Detailed research note

Lantern: operational signals, programme control and financial-account decisions

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

Bounded primary-source pass, observed 9 September 2026. This is Tech Coalition's child-safety programme, not a similarly named political vendor. No canonical case changes. Acquisition stopped at this operational-record breakpoint; rights and remedy analysis is separately recorded in lantern-rights-review.md.

Finding and limits

Lantern provides a documented mechanism through which one company's child-safety investigation can inform another company's account or financial-service decision. The operator reports a case involving 18 Cash App account closures and action on Xbox accounts. Block separately confirms that its investigations team uses Lantern signals. These are meaningful programme and participant accounts of operational use, but the specific closures, arrests, accuracy and counterfactual effect have not been independently established in this pass. The public material allocates admission and programme standards to Tech Coalition, hosting to Meta, signal selection and labelling to originating companies, and subsequent investigations and enforcement to receiving companies. It does not establish a single actor directing every resulting decision.

Money, infrastructure and admission

The 2024 transparency report states that participation has no cost, that Tech Coalition and its members fully fund the programme, and that Meta provides technical hosting in kind. Eligible non-members can apply. This supports organizational funding and an in-kind infrastructure relationship; it does not show a monetary budget, participant-by-participant payment, restricted award, or donor approval right. The current programme and membership pages are institutional descriptions rather than financial ledgers. Their funding statements do not establish the legal entity making each payment. [2024 report, PDF 4](http[local research file] [programme page](http[local research file]

Tech Coalition administers applications and compliance review. The 2024 report describes a formal legal agreement between participants after acceptance; it also describes more granular requirements for properly staffed teams able to investigate and act responsibly. Tech Coalition maintains the Official Program Expectations and reviews them with participating companies. In 2025, Tech Coalition expressly administers vetting and grants database access. Meta's in-kind hosting on ThreatExchange is reaffirmed. Hosting does not by itself establish editorial approval of individual signals, ownership of participant decisions, or a veto over programme rules. The executed agreement, hosting contract and individual voting or veto rights were not acquired. [2024 report, PDF 5–6](http[local research file] [2025 report, PDF 16, 28–29](http[local research file]

Admission standards have a reported consequence: the 2024 report says one unnamed participant could not meet compliance requirements and would not continue in 2025. This is evidence of the operator announcing non-continuation, not independent identification of that company or confirmation of the revocation date. The report counts 26 enrolled companies at the end of 2024, including three financial institutions; the 2025 report counts 31 at year end. The undated current programme page displays 38 participants as observed on 9 September 2026. Those are different observation periods, not interchangeable totals. NGOs, governments, law enforcement and researchers are excluded from programme participation. A law-enforcement request can initiate a company's investigation without making that authority a Lantern member or signal uploader. [2024 report, PDF 4, 7, 9](http[local research file] [2025 report, PDF 9](http[local research file] [programme FAQ](http[local research file]

What enters the system and who labels it

Signals extend beyond hashes of known abuse imagery. Public examples include URLs, account identifiers, keywords or codewords, repeated unsolicited contact with minors, attempts to move conversations between platforms, and payment requests or extortion language. Participants choose what to share and ingest within programme rules, their policies and legal obligations. Published rules require manual review before upload and receiving-company investigation before action. They require a connection to online child sexual exploitation and abuse (OCSEA), necessity and proportionality, consistency with applicable law and public terms or privacy policies, and permitted sharing under the agreement. These are stated operating requirements, not independent proof of compliance in every case. [Programme page, signal sections and FAQ](http[local research file] [2024 report, PDF 14](http[local research file] [2025 report, PDF 28–29](http[local research file]

Tech Coalition maintains the taxonomy in collaboration with participants, which may propose updates. At least one official taxonomy tag is required; severity and review status accompany signals. The public appendix supplies names and definitions, while the full taxonomy's examples are not published, with sensitivity given as the reason. The reports explicitly distinguish platform-policy classifications from legal determinations: some included behaviour may violate a platform's policy without being criminal CSAM. [2024 report, PDF 14, 19–21](http[local research file] [2025 report, PDF 14](http[local research file]

