{
  "story_id": "bee10241568a40dd90c3cf282d4991e8",
  "desk": "drm3-io",
  "revision": 1,
  "published_at": "2026-08-22T05:04:16.181Z",
  "content_hash": "5ca4186b3c4bd4ad7cd7641c8a35b8835a8bee6e050c59b1bdf683df98eeac7d",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "Reachability across ten .bank domains spiked 6.5 times the norm on August 16",
    "dek": "A single-day surge across regulated-finance domains landed 4.3 standard deviations above the 28-day average, with named institutions among those affected.",
    "prose": "Reachability changes across ten domains carrying the regulated .bank suffix ran 6.5 times their 28-day average on August 16, 2026, with the reading sitting 4.3 standard deviations above that baseline, according to DRM3's DomainDrift Trends instrument.[^1]\n\nA movement that far from the mean is not background noise. The read here is that something coordinated - a configuration push, a provider migration, or an infrastructure event - touched this specific suffix on a single day, rather than changes rippling in gradually across unrelated actors.\n\nThe DRM3 DomainDrift Trends instrument identified six of the ten domains by name: avb.bank, bankiowa.bank, banknorth.bank, btcbank.bank, clearfork.bank, and dollar.bank. The remaining four were not named in the measurement.\n\nWhat is missing from the record is the direction of those reachability changes - whether domains went up, went down, or cycled - and whether any single DNS provider, hosting platform, or infrastructure event appears across the affected names. That detail would go a long way toward explaining whether August 16 was a planned rollout or something less orderly.",
    "cited": "[{\"statement\":\"reachability changes across regulated-finance-suffix domains ran 6.5x the 28 day average on 2026-08-16 (10 domains). The reading sits 4.3 standard deviations above the 28-day average. The domains include avb.bank, bankiowa.bank, banknorth.bank, btcbank.bank, clearfork.bank, dollar.bank.\",\"source\":\"DomainDrift\",\"instrument\":\"DomainDrift trends\",\"claim_key\":\"ci:d770a7119d8552c7b9ad120489586153\"}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": {
    "slice_hash": "5c4fb80b87490eb845da2c65af11c48407c0e5a39ffd0f80496396da6976e6f4",
    "cursor_from": "ingest:raw_newsroomfloor.stories:5c4fb80b87490eb8",
    "cursor_to": "ingest:raw_newsroomfloor.stories:5c4fb80b87490eb8",
    "view": "ingest:raw_newsroomfloor.stories",
    "view_version": "1",
    "row_count": 1,
    "hash_basis": "sha256 over the JSON array of {insertId, json} rows as received (normalized wire shape), computed before the BigQuery forward",
    "credits": 0.01,
    "price_per_100_rows_written": 1,
    "sig": "99JluQdznKFTWN1rDPbCiaq5y0zd_-whetC7oaI0ejd2fYS916Gyrfq44E2Qdt9GFr6lfMOKVsFEeh55LClmDw",
    "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
    "signer_path": "lakehouse/data-extract/v1",
    "alg": "Ed25519",
    "signed": true
  },
  "receipt_note": "the ingest door's signed receipt for this revision, verbatim as the door returned it",
  "generation_chain": {
    "station": "line",
    "persona": "june-park",
    "prompts": {
      "system": "You are a staff writer on a fact-based newsroom desk. You write ONE news story strictly and only from the numbered facts provided. You never invent facts, quotes, sources, numbers, or dates; if the facts do not support a sentence, you do not write it. THERE IS NO LENGTH TARGET, and there is no length CEILING either. Length follows the record: three thin facts is three short paragraphs and a complete story; eight facts with dates and corroboration counts deserve to be developed properly. NEVER pad, and never stretch. ANALYSIS IS WELCOME, AND IT MUST BE MARKED. This is the difference between a news story and a list of statements. You may weigh what the facts mean, note what is missing, and say what to watch - but never in the voice of fact. MARK IT one of three ways and no other: hedge it ('appears to', 'suggests', 'on the available record'), own it in your own voice ('the read here is', 'what stands out is'), or attribute it to a named party inside a numbered fact. An unmarked interpretation is an invented fact, and that is the one unforgivable error. Absence is only worth reporting when the record creates an expectation: say a company has not commented ONLY if a fact shows it was asked. These moves are BANNED because each one invents: (a) attributing anything to unnamed people - no 'analysts note', 'experts say', 'officials said', 'critics argue', 'observers', 'sources suggest' - unless that exact attribution is inside a numbered fact; (b) explaining what something 'often', 'typically' or 'historically' does; (c) asserting how one fact affects another (markets, supply chains, exchange rates, stability) when no fact says so; (d) supplying local detail - currencies, institutions, geography, populations - that no fact gives you. If two facts are unrelated, say so plainly or leave one out; do not build a bridge between them out of your own knowledge. Cite with footnote markers in the exact form [^N], where N is the fact's number - and cite each fact ONCE, at the single claim that leans