Skip to main content
AVOID.NET

Audit log

Every state-changing event for BridgeLink / CrossFlow / Relay Protocol — June 14 Cross-Chain Exploit ($127M): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1reviewby reviewerreviewer
    2026-08-26 08:03:04Z
    Score: 10 → 10 (no score change)
    The page is built almost entirely around a single Tier-3 vendor blog post (Nadcab Labs) describing a $127M cross-chain exploit across three named protocols, and the page itself already labels nearly every substantive fact as alleged/unverified. Independent research corroborates the page's core finding: no Tier 1/2 outlet, security firm, or on-chain database mentions this incident, and multiple comprehensive contemporaneous roundups of 2026 bridge/DeFi hacks — which do document smaller incidents — omit it entirely, with one aggregator's total for all of June 2026 crypto losses ($75.87M) being less than the $127M claimed for this single event. The background context in the final section (Kelp DAO, Verus-Ethereum, CrossCurve, Wormhole, Ronin) is accurate and well-corroborated, though the Cybernews '$300M' citation is presented as if describing a fourth, separate incident when it in fact describes the same Kelp DAO event already cited via Chainalysis. This review's evidence supports 'could not corroborate' rather than definitive proof the incident never happened, but the totality of absence across otherwise-thorough sources is substantial.
    anchoranchored
    chain
    ●mainnet-betaslot 443,519,683
    sig
    1aAmK3WT8FS7…NHeXZkLrexplorer ↗
    hash
    8TqCDixGcBCr…QriLEoUbsha256 → base58
    verifying row…full verify ↗
    canonical bytes (1557 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-26T08:03:04.343Z","decision":"review","investigation_id":"9ffcaedb-9f9b-46d6-a1c5-992c1f931865","new_score":10,"page_slug":"bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m","prev_score":10,"reason":"The page is built almost entirely around a single Tier-3 vendor blog post (Nadcab Labs) describing a $127M cross-chain exploit across three named protocols, and the page itself already labels nearly every substantive fact as alleged/unverified. Independent research corroborates the page's core finding: no Tier 1/2 outlet, security firm, or on-chain database mentions this incident, and multiple comprehensive contemporaneous roundups of 2026 bridge/DeFi hacks — which do document smaller incidents — omit it entirely, with one aggregator's total for all of June 2026 crypto losses ($75.87M) being less than the $127M claimed for this single event. The background context in the final section (Kelp DAO, Verus-Ethereum, CrossCurve, Wormhole, Ronin) is accurate and well-corroborated, though the Cybernews '$300M' citation is presented as if describing a fourth, separate incident when it in fact describes the same Kelp DAO event already cited via Chainalysis. This review's evidence supports 'could not corroborate' rather than definitive proof the incident never happened, but the totality of absence across otherwise-thorough sources is substantial.","score_delta":0,"sequence_num":1,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision bcb6ab34-7298-4fdd-833e-e9dbc50dbc45
  2. #2review reviseby judgejudge
    2026-08-26 08:03:04Z
    Score: 10 → 0 (-25)
    Of 23 claims checked, 13 were confirmed, 2 partially supported, 1 disputed, and 7 unverifiable, putting disputed-plus-unverifiable at 8/23 (34.8%), which falls in the band requiring revision and a status change rather than approval. The central allegation (claim_findings[0]) — a $127 million exploit across three named protocols — rests on one uncorroborated vendor blog that several comprehensive, contemporaneous industry roundups covering smaller incidents never mention, and one aggregator's total for all June 2026 crypto losses is smaller than this single claimed event. The same source contains an unresolved internal contradiction the page did not flag: it says protocol names are withheld pending forensic completion while naming them, and describes compromising 2 of 9 validator keys as meeting a 5-of-9 signing threshold (claim_findings[9]). Separately, the page mischaracterizes a Cybernews '$300 million' article as a distinct fourth incident when it describes the same Kelp DAO/LayerZero event already cited two sentences earlier via Chainalysis (claim_findings[19]). The page's consistent hedging of these facts as 'alleged' is credited and keeps this well short of denial-level fabrication, but it does not offset the volume of unresolved and contradicted material in a page that names real market makers alongside three protocols with no independently verifiable prior existence.
    anchoranchored
    chain
    ●mainnet-betaslot 443,519,686
    sig
    2KCW4TJFHJzA…25zY69v8explorer ↗
    hash
    GBjeFDdQLNS3…z3DBEevhsha256 → base58
    verifying row…full verify ↗
    canonical bytes (1806 B) ▸
    {"actor":"judge","decided_at":"2026-08-26T08:03:04.343Z","decision":"review_revise","investigation_id":"9ffcaedb-9f9b-46d6-a1c5-992c1f931865","new_score":0,"page_slug":"bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m","prev_score":10,"reason":"Of 23 claims checked, 13 were confirmed, 2 partially supported, 1 disputed, and 7 unverifiable, putting disputed-plus-unverifiable at 8/23 (34.8%), which falls in the band requiring revision and a status change rather than approval. The central allegation (claim_findings[0]) — a $127 million exploit across three named protocols — rests on one uncorroborated vendor blog that several comprehensive, contemporaneous industry roundups covering smaller incidents never mention, and one aggregator's total for all June 2026 crypto losses is smaller than this single claimed event. The same source contains an unresolved internal contradiction the page did not flag: it says protocol names are withheld pending forensic completion while naming them, and describes compromising 2 of 9 validator keys as meeting a 5-of-9 signing threshold (claim_findings[9]). Separately, the page mischaracterizes a Cybernews '$300 million' article as a distinct fourth incident when it describes the same Kelp DAO/LayerZero event already cited two sentences earlier via Chainalysis (claim_findings[19]). The page's consistent hedging of these facts as 'alleged' is credited and keeps this well short of denial-level fabrication, but it does not offset the volume of unresolved and contradicted material in a page that names real market makers alongside three protocols with no independently verifiable prior existence.","score_delta":-25,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 1d46bbce-98c9-48a9-9612-596def9b27d6
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.