The scope of individual tags matters. Minor Sexualization extends beyond criminal imagery. Grooming (Inappropriate Contact) concerns inappropriate adult–child trust-building behaviour before an explicit sexual stage; it does not label every adult–child contact. The outrage and humour meme categories require depiction of CSAM or sexualization of minors; they are not generic political outrage or satire categories. Financial Transaction is supplemental and cannot stand alone: it concerns evidence or communication about a completed or proposed transaction possibly connected to abuse. The supplemental self-harm category is likewise connected to OCSEA. These distinctions prevent promotion of a child-safety taxonomy into an unbounded payments, speech or mental-health classification system. [2024 report, Appendix A, PDF 19–21](http[local research file]

The 2025 report describes a new sadistic-online-exploitation tag tied to sexualized suffering, fear or humiliation; an additional protocol for data about minors suspected of perpetration expects extra precautions to verify the basis and necessity of sharing, with Tech Coalition-coordinated one-to-one sharing with the company directly implicated. Platform tags, including Steam, are cross-platform investigation context; they do not establish membership or an enforcement action. Proposed alignment with the Industry Classification in 2026 is forward-looking language in this report, not proof that it occurred. Whitelisted sharing, introduced in 2024, also permits sharing with selected partners rather than every participant. [2025 report, PDF 14–15](http[local research file] [2024 report, PDF 12](http[local research file]

The financial route: pilot, expansion and an attributed case

The public pilot account, dated 17 July 2025, identifies Cash App, MEGA, Meta, PayPal, Snap and Western Union as the six participants in an August 2024–first-half-2025 pilot. Tech Coalition reports 1,935 shared signals and 108 financial-institution investigations, some still ongoing, plus reports to US government authorities. It does not supply a count of prosecutions or convictions. Financial participants receive signals but do not upload them. The full pilot report is offered through the Member Resource Center or by contacting Tech Coalition; this pass used the public account and did not authenticate or request access. [Pilot results](http[local research file]

On 14 May 2026, the operator announced eligibility for qualifying financial institutions worldwide, evaluated individually, with priority for peer-to-peer payments. This is an expansion of eligibility, not proof that every bank, payment provider or cryptocurrency service participates. The announcement preserves the receive-only role. [Financial expansion announcement](http[local research file]

In the 2025 transparency report's case study, a law-enforcement request led Meta to conduct its own investigation into alleged CSAM production and distribution, report to NCMEC, and share signals through Lantern. Tech Coalition says Block then identified a network of 18 Cash App accounts suspected of CSAM sales or purchases, closed those accounts, banned users and reported to authorities; Microsoft acted on several Xbox accounts. The report further says law enforcement confirmed a contribution to multiple arrests. No identifiable police release, court docket or underlying order corroborating those arrests was acquired. The evidentiary verb remains “Tech Coalition reports.” This sequence does not show government uploading directly into Lantern. [2025 report, PDF 8](http[local research file]

Block's own September 2025 publication independently establishes what that participant publicly says about its use: Cash App is active in Lantern, and its investigations team uses signals as intelligence and assesses detection rules and product or risk controls. This corroborates participation and claimed operational use from the receiving company, but does not independently verify the particular 18-account case. Its adjacent overall NCMEC reporting figure must not be attributed wholly to Lantern. The same page separately places Cash App in ICMEC's US Financial Coalition Against Child Sexual Exploitation; that is a concrete organizational participation bridge, not evidence that ICMEC controls Lantern. [Block report, PDF 19 / printed 18](http[local research file]

