# ADVERSARIAL VERIFICATION — onion-derivation--MERGED

Verifier posture: skeptical / refutation-seeking.
Date: 2026-07-24.
Target file: `<research-workspace>/artifacts/onion-derivation--MERGED.md`
(Note: the task named `onion-derivation--MERGED--MERGED.md`; that file does not exist. The
authoritative merged file on disk is `onion-derivation--MERGED.md`, which I verified.)
Also read: `onion-derivation--A.md`, `onion-derivation--B.md`.

VERDICT: **agrees = false** — but only on peripheral/provenance points. The **core cipher artifact
is byte-perfect, reproduces exactly, is independently corroborated by a source NOT in the
provenance list, and shows NO sign of fabrication or memory-reconstruction.** The discrepancies
below are all outside the cipher payload.

================================================================================================
## A. WHAT I RECOMPUTED AND CONFIRMED (core — zero discrepancies)
================================================================================================

**A1. The 176-char A/x block decodes exactly as claimed.**
Extracted the single-line block programmatically from `onion-derivation--MERGED.md` line 27 (never
retyped), mapped A→0 / x→1, packed MSB-first 8 bits/byte:
- length 176, alphabet {A,x} only, 22 bytes, 0 residue bits.
- hex  = `36 36 36 36 36 36 6d 37 78 36 78 35 72 65 67 63 2e 6f 6e 69 6f 6e`  → matches published.
- ascii = `666666m7x6x5regc.onion` → matches published.

**A2. Wrapped form and its annotation are exactly right.**
MERGED §1b lines join to the identical 176-char string. Measured lengths = **50 / 50 / 50 / 26**
(= 176). Per-line counts exactly as MERGED states: L1 25A/25x, L2 22A/28x, L3 22A/28x, L4 10A/16x.

**A3. All renderings across A, B, MERGED are byte-identical.**
Regex-extracted every A/x run ≥100 chars: A=1 run, B=5 runs, MERGED=4 runs — every one is 176 chars
and `== canonical` True. A's wrapped block, B's wrapped block, and the 3× meta-transcription repeats
all match.

**A4. Corrupted-variant arithmetic is self-consistent.**
The flagged bad first line `xAxxAAAxxAxxAAAxxAxxAAAxxAxxAAx` is 31 chars; 176−50+31 = 157, and
157 mod 8 = 5 ≠ 0 → undecodable, exactly as MERGED §5 says.

**A5. Cited LOCAL sources genuinely contain the block (no smoothing over a gap).**
- `recon/cipherbrain-comments/how-a-blog-reader-solved-the-tengri-137-mystery.raw.html`: block
  present **3×** (wrapped with `<br />`; that is why a naive single-line grep returns 0). Decode
  line confirmed: `666666m7&#120;6&#120;5regc.onion` — the `&#120;`=`x` entity note in the artifact
  is real.
- `recon/web-archives/wikia-Twitter_message_2017-FULL-wayback-20170403.txt`: block present **3×**
  (wrapped).
- `recon/reddit/r-tengri137-5zisip-...md`: block present **3×** (single-line, lines 76/84/92).

**A6. Number facts check out.** 6448 = 2⁴·13·31 (and ≠ 6439 = 47·137); 3151 = 23·137.

================================================================================================
## B. INDEPENDENT SOURCES NOT IN THE PROVENANCE LIST — diffed char-by-char (agree)
================================================================================================

**B1. GitHub repo `bartman081523/tengri137-selenoprotein`** (NOT cited in the reconstruction's
provenance URLs). Fetched `original_sources/wikia/wikia_Twitter_message_2017.html` raw:
- canon A/x block present **3×**, every occurrence byte-identical to canonical.
- full address `666666m7x6x5regc.onion` present.
- full hex string `36 36 36 36 36 36 6d 37 78 36 78 35 72 65 67 63 2e 6f 6e 69 6f 6e` present.
→ Independent third-party mirror reproduces block + hex + address exactly.

**B2. Live fetch (2026) of the Klausis 2017-03-18 post** (post body, independent of the on-disk
comment-thread copy): canon block present **3×**, all byte-identical; partial address
`666666m7x6x5` and the "1800 years" vanity-mining figure present. Agrees.

**B3. WebSearch corroboration**: independent write-ups confirm solver = **Norbert Biermann**, the
27-symbol run-length letter table, and the meta-word `abccadefbgheijklmelndjecndeopcdebmekqdjer…`.

