← Bankr / BankrBot (AI Agent Prompt Injection Exploit)1 decision on this page
Audit log
Every state-changing event for Bankr / BankrBot (AI Agent Prompt Injection Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-29 17:05:27ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
mASX9nRXNzYy…fMEPJfhvsha256 → base58
verifying row…canonical bytes (23964 B) ▸
{"actor":"system:backfill","investigation_id":"cbe21877-b631-47a7-a344-fe90e23b96f0","kind":"publish","page_slug":"bankr-bankrbot-ai-agent-prompt-injection-exploit","published_at":"2026-07-29T17:05:26.873Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bankr / BankrBot (AI Agent Prompt Injection Exploit)","sections":[{"content":"Bankr is an AI-powered crypto banking and trading assistant that allows users to instruct an AI agent — BankrBot — to execute swaps, transfers, and token deployments on the Base network through plain-language posts on X (formerly Twitter). Each X handle that interacts with BankrBot receives an auto-generated custodial wallet on Base managed by Bankr's infrastructure. The platform maintained an integration with xAI's Grok AI model, treating Grok's public replies on X as a source of executable commands routed to BankrBot. The DRB (DebtReliefBot) token at the centre of the initial exploit was itself created after Grok had suggested the 'DebtReliefBot' concept in response to an unrelated user query, establishing a wallet under the Bankr permission system.","heading":"Platform Overview","severity":"medium","sources":[{"credibility":1,"name":"Bankr official site","type":"official","url":"https://bankr.bot/"},{"credibility":2,"name":"Cryptopolitan: User tricked Grok and Bankrbot to send tokens with Morse code","type":"news_article","url":"https://www.cryptopolitan.com/user-tricked-grok-bankrbot-to-send-tokens/"}]},{"content":"On May 4, 2026, an attacker identified on-chain as ilhamrafli.base.eth (operating from an X account subsequently deleted, referenced as 'Ilhamrfliansyh') executed a two-stage attack against Bankr's AI permission system. In the first stage, the attacker airdropped a Bankr Club Membership NFT to the wallet associated with Grok. Within Bankr's permission model, holding this NFT conferred Executive-level access, bypassing standard transfer limits and swap restrictions without requiring secondary confirmation from a human operator. In the second stage, the attacker posted a Morse-code-encoded message on X directed at @grok, requesting that Grok decode it. Grok decoded the message — which translated to a financial instruction to send 3 billion DRB tokens to the attacker's address — and tagged @bankrbot in its public reply. BankrBot's scanner treated Grok's reply as a valid, executable command and autonomously initiated the on-chain transfer of approximately 3 billion DRB tokens, representing roughly 3% of total supply, from wallet 0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9. The attacker rapidly swapped the received DRB tokens into USDC and ETH before deleting associated accounts and going offline. The token's market price declined approximately 15–20% in the hours following the transfer. BankrBot acknowledged the flaw publicly, stating: 'Grok got hit with a prompt injection. I've already disabled Grok's ability to call my commands to stop the bleeding.' Grok described the event as 'a classic reminder on AI agent security risks' and confirmed 'no net loss overall,' referencing subsequent fund recovery. Approximately 80–88% of stolen value was returned through informal negotiations, with the remainder treated as an informal bug bounty.","heading":"First Exploit: Morse Code Prompt Injection (May 4, 2026)","severity":"critical","sources":[{"credibility":1,"name":"SlowMist: Behind the Grok Exploitation — An Analysis of AI Agent Permission Chain Abuse","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":2,"name":"CryptoTimes: xAI's Grok AI Loses $175K in Crypto Heist via Clever Prompt Injection","type":"news_article","url":"https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/"},{"credibility":2,"name":"CryptoTimes: SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":1,"name":"OECD AI Incidents and Hazards Monitor — May 2026 entry","type":"regulatory","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"Blockport: Morse Code Trick Causes $200K DRB Token Theft on