Outcome totals require care

The 2025 report counts 983,602 signals shared and retained for that year. Its cumulative figure is 2,047,982 for 2023–2025, with the retention cut-off stated as 3 March 2026. Retained signals are not all uploads ever made, unique people, or verified criminal cases. The combined action headline also adds accounts, URLs and content units; it is not a count of people. Outcomes are voluntarily supplied by companies, and the operator says its downstream-action measures exclude the original uploader's prior actions. That is a reported accounting rule, not an independently tested causal estimate. [2025 report, PDF 5–7, 16](http[local research file]

There is an unresolved discrepancy inside the captured original: PDF 5 and 7 give 31,504 account actions for 2025, while PDF 16 gives 31,485, a difference of 19. PDF 5 and 16 were visually checked. Do not silently select one or infer wrongdoing from the inconsistency. The report does not establish wrongful-action rates or the proportion of decisions subsequently reversed. The 44,210 removed signals reported on PDF 11 mix reasons that are not publicly disaggregated; deletion is not a measure of confirmed false positives. The separate rights packet covers the original uploader's removal right and the gap concerning propagation of corrections to earlier recipient decisions.

Read scope and custody

Seven originals were captured through ordinary public GETs. lantern-captures.json records exact URLs, byte counts, SHA-256 hashes and reading scopes. Hashes identify original response bytes; extracted text and renders are derivatives. Pages below mean physical PDF pages; printed pages coincide for the two Lantern reports.

Captured source Date and actual inspected scope
2025 report Reporting year 2025; release landing dated 28 April 2026. Reader text PDF 3–12 and original extraction PDF 13–16, 24–29 read for this lane. PDF 5 and 16 visually checked. Not a comprehensive visual audit of all 30 pages.
2024 report Reporting year 2024; publication day not established. Original text PDF 4–7, 9, 12–14, 19–21 read; cover/contents inspected. PDF 4 and 20 visually checked.
Programme page Undated current page, observed 9 September 2026. Main body, signal sections, FAQ and funding footer read.
Membership page Undated current page, observed 9 September 2026. Main body/footer read as general institutional context; no fee amount or Lantern allocation established.
Financial expansion Main article dated 14 May 2026, read in full from capture. HTML title names an unrelated Initiate 2026 item; article heading/date/body identify the source used here.
Financial pilot results Main article dated 17 July 2025, read in full. Restricted full pilot report not accessed.
Block report Cover dated 10 September 2025; cover and PDF 19 / printed 18 read from the original. Not a comprehensive review of the 21-page report.

The old /lantern/ route failed in the reader; the site's actual /programs/lantern/ route succeeded. The financial-expansion reader timed out once; an ordinary GET substitute succeeded. Root's closed BSR PDF GET failure was not retried; its selected reader passages remain under the separate rights packet's custody. No private account or dataset was accessed.

Integration boundary and next discriminator

Precise supported relations are: Tech Coalition/member funding of Lantern without allocated amounts; Meta's in-kind hosting; Tech Coalition admission, access and programme-standard administration; participants' manual signal selection and shared taxonomy development; and recipients' own investigation and policy decisions. The 18-account outcome must remain attributed to the operator. No individual member's veto, mandatory recipient sanction, government membership, or donor instruction is established.

The strongest local forest implication is a concrete handoff from platform intelligence to financial-service exclusion, with authority distributed across admission, classification, infrastructure, origination and recipient decision-making. The strongest alternative to a centrally directed sanction system is the published model of legally constrained, company-specific investigations against genuinely cross-platform child exploitation. Public self-reports alone cannot determine how consistently that model operates or how errors travel.

The next discriminating record is the operative participant agreement and a worked, anonymized correction case showing originator retraction, notification to prior recipients, treatment of exported copies, reopening of earlier restrictions, and user notice or remedy. Those records would distinguish a reversible intelligence exchange from a system in which corrected signals can leave lasting distributed consequences. The Tech Coalition programme office and involved participants are the likely custodians; no outreach is authorized or undertaken. A disclosed programme budget or hosting agreement would separately resolve who pays what and any associated rights. This bounded pass stops here.