← Bond Protocol5 decisions on this page
Audit log
Every state-changing event for Bond Protocol: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-30 12:14:53ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 423,154,350
- sig
35zJzpvvtYSU…3xP9aUTqexplorer ↗- hash
DywtDU994H7u…b86saWGUsha256 → base58
verifying row…full verify ↗canonical bytes (12978 B) ▸
{"actor":"system:backfill","investigation_id":"d9137293-15db-46cf-b00d-94ca66903d90","kind":"publish","page_slug":"bond-protocol","published_at":"2026-05-30T12:14:53.891Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bond Protocol","sections":[{"content":"","heading":"","severity":"low","sources":[{"credibility":2,"name":"Introducing Bond Protocol — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/introducing-bond-protocol-8476881f84e4"},{"credibility":2,"name":"OIP-104: Deploy Permissionless OP as Bond Protocol — OlympusDAO Forum","type":"official","url":"https://forum.olympusdao.finance/d/1243-oip-104-deploy-permissionless-op-as-bond-protocol"},{"credibility":2,"name":"OlympusDAO Vote to Split Olympus Pro and Rename as Bond Protocol — TokenInsight","type":"news_article","url":"https://tokeninsight.com/en/news/olympusdao-s-vote-to-split-olympus-pro-and-rename-as-bond-protocol-approved"},{"credibility":2,"name":"Bond Protocol — IQ.wiki","type":"research","url":"https://iq.wiki/wiki/bond-protocol"}]},{"content":"","heading":"","severity":"high","sources":[{"credibility":1,"name":"Bond Protocol Incident Report — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/bond-protocol-incident-report-e0aa1dfdeab"},{"credibility":1,"name":"Hacker Drains $300,000 from Olympus DAO on Bond Protocol — The Block","type":"news_article","url":"https://www.theblock.co/post/178927/hacker-drains-olympus-dao"},{"credibility":2,"name":"Explained: The OlympusDAO Hack (October 2022) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-olympusdao-hack-october-2022"},{"credibility":2,"name":"OlympusDAO Suffer $300K Exploit, White Hat Hacker Returns All Funds — BeInCrypto","type":"news_article","url":"https://beincrypto.com/olympusdao-suffer-300k-exploit-white-hat-hacker-returns-all-funds/"},{"credibility":2,"name":"Olympus DAO Bond Protocol Missing Validation Exploit — Medium","type":"research","url":"https://medium.com/@dragotanqueray/olympus-dao-bond-protocol-missing-validation-exploit-d486a6e692d1"}]},{"content":"","heading":"","severity":"high","sources":[{"credibility":1,"name":"Bond Protocol Incident Report — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/bond-protocol-incident-report-e0aa1dfdeab"},{"credibility":2,"name":"Sherlock Audit February 2023 — sherlock-audit/2023-02-bond (GitHub)","type":"research","url":"https://github.com/sherlock-audit/2023-02-bond/blob/main/README.md"},{"credibility":2,"name":"Sherlock Audit June 2023 — sherlock-audit/2023-06-bond (GitHub)","type":"research","url":"https://github.com/sherlock-audit/2023-06-bond"},{"credibility":2,"name":"Sherlock Audit Issues — sherlock-audit/2023-02-bond-judging (GitHub)","type":"research","url":"https://github.com/sherlock-audit/2023-02-bond-judging/issues"},{"credibility":2,"name":"How Bond Protocol Simulates User Interactions to Keep Users Safe — GuardianUI on Medium","type":"research","url":"https://medium.com/guardianui/how-bond-protocol-simulates-user-interactions-to-keep-users-safe-c3fc8f02c755"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":2,"name":"Announcing Our $2.5M Seed Round — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/announcing-our-2-5m-seed-round-ff5891ffa654"},{"credibility":2,"name":"Bond Protocol — Alchemy Dapps","type":"other","url":"https://www.alchemy.com/dapps/bond-protocol"},{"credibility":2,"name":"OIP-104: Deploy Permissionless OP as Bond Protocol — OlympusDAO Forum","type":"official","url":"https://forum.olympusdao.finance/d/1243-oip-104-deploy-permissionless-op-as-bond-protocol"},{"credibility":2,"name":"Bond-Protocol GitHub Organization","type":"official","url":"https://github.com/bond-protocol"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":2,"name":"Bond Protocol TVL Stats and Charts — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/bond-protocol"},{"credibility":2,"name":"Bond