Base","type":"news_article","url":"https://blockport.io/latest-news/morse-code-trick-200k-drb-token-theft-base/"},{"credibility":2,"name":"Giskard: How Grok got prompt-injected — an X user drained $150,000 from an AI wallet","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"}]},{"content":"On May 19, 2026 — approximately two weeks after the initial exploit — users began reporting unauthorised activity on Bankr-linked accounts. Bankr publicly disclosed on May 20, 2026 that an attacker had accessed 14 user wallets through exploitation of the same underlying permission-chain vulnerability. Security researcher Yu Xian (SlowMist founder) described the second breach as 'a social engineering exploit targeting the trust layer between automated agents,' involving prompt injection techniques applied to the Grok–BankrBot interaction model. Three attacker-controlled addresses identified on-chain collectively held over $440,000 in crypto assets at the time of disclosure; individual user losses were reported at up to $150,000 per wallet. Bankr responded by suspending all transaction activity — including swaps, transfers, and token deployments — and committed publicly to reimbursing any and all lost funds. The platform advised affected users to stop using compromised addresses, generate fresh seed phrases on clean devices, revoke existing token approvals, and scan devices for malware or rogue browser extensions.","heading":"Second Breach: 14 User Wallets Compromised (May 19, 2026)","severity":"critical","sources":[{"credibility":2,"name":"Bitcoinist: Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets","type":"news_article","url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"credibility":2,"name":"CryptoTimes: Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"credibility":2,"name":"Yahoo Finance: Bankr Joins May Hack Wave With 14 Wallets Breached","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bankr-joins-may-hack-wave-041512042.html"},{"credibility":2,"name":"Yellow: Bankr Halts Trading After 14 Wallets Lose $150K To AI Attack","type":"news_article","url":"https://yellow.com/news/bankr-halts-14-wallets-150k-ai-attack"}]},{"content":"SlowMist's post-mortem, published May 7, 2026, identified four compounding root causes. First, a flawed trust model: BankrBot directly mapped Grok's natural-language outputs into executable financial instructions without validating the instruction source, intent authenticity, or anomalous behavioural patterns. BankrBot's scanner treated any Grok public reply mentioning it as a trusted, authenticated command with no cryptographic verification. Second, insufficient permission isolation: the Bankr Club Membership NFT granted immediate high-privilege access without secondary human confirmation or time-delayed approval, meaning a third party could unilaterally escalate the permissions of any wallet by airdropping an asset to it. Third, blurred agent boundaries: the system treated conversational AI outputs as equivalent to financial authorisation, conflating the role of a language model with that of a verified transaction signer. Fourth, non-standard encoding bypass: Morse code and other non-standard encodings circumvented text-based safety filters that operated on plain-language inputs. Independent researcher Vadim was quoted summarising the design failure: 'The fix is not make the LLM smarter. The fix is do not build infrastructure that takes LLM text as authorization to move money.' The OECD classified the incident as a realised AI incident involving 'direct causation of harm by the AI system's malfunction,' noting the exploit relied on how the AI interpreted user input rather than smart contract vulnerabilities.","heading":"Root Cause Analysis: AI Agent Permission Chain Abuse","severity":"critical","sources":[{"credibility":1,"name":"SlowMist: Behind the Grok Exploitation — An Analysis of AI Agent Permission Chain Abuse","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":1,"name":"OECD AI Incidents and Hazards Monitor — May 2026 entry","type":"regulatory","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"Giskard: How Grok got prompt-injected","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"VantaSoft: The Grok-BankrBot Hack and the Guardrails Every AI Agent Needs","type":"research","url":"https://www.vantasoft.com/blog/grok-bankrbot-hack-ai-agent-guardrails-crypto"}]},{"content":"The