================================================================================================
## C. PROVENANCE-TIER AUDIT (PGP artifact) — verified, with one caveat
================================================================================================

I decoded the OpenPGP signature packet in
`recon/web-archives/pastebin-P59Kf0cs-gate-is-open-onion-pgp-signed.txt` from scratch AND confirmed
with `gpg --verify`:
- signature version 4, type 0x01 (canonical text), RSA, hash SHA-256 (matches `Hash: SHA256`).
- **creation time = 1491162480 = 2017-04-02 19:48:00 UTC** (gpg: "Signature made … 2 kwi 21:48:00
  2017 CEST"). Matches the claimed "≈2 April 2017" gate opening.
- **issuer key id = D152D6C5666AB731 → short `0x666ab731`**, exactly the claimed operator key.
- `pastebin.com/raw/P59Kf0cs` returns HTTP 200 → B's "still live" claim confirmed.
Full cryptographic verification could NOT be completed here: the on-disk key export `tmp_key.asc`
carries no user-ID packet, so gpg reports "no user ID / Can't check signature: No public key". The
signature metadata is fully consistent, but the "readers confirmed the signature validated" claim
is a contemporary report I could not independently reproduce with the material on disk.

================================================================================================
## D. DISCREPANCIES FOUND (all peripheral; none in the cipher payload)
================================================================================================

**D1. Source `onion-derivation--A.md` contains a real factual error (line 52).**
Verbatim: "The first three lines are 49 characters, the last is 25 (176 total)." This is wrong
(actual = 50/50/50/26) AND internally inconsistent (49×3+25 = 172 ≠ 176). MERGED correctly catches
and corrects this as VARIANT V1, but the error is genuinely present in file A.

**D2. MERGED §7 nmap block is labelled "VERBATIM" but is actually truncated.**
The source (`5zisip`, comment `dfmfx56`) ends with a 9th line
`WARNING: No targets were specified, so 0 hosts scanned.` and has trailing spaces after the two
`…regc.onion ` DNS-request lines. MERGED's reproduction drops the WARNING line and the trailing
spaces while calling the block "VERBATIM". Minor ground-rule-1 fidelity slip (peripheral quote, not
cipher data).

**D3. P59Kf0cs is framed as "PRIMARY, 2017" without disclosing its first archive is 2020.**
MERGED §6/§7 lists the gate-message paste under "all PRIMARY, 2017" and cites a
`web/20230716…` capture. The on-disk source file's own header discloses that the **earliest Wayback
capture is 2020-06-06** and that "Capture date is 2020, NOT contemporary." The 2017 dating rests
solely on the internal (and in principle forgeable) PGP creation timestamp — which I did verify as
2017-04-02. Tier PRIMARY is defensible under ground rule 5 (PGP-signed artifacts count as PRIMARY),
but MERGED omits a material provenance fact its own source flags.

**D4. themessage.txt completeness caveat was dropped.**
MERGED §8 / V2 treats the 6448-char block as the complete `themessage.txt` and the 404-char Reddit
`63x2es` block as its "truncated prefix." The on-disk source
`ARTIFACT-themessage-txt-6448-chars-onion.txt` (lines 17-21) explicitly flags as **UNRESOLVED**
whether even the 6448-char block is complete — commenter #12: "Sorry, this is only the beginning …
Can't post the complete message (6448 letters!)" — and warns "DO NOT assume this is a truncated
prefix without re-checking." MERGED presents it as resolved. (I did verify the on-disk block IS
exactly 6448 chars and opens `MYVZZJCKTBWKOWUWZOCZMPJHWHFATRZV`; and the 1422-digit
`nothingisrandom` opens `601010109301050107020303`, stored doubled — both numeric claims correct.)

================================================================================================
## E. CLAIMS I TESTED THAT DID **NOT** REFUTE THE RECONSTRUCTION
================================================================================================

- **"Original beep WAV is lost / never archived."** The bartman GitHub repo has a file
  `original_sources/reddit/instaud_7fa2c325_hidden_link.wav`, which looked like a survival. It is
  NOT — it is a saved copy of the S3 error `<Error><Code>NoSuchBucket</Code>…<BucketName>instaudio`.
  So the corpus's "WAV lost" claim is **corroborated**, not refuted.
- Reddit attributions exact: `df02ruz`/tikitembo7/2017-03-16 12:06:27 UTC/score 4; nmap
  `dfmfx56`/MJMULDER/2017-03-30 21:20:35 UTC; OP `NimrodX0`/2017-03-15. defango timeout quote and
  `imgur.com/a/jX0ST` pointer present at lines 138/140. CEST→UTC conversion (23:17 CEST = 21:17 UTC)
  correct.

================================================================================================
## F. BOTTOM LINE
================================================================================================
- **Core artifact (176-char A/x block → A0/x1 MSB-first → hex → `666666m7x6x5regc.onion`, Tor v2):
  fully CONFIRMED. Zero discrepancies. Independently reproduced (my own decode) and independently
  sourced (GitHub mirror + live 2017-03-18 post, neither in the provenance list). No fabrication.**
- **agrees = false** is set only because of the peripheral items D1–D4 (a real error in file A, a
  mislabelled-"verbatim" nmap truncation, and two provenance/completeness omissions in the merged
  file). None affect the address derivation.