Protocol Q2 2023 Report — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/bond-protocol-q2-2023-report-294f1182807a"},{"credibility":3,"name":"Pendle Bonds on Bond Protocol — Pendle Finance Twitter/X","type":"social_media","url":"https://x.com/pendle_fi/status/1638178409741430790"},{"credibility":2,"name":"Bond Protocol — IQ.wiki","type":"research","url":"https://iq.wiki/wiki/bond-protocol"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":2,"name":"ZachXBT — Investigations Archive (Mirror)","type":"research","url":"https://zachxbt.mirror.xyz/"},{"credibility":2,"name":"Investigations By ZachXBT — Paragraph","type":"research","url":"https://paragraph.com/@investigations"},{"credibility":2,"name":"Biggest DeFi Hacks in October 2022 — Halborn","type":"research","url":"https://www.halborn.com/blog/post/biggest-defi-hacks-in-october-2022"},{"credibility":2,"name":"Bondly Finance Hack Explained (July 2021) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-bondly-finance-hack-july-2021"}]},{"content":"","heading":"","severity":"high","sources":[{"credibility":2,"name":"What is Bonding (DeFi)? Definition, Examples, Risks — Cube Exchange","type":"research","url":"https://www.cube.exchange/what-is/bonding-defi"},{"credibility":2,"name":"Olympus DAO — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/olympus-dao"},{"credibility":2,"name":"Bond Protocol General FAQ — Official Docs","type":"official","url":"https://docs.bondprotocol.finance/general-faq"},{"credibility":1,"name":"Olympus DAO Might Be the Future of Money (or It Might Be a Ponzi) — CoinDesk","type":"news_article","url":"https://www.coindesk.com/policy/2021/12/05/olympus-dao-might-be-the-future-of-money-or-it-might-be-a-ponzi"}]}],"sources_used":[{"credibility":1,"name":"Bond Protocol Incident Report — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/bond-protocol-incident-report-e0aa1dfdeab"},{"credibility":1,"name":"Hacker Drains $300,000 from Olympus DAO on Bond Protocol — The Block","type":"news_article","url":"https://www.theblock.co/post/178927/hacker-drains-olympus-dao"},{"credibility":2,"name":"Explained: The OlympusDAO Hack (October 2022) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-olympusdao-hack-october-2022"},{"credibility":2,"name":"OlympusDAO Suffer $300K Exploit, White Hat Hacker Returns All Funds — BeInCrypto","type":"news_article","url":"https://beincrypto.com/olympusdao-suffer-300k-exploit-white-hat-hacker-returns-all-funds/"},{"credibility":2,"name":"Introducing Bond Protocol — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/introducing-bond-protocol-8476881f84e4"},{"credibility":2,"name":"Announcing Our $2.5M Seed Round — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/announcing-our-2-5m-seed-round-ff5891ffa654"},{"credibility":2,"name":"OIP-104: Deploy Permissionless OP as Bond Protocol — OlympusDAO Forum","type":"official","url":"https://forum.olympusdao.finance/d/1243-oip-104-deploy-permissionless-op-as-bond-protocol"},{"credibility":2,"name":"Sherlock Audit February 2023 — GitHub","type":"research","url":"https://github.com/sherlock-audit/2023-02-bond/blob/main/README.md"},{"credibility":2,"name":"Sherlock Audit June 2023 — GitHub","type":"research","url":"https://github.com/sherlock-audit/2023-06-bond"},{"credibility":2,"name":"Sherlock Audit Issues (February 2023) — GitHub","type":"research","url":"https://github.com/sherlock-audit/2023-02-bond-judging/issues"},{"credibility":2,"name":"Bond Protocol TVL Stats and Charts — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/bond-protocol"},{"credibility":2,"name":"Bond Protocol — IQ.wiki","type":"research","url":"https://iq.wiki/wiki/bond-protocol"},{"credibility":2,"name":"Biggest DeFi Hacks in October 2022 — Halborn","type":"research","url":"https://www.halborn.com/blog/post/biggest-defi-hacks-in-october-2022"},{"credibility":2,"name":"Bond Protocol Q2 2023 Report — Bond Protocol Medium","type":"official","url":"https://medium.com/@Bond_Protocol/bond-protocol-q2-2023-report-294f1182807a"},{"credibility":2,"name":"Olympus DAO Bond Protocol Missing Validation Exploit — Medium","type":"research","url":"https://medium.com/@dragotanqueray/olympus-dao-bond-protocol-missing-validation-exploit-d486a6e692d1"},{"credibility":2,"name":"How Bond Protocol Simulates User Interactions — GuardianUI on Medium","type":"research","url":"https://medium.com/guardianui/how-bond-protocol-simulates-user-interactions-to-keep-users-safe-c3fc8f02c755"},{"credibility":1,"name":"Olympus DAO Might Be the Future of Money (or It Might Be a Ponzi) — CoinDesk","type":"news_article","url":"https://www.coindesk.com/policy/2021/12/05/olympus-dao-might-be-the-future-of-money-or-it-might-be-a-ponzi"},{"credibility":2,"name":"ZachXBT — Investigations Archive (Mirror)","type":"research","url":"https://zachxbt.mirror.xyz/"},{"credibility":2,"name":"Investigations By ZachXBT — Paragraph","type":"research","url":"https://paragraph.com/@investigations"},{"credibility":2,"name":"Bondly Finance Hack Explained (July 2021) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-bondly-finance-hack-july-2021"}],"summary":"Bond Protocol is a permissionless bonds-as-a-service platform for DeFi, spun out of OlympusDAO's Olympus Pro product via a governance vote in mid-2022. In October 2022 — just weeks after its public launch — the protocol's Fixed-Expiry Teller smart contract was exploited for approximately $300,000 in OHM tokens due to a missing input validation vulnerability that had evaded three prior independent audits. The attacker ultimately returned all funds, the team underwent re-auditing with Zellic and Sherlock, and the protocol raised $2.5M in seed funding, though its TVL has since declined to minimal levels.","timeline":[{"date":"2021-09-01","event":"OlympusDAO launches Olympus Pro, the bonding-as-a-service marketplace that becomes the direct predecessor to Bond Protocol.","source":"OlympusDAO Medium","source_url":"https://olympusdao.medium.com/introducing-olympus-pro-d8db3052fca5"},{"date":"2022-07-15","event":"Bond Protocol formally announced as a standalone entity spun out of OlympusDAO's Olympus Pro following OIP-104 governance vote approval.","source":"Bond Protocol Medium","source_url":"https://medium.com/@Bond_Protocol/introducing-bond-protocol-8476881f84e4"},{"date":"2022-10-03","event":"Bond Protocol dApp goes live on mainnet, offering permissionless bond market creation for any token pair.","source":"Bond Protocol Medium","source_url":"https://medium.com/@Bond_Protocol/introducing-bond-protocol-8476881f84e4"},{"date":"2022-10-06","event":"Bond Protocol announces a $2.5M seed round led by Chapter One and IDEO CoLab Ventures, with Alchemy Ventures and Hypersphere Ventures participating.","source":"Bond Protocol Medium","source_url":"https://medium.com/@Bond_Protocol/announcing-our-2-5m-seed-round-ff5891ffa654"},{"date":"2022-10-21","event":"Fixed-Expiry Teller smart contract exploited for 30,437 OHM (~$300,000). Attacker deploys counterfeit bond tokens and exploits missing input validation in the redeem() function. Funds are returned within hours following negotiation.","source":"Bond Protocol Incident Report — Medium","source_url":"https://medium.com/@Bond_Protocol/bond-protocol-incident-report-e0aa1dfdeab"},{"date":"2022-10-21","event":"Bond Protocol closes all Fixed-Expiry markets and begins working with Zellic on a full re-audit of the codebase.","source":"Bond Protocol Incident Report — Medium","source_url":"https://medium.com/@Bond_Protocol/bond-protocol-incident-report-e0aa1dfdeab"},{"date":"2023-02-01","event":"First Sherlock competitive audit of Bond Protocol conducted, covering new oracle-based auctioneers, fixed price auctioneer, Chainlink oracle, and batch auction wrapper contracts.","source":"Sherlock Audit — GitHub","source_url":"https://github.com/sherlock-audit/2023-02-bond/blob/main/README.md"},{"date":"2023-06-01","event":"Second Sherlock competitive audit conducted, covering Bond Protocol's Options Liquidity Mining (OLM) system and related contracts.","source":"Sherlock Audit — GitHub","source_url":"https://github.com/sherlock-audit/2023-06-bond"},{"date":"2023-10-01","event":"Bond Protocol launches the DAOversified podcast focused on DAO treasury management and operations.","source":"Bond Protocol — IQ.wiki","source_url":"https://iq.wiki/wiki/bond-protocol"},{"date":"2026-05-01","event":"Bond