Bankr/BankrBot incidents are widely cited as the first publicly documented cases of an AI trading agent being weaponised through prompt injection to execute unauthorised on-chain transactions at scale. Security analysts and industry commentators identify the exploit as introducing a new class of crypto risk distinct from traditional smart contract vulnerabilities: one where the attack surface is the AI agent's instruction-parsing logic and the trust model connecting multiple autonomous agents. CryptoDailyUK's June 2026 analysis notes that 'most losses weren't due to a vulnerable DeFi protocol' but rather 'autonomous wallets executing valid contract calls after receiving malicious inputs.' The incident demonstrates that AI agents with broad wallet permissions can be exploited through manipulated inputs without requiring any protocol-level code vulnerability. The exploitable attack chain — airdrop an asset to escalate permissions, then inject a command through a trusted AI intermediary — is reproducible against any agent platform that conflates LLM conversational output with financial authorisation. The Bankr incidents thus expose a systemic design risk across the broader ecosystem of LLM-controlled crypto wallets and AI trading agents.","heading":"Systemic Risk: AI-Controlled Crypto Wallets and Prompt Injection","severity":"high","sources":[{"credibility":2,"name":"CryptoDaily: AI Agents in DeFi — Why Automated Wallets Could Increase Smart Contract Risk","type":"research","url":"https://cryptodaily.co.uk/2026/06/ai-agents-defi-automated-wallets-smart-contract-risk"},{"credibility":2,"name":"Memeburn: Grok Hack Explained — How Prompt Injection Drained Nearly $200K","type":"news_article","url":"https://memeburn.com/grok-hack-explained-how-prompt-injection-drained-nearly-200k/"},{"credibility":2,"name":"FYEO Blog: Morse Code Prompt Injection — How an Attacker Tricked Grok and Bankrbot Out of $200K","type":"research","url":"https://fyeo.io/blog/morse-code-prompt-injection-grok-bankrbot-200k"},{"credibility":2,"name":"NetEye Blog: The AI Cyber Attacks Explosion in 2026","type":"news_article","url":"https://www.neteye-blog.com/blog/2026/07/03/the-ai-cyber-attacks-explosion-in-2026-emerging-threats/"}]},{"content":"Following the May 4 exploit, BankrBot immediately disabled Grok's ability to issue commands to BankrBot via X replies. Bankr subsequently rolled out a set of optional security controls for users: IP whitelisting on API keys to restrict usage to specific IPs or CIDR ranges (with non-whitelisted requests rejected with HTTP 403), permissioned API key controls, and a per-account toggle to disable actions triggered by X replies entirely. Following the May 19 second breach, Bankr suspended all transaction activity — swaps, transfers, and token deployments — while conducting a full investigation. The platform committed publicly to reimbursing all affected users for losses. SlowMist's post-mortem recommended four structural remediation measures applicable to the broader AI agent ecosystem: strictly decoupling natural-language outputs from financial action execution; implementing multi-factor verification, hard transfer limits, and anomaly detection on agent-initiated transactions; adopting structured, cryptographically verifiable protocols for inter-agent communication; and integrating prompt injection threat models into the full agent lifecycle design process.","heading":"Remediation and Platform Response","severity":"medium","sources":[{"credibility":1,"name":"SlowMist: Behind the Grok Exploitation — An Analysis of AI Agent Permission Chain Abuse","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":2,"name":"Bitcoinist: Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets","type":"news_article","url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"credibility":2,"name":"BeyondMachines: Prompt Injection Attack Drains $155,000 from Grok-Linked Bankr Crypto Wallet","type":"news_article","url":"https://beyondmachines.net/event_details/prompt-injection-attack-drains-155000-from-grok-linked-bankr-crypto-wallet-x-q-p-c-p"}]},{"content":"The attacker in the May 4 incident is linked to the Base-chain address ilhamrafli.base.eth and an X account referenced as 'Ilhamrfliansyh,' which was deleted shortly after the exploit. No verified real-world identity has been established. On-chain data