𝕏 contact / share tips

LJF Forensics — About

what this archive is, and what it proves · ← page search · ▦ gallery · 👥 community · 🔁 reuse clusters

The LJF Forensics Archive is an offline, independently-verifiable copy of what the foundation published on its two websites — lilyjayfoundation.com and lilyjayfoundation.com.au — much of it since deleted from the sites, which remain online. It is preserved so anyone can examine the open questions about the foundation from the primary source, rather than take anyone's word for it.

Why it exists

The Lily Jay Foundation is an Australian humanitarian fundraising project (#TeamGaza / #TeamSudan). Its website began deleting content after ABC News Verify published an investigation on 5 July 2026 reporting AI-generated and manipulated material in the foundation's charity videos and award images. (ABC News Verify, 5 Jul 2026)

This archive captured 1,754 pages from lilyjayfoundation.com plus 124 from a second live site, lilyjayfoundation.com.au, along with roughly 3,000 media files — many since deleted from the still-live sites. Every page is traceable to a dated snapshot in the Internet Archive's Wayback Machine, so the record can be independently confirmed.

Two domains

The foundation publishes on two live websiteslilyjayfoundation.com and lilyjayfoundation.com.au — which share much of the same content and the same media library. This archive preserves both. Every search result and image is labelled with the domain(s) it appears on (.com, .com.au, or both), so you can see where each item was published. Where the same post appears on both, the archive keeps one copy and links the .com.au capture next to it. That the same posts and photos run on two separate domains is a mechanical observation — what it means is for you to weigh.

What you can do here

What the findings prove — and what they don't

This archive states mechanical facts as facts — that a page existed on a given date, that a file is present, that an image appears on multiple posts — because those are directly verifiable. Everything else is framed as an open question or attributed to its source. The archive does not assert that the foundation committed fraud or that any specific image is fake.

Community evidence is unverified until reviewed. Anyone can add a note; contributions show as unverified until a moderator marks them verified. Corroboration counts how many people agree — it is a signal, not proof.

Reverse-image-search results are a signal, not a verdict. "No matches" or "matches a stock photo" is context for you to weigh, not a conclusion the archive draws for you.

Right of reply & corrections

If you represent the Lily Jay Foundation, or you believe anything here is inaccurate, corrections and a right of reply are welcome. Contact @mostaniner on X.

How to verify anything yourself

Snapshot history

The Internet Archive often holds more than one capture of the same page over time. Every archived page shows its full snapshot history in the 📼 panel (bottom-right): each dated Wayback capture, newest and oldest alike. A marks a capture whose page bytes differ from the one before it — i.e. the page changed at some point between captures.

Where a version's content differs, this archive mirrors that version locally too, so you can open it inside the archive (not just on Wayback) and it survives even if the Internet Archive is unreachable. From inside any page you can switch straight to an earlier or later crawl.

What a differing capture proves: only that the page's bytes were not identical — that can be a content edit or just changed boilerplate. It's a signpost to look, not a verdict. Open the two versions and compare them yourself.

Content credentials (C2PA)

Some archived images carry an embedded C2PA content credential — a record attached by the software that created or edited the file, describing how it was made. Where the archive detects one, the image page and gallery show a badge.

What a credential says: if it carries the IPTC trainedAlgorithmicMedia assertion, the file itself declares that it was generated by an AI model. That is a mechanical fact about the bytes — anyone can read it — not an opinion. Of the images flagged here, the manifests name GPT-4o, gpt-image or OpenAI-API as the generator and are signed under OpenAI's certificate chain; one is signed under Google's C2PA media-services chain.

Why public validators report these as “invalid”. If you upload one of these files to a checker such as contentcredentials.org/verify, it will say the credential cannot be verified and that the file may have been manipulated. That is expected, and it is worth understanding why.

A validator re-hashes the image's current pixels and compares them with the hash signed into the manifest. Every flagged file here also records a c2pa.converted action — each image was re-encoded after it was signed (the site served its media through an image pipeline, which re-compresses uploads). Re-encoding changes the pixels, so the signed hash no longer matches and the binding breaks.

So “invalid” here means “the chain of custody broke downstream”, not “the credential is fake.” The manifest is still present and intact — in one case a 98 KB signed container naming its generator, and carrying its own recorded validation results (“claim signature valid”) from before the conversion step. Equally, this cuts both ways: because the signature no longer binds to this copy, the archive cannot cryptographically prove the assertion. Read it as strong evidence of AI origin, not as proof.

What it does not prove: credentials are easily stripped when an image is re-saved or re-uploaded, so their absence does not mean an image is authentic. A credential could in principle be added by anyone. This archive reports a credential's presence and contents; it does not independently re-verify the cryptographic signature, and — for the reasons above — a third-party validator will not verify it either.

Image reuse (perceptual hashing)

The archive fingerprints every image with a perceptual hash and groups files that are near-identical — the same photo re-saved, re-cropped, or re-uploaded under a different filename. Where an image belongs to such a group, its image page and the gallery show a 🔁 badge with the number of copies, and the image page links to each one. Browse all reuse clusters →

What this is: a mechanical observation about the pixels — that two files are visually the same image — computed offline, with no AI and no external service.

What it does not prove: reuse on its own is not wrongdoing — organisations legitimately reuse their own photos, and "near-identical" is a similarity threshold, not a guarantee of an exact match. Treat a cluster as context to weigh, not a verdict. Where the same image appears on pages for different campaigns — for example Gaza and Sudan — the archive notes that as well, again as an open question for you to examine rather than a claim the archive draws for you.