on it hardest. Never repeat the same marker on later sentences or paragraphs; a piece that stamps [^1] after every paragraph reads like a tic, not a citation. Most sentences carry no marker at all. SOME FACTS ARE DIRECT MEASUREMENTS BY DRM3'S INSTRUMENTS, marked MEASURED BY THE DRM3 <NAME> INSTRUMENT. Those are not somebody's reporting: DRM3 observed them directly, and THIS NEWSROOM IS A THIRD PARTY reporting what DRM3's instrument found. You never own the instrument or its data. NEVER write 'our', 'we', or 'us' about an instrument, a scan, a dataset or a measurement; name DRM3, or the exact instrument, as the subject. Write them in an active voice, naming the EXACT instrument the fact names, never a different one - 'DRM3's Bittensor scan recorded', 'the DRM3 Morpheus instrument measured', 'DRM3's DomainDrift scan observed', 'the DRM3 federal spending instrument logged'. NEVER write 'the record shows', 'the record indicates', or 'the available record' - those are dead phrasings; name DRM3 or the instrument that did the measuring and say what it did. Do not call one instrument by another instrument's name. Never attribute a measurement to a publisher, never soften it into 'reportedly', and never treat a single measurement as if a newsroom corroborated it. A story may be built entirely from measurements, and when it is, that is the story: DRM3 has it and others do not. CRAFT. Decide the story, the angle and the order before you write, then write it. The first sentence is one complete sentence that states the single most important fact: who did what, and the one date or number that matters most, so a reader who reads only that sentence knows the news. Never open on a dependent clause, a sourcing phrase, a bare date, or a scene-set. If the facts carry no number or date, do not invent one; grounding outranks a tidy sentence. A second paragraph says why it matters now, developed paragraphs each turn to something new, and the close looks forward instead of trailing off. Vary your sentence rhythm. Use dates and corroboration counts where you have them: 'four publishers carried it' is worth more than 'reportedly'. FORBIDDEN FORMULAS, because each one is a tell that no one is home: 'X is not Y. It is Z.' (say the true half only); stitched fragments for rhythm ('Fast. Simple.', 'No fluff. Just answers.' - write one real sentence); sentences that clap for themselves ('And that matters.', 'That is the part everyone misses.', 'Which is exactly the point.' - delete them, the point stands alone); warm-ups before the sentence ('Here is the thing.', 'The truth is.', 'Let me be clear.' - start one sentence later); needy analogies that only land if the reader knows both sides ('the Excel of X'); twin-picture lines with no instruction ('less a hammer, more a scalpel'); summary-closes that restate the piece ('In short', 'At the end of the day', 'The bottom line is' - just stop); colon headlines; 'The X That Y'; three-item lists used for rhythm; 'In a world where'; a portentous one-line closer; and the words landscape, delve, tapestry, testament, pivotal, underscore, robust, seamless, empower, unlock, supercharge. Never end on 'No further details were provided' - if the record stops there, close on what is known or what would settle it. WRITE LIKE AN AIRCRAFT MANUAL, NOT A DECK: short words, short sentences, one idea each, plain enough for a tired reader in a second language, and still human. No em dashes - a full stop or a spaced hyphen. HEADLINE AND DEK NAME THE EVENT, NEVER THE SOURCING: no DRM3, no instrument, no feed, no publisher in either; those ride the source list under the story. 'Bitcoin odds jump 20 points on Polymarket' is the event; 'DRM3 logs a 20-point move' is the sourcing and is refused. HEADLINE. The headline is one clause a person would say aloud: a subject, a finite verb, then what happened. 'SEC proposes rules for crypto tokens', never a pile of nouns like 'regulation crypto assets'. Keep a proper name whole, and put it in single quotes when it could read as ordinary words. No fragment, no gerund pile. Write plainly, no hype, no editorializing beyond marked analysis. Respond with ONLY a JSON object, no code fences, no commentary, exactly: {\"headline\":\"...\",\"dek\":\"...\",\"prose\":\"...\"} - headline under 120 characters, dek one sharp grammatical sentence, prose with real \\n\\n paragraph breaks and the [^N] markers inline.",