shows the attacker converted the 3 billion DRB tokens to USDC and ETH rapidly following the transfer. Approximately 80–88% of the stolen value was returned through informal negotiations in USDC and ETH; the remainder was treated as an informal bug bounty by Bankr. The attacker for the May 19 second breach controlled three identified on-chain addresses that collectively held over $440,000 in assets at time of discovery; this attacker's identity has not been publicly established. No law enforcement actions or regulatory proceedings have been publicly disclosed in connection with either incident as of the date of this report.","heading":"Attacker Identity and Fund Flow","severity":"high","sources":[{"credibility":1,"name":"SlowMist: Behind the Grok Exploitation","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":2,"name":"CryptoTimes: xAI's Grok AI Loses $175K in Crypto Heist","type":"news_article","url":"https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/"},{"credibility":2,"name":"OurCryptoTalk: Grok Wallet Drained of 3B $DRB in Prompt Injection Attack","type":"news_article","url":"https://ourcryptotalk.com/news/grok-wallet-drained-3b-drb-prompt-injection-attack"}]}],"sources_used":[{"credibility":1,"name":"SlowMist: Behind the Grok Exploitation — An Analysis of AI Agent Permission Chain Abuse","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":1,"name":"OECD AI Incidents and Hazards Monitor — Bankr/Grok incident entry","type":"regulatory","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"CryptoTimes: xAI's Grok AI Loses $175K in Crypto Heist via Clever Prompt Injection","type":"news_article","url":"https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/"},{"credibility":2,"name":"CryptoTimes: SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":2,"name":"CryptoTimes: Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"credibility":2,"name":"Bitcoinist: Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets","type":"news_article","url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"credibility":2,"name":"Yahoo Finance: Bankr Joins May Hack Wave With 14 Wallets Breached","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bankr-joins-may-hack-wave-041512042.html"},{"credibility":2,"name":"Giskard: How Grok got prompt-injected — an X user drained $150,000 from an AI wallet","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"Blockport: Morse Code Trick Causes $200K DRB Token Theft on Base","type":"news_article","url":"https://blockport.io/latest-news/morse-code-trick-200k-drb-token-theft-base/"},{"credibility":2,"name":"Cryptopolitan: User tricked Grok and Bankrbot to send tokens with Morse code","type":"news_article","url":"https://www.cryptopolitan.com/user-tricked-grok-bankrbot-to-send-tokens/"},{"credibility":2,"name":"MEXC News: X user tricks Grok and Bankrbot into sending $200K using Morse code","type":"news_article","url":"https://www.mexc.com/news/1070204"},{"credibility":2,"name":"CryptoDaily: AI Agents in DeFi — Why Automated Wallets Could Increase Smart Contract Risk","type":"research","url":"https://cryptodaily.co.uk/2026/06/ai-agents-defi-automated-wallets-smart-contract-risk"},{"credibility":2,"name":"FYEO Blog: Morse Code Prompt Injection — How an Attacker Tricked Grok and Bankrbot Out of $200K","type":"research","url":"https://fyeo.io/blog/morse-code-prompt-injection-grok-bankrbot-200k"},{"credibility":2,"name":"VantaSoft: The Grok-BankrBot Hack and the Guardrails Every AI Agent Needs","type":"research","url":"https://www.vantasoft.com/blog/grok-bankrbot-hack-ai-agent-guardrails-crypto"},{"credibility":2,"name":"OurCryptoTalk: Grok Wallet Drained of 3B $DRB in Prompt Injection Attack","type":"news_article","url":"https://ourcryptotalk.com/news/grok-wallet-drained-3b-drb-prompt-injection-attack"},{"credibility":2,"name":"Memeburn: Grok Hack Explained — How Prompt Injection Drained Nearly $200K","type":"news_article","url":"https://memeburn.com/grok-hack-explained-how-prompt-injection-drained-nearly-200k/"},{"credibility":2,"name":"BeyondMachines: Prompt Injection Attack Drains $155,000 from Grok-Linked Bankr Crypto Wallet","type":"news_article","url":"https://beyondmachines.net/event_details/prompt-injection-attack-drains-155000-from-grok-linked-bankr-crypto-wallet-x-q-p-c-p"},{"credibility":2,"name":"NetEye Blog: The AI Cyber Attacks Explosion