Insights
Short-form commentary on real software-in-court cases — the specific technical artifact that decided each one.
12 attempts in one day: when the bank's alert system should have screamed
An Israeli court held Bank Leumi liable for an unstopped wire transfer after 12 suspicious same-day attempts exposed its alert system's blind spot.
Read the insight →One update pushed to 1,500 businesses. None of them asked for it.
United States v. Yaroslav Vasinskyi: how the Kaseya VSA supply-chain ransomware attack is proven as a chain of distinct technical evidence, not one story.
Read the insight →A secret lasted longer in a filing cabinet than in a gaming chat
United States v. Jack Teixeira: a classified Pentagon leak posted to a small Discord server was traced across platforms back to one Air Guardsman.
Read the insight →The breach that turned therapy notes into a weapon
Finland v. Kivimaki: how technical attribution across server logs, extortion infrastructure, and bitcoin tracing built the Vastaamo breach case.
Read the insight →The VPN gap that unmasked an insider extortionist
United States v. Nickolas Sharp: correlated VPN and ISP logs unmasked an employee who stole data, extorted his employer, and posed as the whistleblower.
Read the insight →One misconfigured firewall rule, 100 million records
United States v. Paige Thompson: a misconfigured AWS firewall exposed 100M+ Capital One records, and the perpetrator's own bragging almost solved nothing.
Read the insight →One second of Snapchat, a mile of GPS: how a real timeline gets built
State v. Alex Murdaugh shows how a multi-device digital timeline is actually built, and what a software expert tests when sources don't share one clock.
Read the insight →3,500 pages in a box: when the form of production is the dispute
An Israeli district court asked whether dumping printed pages satisfies discovery when the material exists digitally.
Read the insight →Tirosh v. Terflex: why a software defect claim collapses without an expert
In supplier-client software disputes, the case rarely fails on the story — it fails on the proof, and on what was preserved before filing.
Read the insight →The Karen Read case: how one timestamp became a national argument
In the Karen Read case, a single Google-search timestamp reading became the spine of the defense — the artifact does not speak for itself.
Read the insight →A Locked Phone Isn't Evidence. It's a Safe.
An Israeli ruling on a suspect's locked, seized phone shows the real fight isn't over the passcode
Read the insight →AI-Hallucinated Citations: When a Motion Cites Cases That Don't Exist
An Israeli court rejected a motion built on AI-fabricated statutes and case law, and ruled that the burden to verify AI output sits with whoever files it.
Read the insight →Thaler v. Perlmutter: authorship needs a human hand
The Supreme Court let the AI-authorship ruling in Thaler v. Perlmutter stand. The next fight is proving whose hand actually shaped an AI-assisted work.
Read the insight →Six Seconds: The Log That Put a Human on Trial
The first fatal self-driving pedestrian case turned on the car's classification log and driver-monitoring video — why it needs a court-grade expert.
Read the insight →CFAA and the access log that never asked why
Van Buren v. United States turned on one fact: the access log showed who searched and when, not why. That gap is where CFAA cases are won or lost.
Read the insight →Uber's CSO: when the cover-up becomes the evidence
Uber's ex-CISO was convicted over a hidden 2016 breach. The bug-bounty ticket, the NDA, and the e-signature log became the evidence against him.
Read the insight →Mango Markets: the trade that was fraud, then wasn't
A $110M DeFi exploit was fraud in 2024 and legal in 2025 — same oracle and trade records, opposite verdicts. What that split means for software evidence.
Read the insight →Google v. Oracle: the API code the Court didn't rule on
Google v. Oracle turned on 11,500 lines of Java code, and the Court sidestepped copyrightability. Why the artifact, not the label, decided the case.
Read the insight →Epic v. Apple: when App Store architecture becomes the evidence
Epic v. Apple turned twice on the code: Fortnite's hidden hotfix, then engineering emails contradicting sworn testimony. Why it needs a software expert.
Read the insight →Vault 7: the CIA insider case that turned on a log file
The Vault-7 leak conviction turned on CIA access logs — a restored backup, deleted entries, and whether the trail survived cross-examination.
Read the insight →Autopilot on trial: the marketing name versus the vehicle's own log
The first US felony Autopilot-crash case turned on the vehicle's own event data, not the brand name — why it needs a court-grade software expert.
Read the insight →Terra-Luna: when the algorithm becomes evidence
The Terra-Luna collapse shows how a failed software mechanism becomes courtroom evidence
Read the insight →AI Prompts as Evidence: When an Expert's AI Tools Become Part of the Opinion
A landmark U.S. ruling held that an expert's AI prompts are discoverable methodology — making the computer-engineering expert the de-facto gatekeeper
Read the insight →When code is silent and the service speaks: Tornado Cash and the developer-liability principle
In the Pertsev case a developer was convicted over a privacy tool whose core smart contracts could not be changed after deployment
Read the insight →COPA v. Wright: when metadata refutes a witness
In the trial where Craig Wright claimed to be Bitcoin's creator, forensic analysis of metadata
Read the insight →When the watch testifies: Fitbit data vs. the defendant
In the Dabate case the victim's Fitbit step data contradicted the timeline the defendant gave.
Read the insight →Horizon: when 'the computer says so' is simply wrong
Hundreds of UK subpostmasters were prosecuted on shortfalls that the Horizon software reported
Read the insight →FTX, auto-deleting messages, and what survives anyway
SBF directed FTX staff toward auto-deleting messaging, and the court treated that policy as evidence.
Read the insight →Pegasus in the Netanyahu courtroom: what the defense actually got
The court ordered some spyware-related material disclosed to the defense while protecting method-privilege — not everything, and not the tool itself.
Read the insight →