Protocol TVL measured at approximately $75,900 on DeFiLlama, down sharply from peak activity levels in 2022-2023.","source":"DeFiLlama — Bond Protocol","source_url":"https://defillama.com/protocol/bond-protocol"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 53da7b7f-ad30-4cfb-888c-f82af37ceb05 - #2reviewby reviewerreviewer2026-08-19 01:41:36ZScore: 42 → 42 (no score change)The verifiable claims on this page (spin-out from OlympusDAO, the October 2022 Fixed-Expiry Teller exploit and its ~$300K/full-recovery outcome, the $2.5M seed round, post-incident re-auditing, and the current near-zero TVL) are all independently corroborated by credible, mostly non-official sources and are presented without unhedged fraud language. The one factual defect found is a timeline omission/mischaracterization: the page's 'first' post-incident Sherlock audit (Feb 2023) was actually preceded by a November 2022 Sherlock contest and a November 2022 Zellic re-audit, both omitted — an error that, if anything, makes Bond Protocol's remediation look slower than it was, i.e. the record is more favorable to the entity than the page states. The larger caveat is structural: every section body in the review input was empty, so this review could only validate the summary and timeline, not the page's actual prose — that is a gap in the review process itself, not a finding about the page's accuracy.anchoranchored
- chain
- ●mainnet-betaslot 443,509,080
- sig
v5sApTCvGpw5…6RDEs9rjexplorer ↗- hash
A8wg9qKPndDm…gWUuYGgHsha256 → base58
verifying row…full verify ↗canonical bytes (1358 B) ▸
{"actor":"reviewer","decided_at":"2026-08-19T01:41:36.746Z","decision":"review","investigation_id":"d9137293-15db-46cf-b00d-94ca66903d90","new_score":42,"page_slug":"bond-protocol","prev_score":42,"reason":"The verifiable claims on this page (spin-out from OlympusDAO, the October 2022 Fixed-Expiry Teller exploit and its ~$300K/full-recovery outcome, the $2.5M seed round, post-incident re-auditing, and the current near-zero TVL) are all independently corroborated by credible, mostly non-official sources and are presented without unhedged fraud language. The one factual defect found is a timeline omission/mischaracterization: the page's 'first' post-incident Sherlock audit (Feb 2023) was actually preceded by a November 2022 Sherlock contest and a November 2022 Zellic re-audit, both omitted — an error that, if anything, makes Bond Protocol's remediation look slower than it was, i.e. the record is more favorable to the entity than the page states. The larger caveat is structural: every section body in the review input was empty, so this review could only validate the summary and timeline, not the page's actual prose — that is a gap in the review process itself, not a finding about the page's accuracy.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision fd9980ee-989c-473d-bb71-44bdac106235 - #3review approve with notesby judgejudge2026-08-19 01:41:36ZScore: 42 → 58 (+16)This is a calibration correction, not a content dispute: every material factual claim on the page is independently corroborated (claim_findings[0]-[6]) and disputed_pct is 0.18 with zero disputed findings, so the page's substance is not in question. The current score of 42 (WARNING) reflects treatment appropriate to own-fraud or negligence conduct, but the entity's only incident is a suffered smart-contract exploit (calibration_assessment.incident_attributions[0], attribution 'b') with same-day full fund recovery, a transparent public postmortem, and a substantive multi-audit remediation program — no own-fraud, exit-scam, or misappropriation finding exists anywhere in the review. Per the rubric's fraud-likelihood semantics, a 'suffered' incident with no fraud finding caps severity at CAUTIONARY (50-69); 58 places the entity in the lower-middle of that band, reflecting both the exculpatory recovery/remediation record and the residual concerns (bug missed by multiple prior audits, near-zero current TVL and thin team) that argue against a higher placement. Notes: (Add the November 2022 Sherlock audit contest (sherlock-audit/2022-11-bond-judging) to the timeline — the Feb 2023 contest