Strawberry Tabby Leak Evidence: Analyzing the Claims, Documents, and Data
Establishing document authenticity requires looking past sensational headlines and examining the digital trail evidence left behind in the raw files. Independent data forensics specialists analyzed the metadata, compilation timestamps, and network artifacts embedded in the archive.
Their findings revealed a split reality: core technical output logs demonstrated genuine internal infrastructure signatures, while several accompanying narrative documents appeared assembled post-leak to drive engagement.
| Document Component | Forensic Status | Primary Technical Evidence |
|---|---|---|
| Inference Evaluation JSON Logs | Verified Authentic | Valid internal cluster IDs; consistent token serialization patterns across 12,000+ test runs. |
| Internal Benchmark Spreadsheets | Likely Authentic (Partial) | Timestamps match recorded pre-release evaluation phases; formatting matches internal reporting templates. |
| Executive Memos & Narratives | Unverified / Fabricated | Inconsistent PDF metadata; font mismatches; missing digital signatures present on genuine company memos. |
| Compute Expenditure Forecasts | Corroborated by Third Parties | Figures align with public venture reporting and supply-chain hardware procurements (2024, 2026). |
Source verification processes confirmed that the benchmark data was exfiltrated from an internal sandbox environment used by red-team evaluation contractors. However, the sensational claim that the model had achieved autonomous software exploitation without human guidance derived entirely from unverified allegations appended by anonymous forum posters.