Receipt

Fri 4 Sept 2026

The first comprehensive independent security analysis of the C2PA content provenance specification (Golaszewski et al., April 2026 — UMBC Cyber Defense Lab, NSA, Hacker Factor) proved that C2PA fails all of its claimed security goals and all essential goals a provenance system requires. Timestamps can be replaced without detection because nothing in the signed data references the timestamp; conforming validators are not required to check certificate revocation, allowing compromised keys to forge apparently valid provenance; and different conforming validators produce contradictory results on the same media. California's SB 942 and the EU AI Act Article 50 both mandate C2PA-based content credentials as of August 2026 — but the specification versions in production (2.2–2.4) cannot guarantee the integrity of the timestamps, geographic locations, or AI-origin labels that these laws require platforms to display.

Not submitted.

FAILED
public
Advanced
proof format
opentimestamps
status
failed
privacy
public
created
2026-09-04 04:01:41 UTC