incidents / campaign / xinzhai-2026-07

the xinzhai persistence run

unattributed
period2026-07-10 to 2026-07-20
venuespaste.ubuntu.org.cn 3574
attribution basistask-content-match
one population?probable one label root across three record types, one evening's write test and eight snapshots, one cipher for the snapshots and one for the stream, ten days on one schedule. one operator is the plain reading; who is unknown
developerunattributed
records3574 across 79 handles
related

one operator on paste.ubuntu.org.cn, 2026-07-10 to 07-20 (utc+8 as displayed). 21:26 three print('hello') tests under 'xinzhai'. 21:32 to 22:43 eight fernet-encrypted snapshots under xinzhai_v5.2, v52, v60, v61, v70, v71, v72, v73, each split into 30,000-char pastes (4 to 14 parts), plaintext growing from about 65 kb to 231 kb in 71 minutes and never shrinking. the version string changes shape once ('5.2' to '52'), which reads like a hand renaming a save. 22:24 onward 3,484 small opaque posts under xz_knowledge_p1 every five or six minutes for ten days, in ten fixed sizes (124 to 572 chars, 500 the commonest at 1,134). 07-12 to 07-19 eleven posts of exactly 864 chars under xz_improvement_plan_p1, roughly six hours apart until the schedule drifts. three record types, one key scheme for the snapshots (fernet, python cryptography), another for the small ones (no header, unique per message). contents unrecovered. reads like an agent's persistence layer (memory, log, plan) on a public pastebin. operator, model and country unknown

tasks

xinzhai encrypted storethe three record types of the xinzhai run: versioned fernet snapshots, five-minute knowledge posts, six-hour plan posts. see the campaign3574

sources

secondaryopaque paste research mirror: 1,142 xz_knowledge_p1 posts with text, manifest and readme, checkpoint 2026-09-05 12:13 utcnewsites aggregation server, china notebook2026-09-05data/leads/live-2026-09-05b/ip178
primarypaste.ubuntu.org.cn ids 4548500 to 4552399, every page saved, author, tag, displayed time, length and head indexedai-safety-lab (live pull)2026-07-10data/leads/live-2026-09-05b/ubuntu-cn

claims

statusaboutclaimmade bychecked by
reportedthe xinzhai persistence runno confirmed chinese agent swarm; the storage pattern does not establish an agent, an operator or a lab
the investigators' own assessment. our crawl adds the write tests and the six snapshots before the stream, which strengthens 'one operator, automated' and adds nothing on who
china-notebook-mirrorubuntu-cn-crawl
verifiedthe xinzhai persistence runthe 3,484 xz_knowledge_p1 bodies are ten fixed sizes of keyless-looking ciphertext: entropy 7.999 bits per byte over the mirror's 314 kb, no constant byte positions within a cohort, xor of same-size pairs random, not zlib, deflate, gzip or double base64, not fernet
tested on the 1,142 mirrored bodies, cohort sizes confirmed on all 3,484 from the crawl. what leaks is size: ten templates, plaintexts about 65 to 344 bytes if aead. nothing here can be an image
china-notebook-mirrorubuntu-cn-crawl
verifiedthe xinzhai persistence runthe xinzhai_v5.2 to v73 blobs are fernet tokens (version 0x80, aes-128-cbc plus hmac, python's cryptography recipe) wrapped in a second base64 layer, with embedded timestamps 2026-07-10 13:31 to 14:43 utc, eight hours behind the displayed times
header parsed only. no key, no decryption attempted, no contents read. eight versions in 71 minutes; cbc padding gives plaintext sizes 65,472 to 231,152 bytes to within 15, growing 12 to 34 kb a save. no 44-char key-shaped token in any of 4,800 pages crawled around the series, and no xinzhai post outside the 07-10 to 07-20 window
ubuntu-cn-crawlubuntu-cn-crawl