Transparency · updated monthly

Warrant canary.

A signed, time-bound statement designed to make silence visible. The plaintext below is the canonical source.

Current statement

Current and signed

2026-09

A PGP signature is attached and the statement is inside its validity window.

PGP fingerprint

889D A7D2 DCFB 4F60 6B41 7D06 80E3 18D8 60BD 9FCD

Statement SHA-256

cd5106acb1f216bfe4e37ddc08423a78f0519a44701051f5bd1ee93d2eb1d9f2

PGP signature

Attached

Public key

Published

Published

Sep 12, 2026

Renew by

Oct 17, 2026

What the operator attests

These claims are trustworthy only after independent signature verification.

01

leak.fun has not received a National Security Letter, secret court order, or other classified demand for user information.

02

leak.fun has not received an order requiring the operator to weaken, backdoor, or otherwise compromise the service.

03

leak.fun is not subject to a gag order that prevents disclosure of a request for user information.

04

leak.fun has not knowingly provided bulk access to user data or cryptographic key material to a government or law-enforcement agency.

05

No leak.fun canary signing key has been seized or compromised to the operator's knowledge.

Canonical statement

This is the exact content served at /canary.txt.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

leak.fun Warrant Canary
Version: 1
Status: ACTIVE
Statement-ID: 2026-09
Published-At: 2026-09-12T17:40:00.600Z
Valid-Until: 2026-10-17T17:40:00.600Z
PGP-Fingerprint: 889D A7D2 DCFB 4F60 6B41 7D06 80E3 18D8 60BD 9FCD
Public-Key-URL: https://leak.fun/canary-key.asc
Previous-Statement-SHA256: ea384419510066e7edec8d8012c1b8ba05fdb2d1a10181a1b3e91a10c30ceea2
Freshness-Proof: Bitcoin latest block hash: 00000000000000000001cd8fd39ad2b6be5976bf4b45965f6590c7619a008d34; Ethereum latest block hash: 0xa94976da5a227fddc26d2d90bc14299501c848de4118831a2c4f0a09462c81e4
Bitcoin-Block-Hash: 00000000000000000001cd8fd39ad2b6be5976bf4b45965f6590c7619a008d34
Ethereum-Block-Hash: 0xa94976da5a227fddc26d2d90bc14299501c848de4118831a2c4f0a09462c81e4

The leak.fun operator affirms the following statements as of the Published-At
timestamp above.

Statements:
1. leak.fun has not received a National Security Letter, secret court order, or other classified demand for user information.
2. leak.fun has not received an order requiring the operator to weaken, backdoor, or otherwise compromise the service.
3. leak.fun is not subject to a gag order that prevents disclosure of a request for user information.
4. leak.fun has not knowingly provided bulk access to user data or cryptographic key material to a government or law-enforcement agency.
5. No leak.fun canary signing key has been seized or compromised to the operator's knowledge.

Continuity: The Previous-Statement-SHA256 field links each signed statement to
the complete bytes of the statement that preceded it. A missing, late, invalid,
or broken-chain statement should be investigated, but is not by itself proof
that any event described above has occurred.

Scope: These statements are made only to the operator's knowledge as of the
Published-At timestamp. They are a transparency signal, not legal advice or an
absolute guarantee.

End-of-statement: leak.fun warrant canary version 1
-----BEGIN PGP SIGNATURE-----

iJEEARYKADkWIQSInafS3PtPYGtBfQaA4xjYYL2fzQUCaqWOfBsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDEACgkQgOMY2GC9n80ofAEAygYN9TxfbDlz4JHpZlYX
pMNAgHy9TalvwxoN1odtFsMBAKHqMHLsJAh3LpxXbgFcIWyUzegq7h28hE+N52va
qAAH
=rPeL
-----END PGP SIGNATURE-----

Freshness proof

Recent Bitcoin and Ethereum block hashes make silent backdating harder.

Bitcoin block hash
00000000000000000001cd8fd39ad2b6be5976bf4b45965f6590c7619a008d34
Ethereum block hash
0xa94976da5a227fddc26d2d90bc14299501c848de4118831a2c4f0a09462c81e4

How to interpret a change

A missing, late, invalid, or broken-chain statement is a signal to investigate. It is not, by itself, proof that a secret demand or compromise occurred.

Verify independently

Do not trust the visual badge alone. Verify the file and compare the fingerprint.

  1. 1

    Download the plaintext statement and the public key.

  2. 2

    Import the public key into a local GPG keyring.

  3. 3

    Verify the clear-signed statement with GPG.

  4. 4

    Compare the reported fingerprint with the one shown here and in a second trusted channel.

Verification command
gpg --verify canary.txt

Statement archive

Previous statements remain available so the monthly hash chain can be audited.