A Lottery Photo, Certified Hours Before the Draw
Its Google signature and timestamp both check out. The catch: the signature covers not one byte of the picture.

Here is a photograph of a EuroMillions ticket for Friday 28 August 2026, carrying the five numbers and two stars that won that night. Its Content Credentials — the cryptographic label meant to tell real camera pictures from fakes — say it was signed under Google’s “Pixel Camera” certificate and witnessed by a Google time-stamping server at 14:05 UTC that afternoon, hours before the draw. Checked on 5 October 2026 against the official C2PA trust lists, the file comes back trusted, with no failures.
The numbers went on afterwards. David Buchanan, the security researcher who posted the image on 2 October, says he really did photograph a ticket and obtain a valid signature and a valid timestamp, then edited the numbers in, badly, once the draw was public. “Yes, you can tell it’s photoshopped,” he writes; he is not attempting lottery fraud. His point is that, as of his post, none of the C2PA verification tools he could find flagged anything unusual.
That matters because C2PA is the standard behind Content Credentials, which Adobe, Google and others offer as an answer to AI-generated images: the device signs what it captured, and an independent time-stamping authority signs that this signature existed at a given moment. Buchanan does not attack that witness. He assumes it works as advertised.
The gap is a feature of the standard called exclusions: byte ranges of a file that the signature leaves out. Buchanan left out everything. The manifest in his image declares a single exclusion that starts at byte 0 and runs for 3,995,383 bytes — the length of the whole file — and records as the image’s fingerprint the SHA-256 hash of an empty input (47DEQpj8…uFU=). The timestamp is genuine. What it vouches for is a signature over nothing.
This note downloaded the file and ran the Content Authenticity Initiative’s open-source c2patool, version 0.27.22, with the C2PA conformance trust lists loaded: validation state “Trusted”, data hash “valid”, timestamp trusted from “Google Core Time Stamping Authority T10”. The software that wrote the manifest names itself “c2pa poc”, not the camera app. In the picture, a screen beside the ticket shows time.is reading 15:05:29 in Bradford, England — 14:05 UTC. Euro-millions.com lists draw 1,976 on 28 August as 7, 14, 28, 42, 45, with Lucky Stars 6 and 9.
None of this was secret. In June 2025 Neal Krawetz, of the Hacker Factor blog, listed “large exclusion range” among C2PA’s problems: any excluded bytes can be altered without detection. Buchanan’s step is to make the exclusion deliberate and total. In August he had argued that a rooted Pixel can be made to sign whatever its owner likes with the Pixel Camera keys; in this post he calls the claim signature “approximately worthless.”
Dropping exclusions is not a clean fix, because some formats need them: in a PNG, every chunk carries a checksum that has to be rewritten after the signature is embedded. Buchanan proposes spelling out, format by format, exactly which bytes may be left out, and requiring verifiers to enforce it. Not checked here: how the Content Authenticity Initiative’s web verifier displays the file today, or whether C2PA or Google has responded. On 5 October, the photograph still knew the numbers in advance.
How to Hack Time, With C2PA — David Buchanan (retr0id)
Proof-of-concept image posted 2 October 2026: a EuroMillions ticket for the 28 August 2026 draw showing the winning numbers, with C2PA Content Credentials signed under a Google “Pixel Camera” certificate and a Google TSA timestamp of 14:05:33 UTC, hours before the draw. The manifest excludes bytes 0–3,995,383 (the whole file) and records the SHA-256 of an empty input. Re-checked 5 October 2026 with c2patool 0.27.22 and the C2PA conformance trust lists: “Trusted”, no failures. Not checked: the CAI web verifier’s current display; any response from C2PA or Google.
Read David Buchanan’s post Download the signed image See the 28 August 2026 EuroMillions results Read Buchanan’s August post on C2PA and rooted Pixels Read Neal Krawetz’s June 2025 list of C2PA issues