Closing The Hash Loop — Cryptographic Receipt Archive
11 attachments · 11 SHA-256 hashes · 11 OpenTimestamps proofs · one 36-minute capture window
AUTHOR
Matthew David Guertin · MattGuertin@protonmail.com
CAPTURE SESSION
2026-05-13 22:41:53 CDT → 2026-05-14 03:17:54 UTC (36 min 05 s) · bundles 0000–0278
BITCOIN ANCHOR
Block 949,319 · header time 2026-05-14 00:06:03 CDT · trustless lower-bound for every bundle hash
BUILT
2026-05-14 15:18:20 CDT · MnCourtFraud.com/closing-the-loop/ packet assembly
ABSTRACT
On the evening of 2026-05-13, six fraud reports were filed simultaneously through public complaint channels — the FBI Internet Crime Complaint Center, the FTC ReportFraud portal, the US Postal Inspection Service’s External Cybercrime form, the Minnesota Attorney General’s Consumer Assistance Request (which returned an auto-reply sealed by 2048-bit DKIM), the Minnesota Office of the Legislative Auditor’s online allegation form, and the Minnesota House Republicans Whistleblower Portal. Every outbound POST was captured at the wire, every form body preserved, every submission hash-locked into a 279-bundle chain dual-timestamped against the Bitcoin blockchain (block 949,319) and the Roughtime ensemble (Cloudflare / Google / INT2 / independent NIST-style servers, ±1 s window). The eleven attachments in this PDF are the complete receipt set from that capture — every bundle, every HAR, every packet, every parsed form body, every OBS frame, every OTS proof, every Roughtime ticket, the processing pipeline, and the web-optimized recording itself.
§ CAPTURE METHODOLOGY
How the receipts were assembled.
The capture stack is OneWayVideo, a Linux-based controller created by Guertin, that runs an isolated Firefox profile routed through mitmproxy, records the screen via the OBS Studio virtual camera, and writes a numbered JSON “bundle” every ∼ 7 seconds. Each bundle carries the prior bundle’s SHA-256 (forming a verifiable chain), live network packet capture metadata, live HTTP request URLs, downloaded-file SHA-256s, the OBS frame hash, and a 1 000 ms dump of the host’s monotonic-clock nanoseconds as the chain’s seed nonce. The previous bundle’s SHA-256 is also printed in an on-screen overlay window, so the chain is baked into the recorded video pixels in addition to the JSON.
Each bundle hash is committed to OpenTimestamps at write time. After the recording completes, the ots upgrade step anchors every commit against a confirmed Bitcoin block — here, block 949,319, mined 2026-05-14 00:06:03 CDT. A Bitcoin anchor alone gives a ± ~hour window (block median-time-past rules), so the OTS file itself is also signed by the Roughtime ensemble at write time, producing a separate cryptographic timestamp with a midpoint ± 1-second window signed by independent NIST-style servers. The two timestamping layers are mathematically unrelated; tampering would need to forge both.
Downloaded files (here, the six confirmation PDFs returned by the destinations) are wrapped at capture time into a digitally signed PDF vault using a self-issued X.509 certificate CN=Matthew David Guertin, OU=Minnesota Judicial Fraud Exposed, O=CourtListener Docket 70633540. pdfsig verifies every vault PDF as cryptographically valid.










