuracy, its forced-alignment record recovered 0 complete calibration words, and the independent-looking confirmation was later found to reuse a provisional mapping. The proposed glyph/source chain therefore does not establish a quotation, alphabet, plaintext, or key for the 2019 signed image.
Superseded alignment audit and limits → · Machine-readable historical record → · Integration review and retraction boundary → · Previously proposed article ↗
2025 Vumarii: native-resolution working transcription
The 10 July 2025 image is preserved as an 853×892 native X-hosted JPEG and contains a 17-line Vumarii-family cursive text. A retained working sequence assigns 824 base-glyph tokens into the older family catalogue, but 166 assignments are low-confidence and its grouping slashes are not source word separators. It therefore records a useful segmentation starting point, not a language plaintext or solved alphabet.
External research review: no new primary artifact
A separate 27 July 2026 research checkout was reviewed against the material preserved here. Its final note retracts an earlier audio-splice assertion and a tentative 2024/25 Vumarii symbol mapping; neither is used by this dossier. The remaining 2024/25 discussion is a useful warning about pattern completion, but its source images and calibration set are not in this locally verified artifact collection. It therefore supplies no Vumarii plaintext, key, or new endpoint for the public account.
2017 first endpoint: preserved ONION archive
The public bit.ly/aabbbcccc route was re-fetched on 27 July 2026 as a 1,221-byte Dropbox ZIP with exactly one member: the 967-byte clear-signed knowledge.txt. A local packet-level verifier validates its OpenPGP v4 RSA/SHA-256 signature under the established Tengri fingerprint. The record also fixes the note's spacing: ordinary CRLF line endings, one blank paragraph separator, no tabs, and no trailing whitespace. This authenticates the note and bounds a proposed whitespace cipher; it does not reveal the promised last step.
Raw signed note → · Capture and verification audit → · Machine-readable record →