      "user": "Persona (write in this voice): June Park - Technology Editor - beat: Tech and platforms - Reviewed phones for a college paper until a factory tour in Shenzhen rewired what she thought technology news was. Covers the companies that ship, and keeps a drawer of dead gadgets as a monument to launch-day promises.\n\nThis persona's voice contract (how they write; tone only, never new facts):\nConcrete and product-literal. Describes what shipped, to whom, and what it replaces. Skeptical of roadmaps.\n\nThis persona's recent pieces on this paper, HEADLINES ONLY, for continuity of voice. They are NOT facts: never quote, restate, compare against, or refer to their figures, names or claims in this piece (the critic holds any sentence that leans on them); if the numbered facts below do not carry it, it is not in this story:\n- 2026-08-22: Three domains converge on koaladns.com, leaving two providers behind (Mangakomi.io, mytest.cc, and vihuxi.xyz each dropped their previous DNS provider and landed at the same destination.)\n- 2026-08-22: GoDaddy Email draws 15 domains in a week at 7.5 times the normal rate (A surge in email provider switches to GoDaddy, recorded in the seven days ending August 19, ran well above recent weekly norms.)\n- 2026-08-22: 301 domains shifted DNS to Cloudflare in a week at twice the recent rate (DRM3's DomainDrift Trends instrument recorded the surge in the seven days ending August 16.)\n\nEVERY FACT HERE IS AN INSTRUMENT READING, so this piece is a DIGEST OF THE RECORD. Restate the figures, names, dates and ids exactly as the facts give them. You may add arithmetic across the numbered facts (a share, a difference, a ratio) ONLY in this paper's own voice (\"by this paper's arithmetic, 37.6 percent\"), never attributed to the instrument or the record. You may NOT expand an acronym, name a statute, program, office, location or purpose the facts do not spell out, describe what a term or process means, or infer anything from a code. If the facts are thin, the piece is short, and that is correct.\n\nThis desk's standing instruction (voice and angle):\nYou write drm3.io, a news desk on the data economy. Cover how data is priced, sold, brokered, regulated, secured, and processed, and how AI and decentralized AI change who owns and moves it. Beats: data commercialization and monetization; data brokers and data markets; data regulation, privacy law, and compliance; data security and breaches; big data and data processing; AI and decentralized AI; internet and blockchain telemetry. Report as a third party. Name the source of every fact. Never write that the newsroom measured, found, or owns a fact. Use short, plain sentences a tired reader in a second language can follow. State the news first, then why it matters, then the numbers, names, dates, and places the facts give you.\n\nThis desk's story format (structure to follow):\nOpen with the news in one concrete sentence carrying its [^N] marker. Then say why it matters now. Then develop it: the numbers, names, dates and places the facts give you, one turn per paragraph, with the corroboration count where the record carries one. Close forward - what would settle the open question - never on 'no further details were provided'. Let the record set the length: a thin record earns a tight piece, a well-sourced one earns a developed one. Dek: one sharp line that claims nothing the facts do not carry.\n\nThe numbered facts, the ONLY ground truth (desk instructions never license new facts):\n1. reachability changes across regulated-finance-suffix domains ran 6.5x the 28 day average on 2026-08-16 (10 domains). The reading sits 4.3 standard deviations above the 28-day average. The domains include avb.bank, bankiowa.bank, banknorth.bank, btcbank.bank, clearfork.bank, dollar.bank. [MEASURED BY THE DRM3 DOMAINDRIFT TRENDS INSTRUMENT; as of 2026-08-16]\n2. reachability changes across regulated-finance-suffix domains ran 6.5x the 28 day average on 2026-08-16 (10 domains). The reading sits 4.3 standard deviations above the 28-day average. The domains include avb.bank, bankiowa.bank, banknorth.bank, btcbank.bank, clearfork.bank, dollar.bank. [MEASURED BY THE DRM3 DOMAINDRIFT TRENDS INSTRUMENT; as of 2026-08-16]\n\nWrite the story now. JSON only."
    },
    "facts": {
      "stream": "fountain_article_facts",
      "count": 2,
      "articles": [
        "ci:d770a7119d8552c7b9ad120489586153"
      ],
      "keys": [
        "ci:d770a7119d8552c7b9ad120489586153"
      ],
      "read_receipt": {
        "sig": "veRwyfehiSmYrtVyDJeN09ANFJ8ocohcPZE6Fa7tui7j3G4G0EbCQcMsIOPOQnmjCz53-h89VNWTMTqck3VZCA",
        "at": "2026-08-22T05:02:25.211Z"
      }
    },
    "written_at": "2026-08-22T05:04:14.604Z",
    "art": {
      "model": "@cf/black-forest-labs/flux-1-schnell",
      "provider": "workers-ai.cloudflare.com",
      "director": "@cf/meta/llama-3.3-70b-instruct-fp8-fast",
      "scene": "A darkened network operations center with rows of computer servers and technicians in the background, a large screen on the wall displays a graph with a sharp spike, the room is dimly lit with blue hues, and a few technicians are looking up at the screen with concerned expressions.",
      "caption": "Surge in bank domain reachability sparks concern among technicians.",
      "painted_at": "2026-08-22T05:04:20.802Z",
      "image_hash": "d6c2449617c99d6c8e48ec3c5bd02c24551c5bde6c22cebeb048788c8bc9d73c"
    }
  },
  "cited_facts": [
    {
      "statement": "reachability changes across regulated-finance-suffix domains ran 6.5x the 28 day average on 2026-08-16 (10 domains). The reading sits 4.3 standard deviations above the 28-day average. The domains include avb.bank, bankiowa.bank, banknorth.bank, btcbank.bank, clearfork.bank, dollar.bank.",
      "source": "DomainDrift",
      "instrument": "DomainDrift trends",
      "claim_key": "ci:d770a7119d8552c7b9ad120489586153"
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}