was not the first post-incident audit, and the omission currently understates how quickly the team responded.) (Confirm the 'Bondly Finance Hack Explained (July 2021)' Halborn citation is clearly labeled as an unrelated, similarly-named project and not presented in a way a skimming reader could conflate with Bond Protocol.) (Verify the ZachXBT citations (zachxbt.mirror.xyz, paragraph.com/@investigations) are entity-specific reporting on Bond Protocol; if they are only general archive landing pages, remove them or label as general context.) (Add coverage of current operational thinness (third-party data showing headcount near 1) alongside the existing TVL-decline note.)anchoranchored
- chain
- ●mainnet-betaslot 443,509,084
- sig
4rftFobwsSYn…xZVpPWVzexplorer ↗- hash
yET9eijV36HK…afhzjTxnsha256 → base58
verifying row…full verify ↗canonical bytes (2243 B) ▸
{"actor":"judge","decided_at":"2026-08-19T01:41:36.746Z","decision":"review_approve_with_notes","investigation_id":"d9137293-15db-46cf-b00d-94ca66903d90","new_score":58,"page_slug":"bond-protocol","prev_score":42,"reason":"This is a calibration correction, not a content dispute: every material factual claim on the page is independently corroborated (claim_findings[0]-[6]) and disputed_pct is 0.18 with zero disputed findings, so the page's substance is not in question. The current score of 42 (WARNING) reflects treatment appropriate to own-fraud or negligence conduct, but the entity's only incident is a suffered smart-contract exploit (calibration_assessment.incident_attributions[0], attribution 'b') with same-day full fund recovery, a transparent public postmortem, and a substantive multi-audit remediation program — no own-fraud, exit-scam, or misappropriation finding exists anywhere in the review. Per the rubric's fraud-likelihood semantics, a 'suffered' incident with no fraud finding caps severity at CAUTIONARY (50-69); 58 places the entity in the lower-middle of that band, reflecting both the exculpatory recovery/remediation record and the residual concerns (bug missed by multiple prior audits, near-zero current TVL and thin team) that argue against a higher placement. Notes: (Add the November 2022 Sherlock audit contest (sherlock-audit/2022-11-bond-judging) to the timeline — the Feb 2023 contest was not the first post-incident audit, and the omission currently understates how quickly the team responded.) (Confirm the 'Bondly Finance Hack Explained (July 2021)' Halborn citation is clearly labeled as an unrelated, similarly-named project and not presented in a way a skimming reader could conflate with Bond Protocol.) (Verify the ZachXBT citations (zachxbt.mirror.xyz, paragraph.com/@investigations) are entity-specific reporting on Bond Protocol; if they are only general archive landing pages, remove them or label as general context.) (Add coverage of current operational thinness (third-party data showing headcount near 1) alongside the existing TVL-decline note.)","score_delta":16,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision edf0f82d-e87a-42ec-affc-5168e747dbae - #4reviewby reviewerreviewer2026-08-25 07:51:36ZScore: 62 → 62 (no score change)The page's central narrative — the October 2022 Fixed-Expiry Teller exploit, its white-hat resolution, the $2.5M seed round, and the three-firm audit history — is well corroborated by independent news, security-research, and auditor-published sources. The main issues found are a likely misattribution of the $3.3M Immunefi bug bounty to 'Bond Protocol' specifically (evidence points to it being OlympusDAO's own program), reliance on the protocol's own self-reported Q1 2023 metrics without independent corroboration, and an understated 'difficult to confirm' framing of current TVL/activity when a concrete current TVL figure was readily discoverable via the page's own cited source.anchoranchored
- chain
- ●mainnet-betaslot 443,512,596
- sig
61XAA3VxDtUk…Neyzzfsaexplorer ↗- hash
EVY478hnHeQ3…9zptUKsysha256 → base58
verifying row…full verify ↗canonical bytes (1034 B) ▸
