In 2024 the High Court in London held that Craig Wright is not Satoshi Nakamoto and did not author the Bitcoin white paper. The decision rested not mainly on human testimony, but on forensic document analysis: metadata, fonts, timestamps and inconsistencies in the files Wright submitted to support his claim.

This is the quiet power of digital evidence: a document carries its own history inside it. Someone who edits a file and tries to pass it off as old is often caught not by the content, but by the technical margins he forgot were there:

  • Creation, modification and access timestamps that do not match the claimed date.
  • A font or format version that did not exist on the date the document purports to carry.
  • Software traces (the editing tool, the operating system, PDF attributes) that belong to a later period.
  • A mismatch between the file’s history and the story told about it.

The lesson reaches well beyond Bitcoin identity. In any dispute over authenticity, originality or date of creation — a contract supposedly signed on a given date, an “original” email, code allegedly written before a competitor’s — the same principle holds. An expert’s first question is not “what does the document say,” but “what does the file’s technical history say, and is it consistent with the claim?”

Why this needs a computer forensics expert witness

Reading metadata looks simple: open the file properties and check the date. In practice every one of those fields can be edited, and some change on their own with each copy. A timestamp put before a court without an account of how it was produced, what alters it, and the file’s chain of custody is a finding that will not survive cross-examination.

That is the work behind a computer forensics expert witness: not reading the field aloud, but explaining what it does and does not establish, and where the versions contradict each other.