C2PA's exclusion feature lets you sign nothing and fake timestamps
How to hack time, with C2PA

David Buchanan demonstrates a time-hacking exploit in C2PA by abusing arbitrary byte-range exclusions. By excluding the entire file, he creates a valid signature over an empty hash, allowing post-hoc tampering without invalidating the signature or the trusted timestamp. He shows a photoshopped EuroMillions ticket with a valid C2PA timestamp hours before the draw. The flaw is known but unfixed; he suggests format-specific exclusion rules.
We're effectively signing nothing at all, but as of today all the C2PA verification tools I can find don't flag anything as unusual.