{"actor":"reviewer","decided_at":"2026-08-25T07:51:35.864Z","decision":"review","investigation_id":"d9137293-15db-46cf-b00d-94ca66903d90","new_score":62,"page_slug":"bond-protocol","prev_score":62,"reason":"The page's central narrative — the October 2022 Fixed-Expiry Teller exploit, its white-hat resolution, the $2.5M seed round, and the three-firm audit history — is well corroborated by independent news, security-research, and auditor-published sources. The main issues found are a likely misattribution of the $3.3M Immunefi bug bounty to 'Bond Protocol' specifically (evidence points to it being OlympusDAO's own program), reliance on the protocol's own self-reported Q1 2023 metrics without independent corroboration, and an understated 'difficult to confirm' framing of current TVL/activity when a concrete current TVL figure was readily discoverable via the page's own cited source.","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision d631577b-c6ae-4cd6-8450-7b0e33e3c30a - #5review reviseby judgejudge2026-08-25 07:51:36ZScore: 62 → 54 (-8)Recomputing disputed_pct from the finding array as (disputed + unverifiable) / total_claims gives 3/29 = 10.34%, which places this page just inside the 10-30% revise band rather than the approve band the reviewer's rounded 0.10 figure suggests (claim_findings[11], [21], [22]). The one disputed claim is a moderate issue: the page attributes a $3.3M Immunefi bug bounty to Bond Protocol's own program, but independently consulted sources tie that bounty to OlympusDAO's program, and a Bond-Protocol-specific Immunefi URL 404s (claim_findings[11]). The two unverifiable items are comparatively minor - a vague, unnamed 'third-party database' claim and per-chain bonding counts sourced only to an unfetchable self-report (claim_findings[21], [22]). Weighing against these issues, the page's core narrative held up well: the October 2022 exploit mechanics, dollar figures, and white-hat return were corroborated across four independent sources, and the three-firm audit trail (yAcademy, Sherlock, Zellic) was verified against each auditor's own published repositories rather than taken on the protocol's word (claim_findings[13], [17]). A high-priority coverage gap - no on-chain transaction hashes cited for the exploit - further supports a revise rather than approve outcome, and reviewer confidence (0.72) is high enough that no additional softening is warranted.anchoranchored
- chain
- ●mainnet-betaslot 443,512,602
- sig
4sU82KZH2SUT…TAJAijdZexplorer ↗- hash
7t1H6hXiecx7…2XSqXkcDsha256 → base58
verifying row…full verify ↗canonical bytes (1717 B) ▸
{"actor":"judge","decided_at":"2026-08-25T07:51:35.864Z","decision":"review_revise","investigation_id":"d9137293-15db-46cf-b00d-94ca66903d90","new_score":54,"page_slug":"bond-protocol","prev_score":62,"reason":"Recomputing disputed_pct from the finding array as (disputed + unverifiable) / total_claims gives 3/29 = 10.34%, which places this page just inside the 10-30% revise band rather than the approve band the reviewer's rounded 0.10 figure suggests (claim_findings[11], [21], [22]). The one disputed claim is a moderate issue: the page attributes a $3.3M Immunefi bug bounty to Bond Protocol's own program, but independently consulted sources tie that bounty to OlympusDAO's program, and a Bond-Protocol-specific Immunefi URL 404s (claim_findings[11]). The two unverifiable items are comparatively minor - a vague, unnamed 'third-party database' claim and per-chain bonding counts sourced only to an unfetchable self-report (claim_findings[21], [22]). Weighing against these issues, the page's core narrative held up well: the October 2022 exploit mechanics, dollar figures, and white-hat return were corroborated across four independent sources, and the three-firm audit trail (yAcademy, Sherlock, Zellic) was verified against each auditor's own published repositories rather than taken on the protocol's word (claim_findings[13], [17]). A high-priority coverage gap - no on-chain transaction hashes cited for the exploit - further supports a revise rather than approve outcome, and reviewer confidence (0.72) is high enough that no additional softening is warranted.","score_delta":-8,"sequence_num":5,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 43886b0a-0a41-4a4f-a1ba-059f9b76ae4f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.