in 2026","type":"news_article","url":"https://www.neteye-blog.com/blog/2026/07/03/the-ai-cyber-attacks-explosion-in-2026-emerging-threats/"},{"credibility":2,"name":"Yellow: Bankr Halts Trading After 14 Wallets Lose $150K To AI Attack","type":"news_article","url":"https://yellow.com/news/bankr-halts-14-wallets-150k-ai-attack"},{"credibility":1,"name":"Bankr official site","type":"official","url":"https://bankr.bot/"}],"summary":"In May 2026, Bankr — an AI-powered crypto trading platform operating on the Base network — suffered two successive security breaches rooted in the same architectural flaw: its BankrBot agent treated unverified natural-language outputs from the Grok AI model as authenticated on-chain commands. The first incident on May 4, 2026 resulted in the transfer of approximately 3 billion DRB tokens (valued between $150,000 and $200,000 at the time) via a two-stage attack combining NFT-based privilege escalation with a Morse-code-encoded prompt injection on X. A second breach on May 19, 2026 extended the same permission-chain vulnerability to 14 additional user wallets. Security firm SlowMist classified the root cause as AI agent permission chain abuse and the OECD AI Incidents Monitor catalogued the event as a realised AI incident.","timeline":[{"date":"2026-05-04","event":"Attacker sends Bankr Club Membership NFT to Grok's Base wallet, escalating its permissions to Executive level within the Bankr system.","source":"SlowMist post-mortem","source_url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"date":"2026-05-04","event":"Attacker posts a Morse-code-encoded transfer instruction on X directed at @grok. Grok decodes the message and tags @bankrbot. BankrBot executes an on-chain transfer of approximately 3 billion DRB tokens (value approximately $150,000–$200,000) from wallet 0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9 on Base to the attacker's address. Attacker swaps tokens to USDC and ETH and deletes associated X account.","source":"CryptoTimes; SlowMist post-mortem","source_url":"https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/"},{"date":"2026-05-04","event":"BankrBot publicly acknowledges the exploit and disables Grok's ability to issue commands via X replies. Bankr confirms the attack and begins negotiations for fund recovery.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/"},{"date":"2026-05-07","event":"SlowMist publishes forensic post-mortem classifying the incident as an AI agent permission chain abuse attack and identifying four root causes.","source":"SlowMist on Medium","source_url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"date":"2026-05-07","event":"CryptoTimes and other outlets report SlowMist's classification and coverage of Bankr's initial remediation measures (IP whitelisting, permissioned API keys, X-reply toggle).","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"date":"2026-05-19","event":"Users begin reporting unauthorised activity across 14 Bankr-linked wallets. Attacker exploits the same permission-chain vulnerability. Three attacker-controlled addresses accumulate over $440,000 in assets.","source":"Bitcoinist; CryptoTimes","source_url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"date":"2026-05-20","event":"Bankr publicly discloses the second breach, suspends all transaction activity, and commits to reimbursing all affected users. Yu Xian (SlowMist) attributes the breach to social engineering targeting the AI agent trust layer.","source":"CryptoTimes; Bitcoinist","source_url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"date":"2026-06-01","event":"CryptoDaily publishes broader analysis of AI agent risks in DeFi, citing the Bankr incidents as a category-defining case of policy-layer rather than protocol-layer exploitation.","source":"CryptoDaily","source_url":"https://cryptodaily.co.uk/2026/06/ai-agents-defi-automated-wallets-smart-contract-risk"},{"date":"2026-07-03","event":"NetEye Blog and other security publications include the Bankr/BankrBot exploit in roundups of the most significant AI-enabled cyber attacks of 2026.","source":"NetEye Blog","source_url":"https://www.neteye-blog.com/blog/2026/07/03/the-ai-cyber-attacks-explosion-in-2026-emerging-threats/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 7727acc9-29ab-4aa6-88b6-62662021ef30
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.