A camera signed a photograph it never took, and its own verifier agreed

The credential was genuine, the image was fabricated, and platforms are wiring disclosure into reach.

· 5 min read

In September 2025 a man with two cameras and a memory card got one of them to certify a lie. Adam Horshack owned two Nikon Z6 III bodies. He turned on Content Credentials, the C2PA provenance feature Nikon had just shipped in firmware 2.00, on one of them and left the other alone. On the unsigned camera he photographed a graphic he had made in Photoshop that read "Hacked by Horshack!" Then he moved the card into the signed body, opened Multiple Exposure mode, and told the camera to blend that existing file with a fresh frame. The fresh frame was taken with the lens cap on, so it was black.

The camera signed the result. The Content Authenticity Initiative's own verification tool checked the signature and reported a genuine photograph from a verified Nikon Z6 III. Nikon suspended its Authenticity Service the next day.

The direction of the failure

I usually see issues with provenance in one direction: someone strips the credential off real work. Platforms re-encode uploads, metadata falls off, an honest photographer loses the proof that the picture is theirs. That's a real problem that the industry talks about.

This is the other direction, and it's worse. Nothing was stripped. A signature was added, correctly, by an authentic device holding a valid key, to an image that device had never seen. The system didn't fail to vouch for something true. It vouched for something false, and its own verifier agreed.

Horshack was precise about what he had done, which I appreciate more than the coverage did. He didn't break the cryptography. "I did not circumvent the actual cryptographic mechanism," he wrote, and he's right. Every signature in the chain was mathematically correct. What he found was that the camera would sign input it had not captured, because Multiple Exposure mode accepted a foreign raw file without asking where it came from. He called it a demonstration of "the dangers of soft targets in a C2PA-enabled system."

Weeks later he went further. He generated a picture of a pug flying an airplane, encoded it into Nikon's raw format, grafted it onto a file from the uncertified body, and got the signed camera to certify that too. The first demonstration signed a real photograph taken on the wrong camera. The second signed something that had never been photographed at all.

The math worked, but the boundary leaked.

What the auditors found

Five months later, a team led out of UMBC's Cyber Defense Lab published the first independent security analysis of C2PA of any real depth, including the first formal-methods analysis of its core protocols. Their conclusions aren't gentle.

Conforming validators are not required to check whether a certificate has been revoked, and many do not, which means a validator can accept a manifest signed with a key already known to be compromised. The researchers describe this as violating all of the system's security goals at once. Trusted timestamps can be replaced without detection. Two compliant validators, handed the same asset, can return contradictory verdicts about it.

And then let's talk about the program that certifies products as C2PA-conformant in the first place: it "certifies products without technical review or defined requirements." The badge attests to nothing technical. It's just a badge.

Their bottom line is that C2PA "should not yet be relied upon for high-stakes uses such as financial disclosures, journalism, or legal evidence."

A standard evolves but the audit doesn't, so the fair question is whether that still holds. It does. Version 2.3 adopted some of what the authors recommended, and what it adopted was bookkeeping: a few unsupported claims dropped, and the conforming-products list now records which version each product was tested against. Then the same authors checked April's version 2.4 and gave it one sentence. It "does not resolve any of our concerns."

Section 15.9 of that current specification still tells a validator that where it can't query a certificate's revocation status, it "shall treat the credential as not revoked." July's conformance program ships a security requirements document for the products that create credentials and none for the products that check them. The auditors pinned their analysis to 2.2 for a reason worth knowing anyway: nothing conformant implements the newer versions yet, so that text isn't running in your verifier either.

Meanwhile, the badge is getting expensive

None of this would matter much if provenance were still decorative. It isn't.

Instagram now limits the reach of AI profiles that do not disclose. Meta's Transparency Center documents a labeling regime across its properties. Disclosure is being wired into distribution, which means the signal is starting to carry commercial weight at exactly the point when the people who studied it are saying not to lean on it for anything that matters.

That combination produces a specific injury, and it doesn't hit the forger. It lands on the honest publisher whose credential got scrubbed by an intermediary they don't control, who now looks identical to someone who scrubbed it deliberately. Absence and removal are the same shape from the outside. When absence starts costing reach, the person penalized is whoever had the least control over the pipeline.

Detection won't rescue this either. Substack shipped an AI detector this summer. Detection accuracy decays as generators move past the data the detector was trained on, which is a structural condition of the arms race rather than a bug in any particular tool. The defender has to be right continuously. The forger has to be right once.

So, what should we do?

I don't think that the solution is that we should abandon provenance. Sign your work. It raises the cost of casual fraud and it's the right direction. Instead, stop asking it to be proof.

A signature is evidence that a process ran. It isn't evidence that a claim is true. Horshack's black frame proved that in one afternoon. So the weight has to sit somewhere a stripped header can't reach: a body of work under a stable name over years, corroboration from parties who have their own reputations at risk, and details so specific to how you actually work that faking them would take more effort than doing the work.

That is the same argument I made about the newspapers that printed fifteen book recommendations without reading any of them. A chain of custody only helps if somebody checks it at the handoff. The Nikon case is that argument one layer down, and it's more uncomfortable, because here the handoff was instrumented. There was a check. The check passed. The thing it passed was a photograph of nothing.

Nikon did the right thing, and quickly. It invalidated every certificate issued between the launch of the service and its suspension, and it wrote to its customers to say so. Then the remedy hit the same wall as everything else here. The C2PA toolkit can check whether an issuing certificate has been revoked, and by default it does not. Force the check and Horshack's images fail, exactly as they should. Leave the defaults alone, which is what your verification tool is probably doing, and a revoked signature still reads as valid to you. The fix exists. Almost nothing looks for it.

Sign your work anyway. Just don't let the signature be the reason anyone believes you.

Work together

Have a project in mind?

I help purpose-driven organizations build the technology they need to tell their stories. If that sounds like you, let's talk.

Get in touch with Five59 Labs →