← Compound Finance4 decisions on this page
Audit log
Every state-changing event for Compound Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-15 02:43:43ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 419,815,230
- sig
5JCSXpcXwhYt…QHCYyDrtexplorer ↗- hash
34yvDbmEPA3c…ABX7dR4Fsha256 → base58
verifying row…full verify ↗canonical bytes (20347 B) ▸
{"actor":"system:backfill","investigation_id":"3f4dd138-18e5-404a-a014-3a75ddc91a6d","kind":"publish","page_slug":"compound-finance","published_at":"2026-05-15T02:43:43.479Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Compound Finance","sections":[{"content":"Compound Finance is an algorithmic, autonomous interest-rate protocol built on Ethereum, originally launched on mainnet on September 27, 2018. It was founded by Robert Leshner and Geoffrey Hayes through Compound Labs, Inc. The protocol introduced the concept of cTokens — ERC-20 tokens minted to depositors representing their share of pooled liquidity. Compound v2 launched in May 2019, and the COMP governance token was deployed in March 2020, with community governance formally activated in June 2020. A third major version (Compound III / Comet) followed, adding multi-chain support across Base, Arbitrum, and others. As of 2025, Compound's total value locked (TVL) is estimated between $2 billion and $3.15 billion, placing it among the top DeFi lending protocols by assets. Robert Leshner stepped down as CEO of Compound Labs in 2023 and moved to a new project, Superstate. The protocol has undergone security audits from Trail of Bits, OpenZeppelin, and Certora.","heading":"Protocol Overview and History","severity":"low","sources":[{"credibility":3,"name":"What is Compound Finance? DeFi Lending Protocol Explained — OKX","type":"news","url":"https://www.okx.com/en-us/learn/compound-finance-defi-lending-platform"},{"credibility":3,"name":"Robert Leshner — IQ.wiki","type":"official","url":"https://iq.wiki/wiki/robert-leshner"},{"credibility":2,"name":"Compound Finance TVL — DeFiLlama","type":"onchain","url":"https://defillama.com/protocol/compound-finance"}]},{"content":"On September 30, 2021, a critical smart contract bug was introduced via Governance Proposal 62, which modified the COMP token distribution ratios for liquidity suppliers and borrowers. The bug consisted of a single character error: a greater-than operator (>) was used in place of a greater-than-or-equal-to operator (>=) in the Compound Comptroller contract. This caused supplyIndex to remain at 1e36 rather than being zeroed out when a market's index was up to date, resulting in massively inflated reward calculations. Anyone who had supplied assets in specific markets (cSUSHI, cMKR, cYFI, cAAVE, cTUSD, cSAI) was eligible to claim erroneous COMP rewards. The maximum exposure was estimated at 280,000 COMP tokens, worth approximately $90 million at the time of discovery. Compound Labs founder Robert Leshner posted publicly that recipients who failed to return the funds would be reported to the IRS, as most recipients were identified on-chain. By early October 2021, approximately 117,000 COMP (roughly $36 million) had been returned voluntarily. Governance Proposal 63 was passed to temporarily disable COMP distribution while a patch was developed, and a subsequent fix was executed on October 9, 2021. No user-supplied or borrowed funds were at risk; only the Comptroller's reserved COMP balance was affected. The Comptroller contract is at Ethereum address 0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b.","heading":"2021 COMP Token Distribution Bug (~$90 Million at Risk)","severity":"high","sources":[{"credibility":2,"name":"DeFi Money Market Compound Overpays Millions in COMP Rewards — CoinDesk","type":"news","url":"https://www.coindesk.com/tech/2021/09/30/defi-money-market-compound-overpays-15m-in-comp-rewards-in-possible-exploit"},{"credibility":1,"name":"DeFi bug accidentally gives $90 million to users, founder begs them to return it — CNBC","type":"news","url":"https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html"},{"credibility":2,"name":"One-character bug gives away $90m in COMP tokens — The Register","type":"news","url":"https://www.theregister.com/2021/10/01/compound_crypto_bug/"},{"credibility":1,"name":"Compound protocol DeFi bug accidentally sends $90 million to users — Fortune","type":"news","url":"https://fortune.com/2021/10/01/crypto-compound-defi-doxxed-irs/"},{"credibility":1,"name":"Compound: Comptroller contract — Etherscan","type":"onchain","url":"https://etherscan.io/address/0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b"}]},{"content":"On December 29, 2023, Compound Finance's official X (formerly Twitter) account was compromised and used to promote a phishing campaign. At approximately 4:57 pm UTC, the hijacked account posted an advertisement for 'free $COMP tokens,' linking to a site at compound-labs.xyz — a domain designed to mimic Compound's official interface. The linked site was identified as a Pink Drainer phishing platform, a known toolkit used to drain connected cryptocurrency wallets. On-chain investigator ZachXBT identified and shared two Ethereum transactions documenting the transfer of over 206,000 LINK tokens (approximately $3.2 million) and approximately 69,000 LINK (approximately $1 million) to wallet addresses associated with known phishing operations, for a combined estimated theft of more than $4.4 million in Chainlink tokens from affected users. The account was compromised for approximately four hours before Compound Labs recovered control and removed the fraudulent posts. Compound Labs confirmed the breach on December 30, 2023. ZachXBT noted that this incident may not represent the full scope of losses.","heading":"December 2023 X Account Compromise and $4.4 Million Phishing Theft","severity":"high","sources":[{"credibility":2,"name":"Compound Finance's X account hacked, promotes phishing site to steal crypto — CoinTelegraph","type":"news","url":"https://cointelegraph.com/news/compound-finance-x-twitter-account-hacked-posted-scam-link"},{"credibility":3,"name":"How a Phishing Attack Stole $4.4 Million from Compound Finance Users — Binance Square","type":"news","url":"https://www.binance.com/en/square/post/2044585130170"},{"credibility":3,"name":"Compound Finance suffers a breach of its X account — Cryptopolitan","type":"news","url":"https://www.cryptopolitan.com/compound-finance-breach-of-its-x-account/"}]},{"content":"On July 11, 2024, ZachXBT publicly warned via his Telegram channel that the compound.finance domain had been hijacked and was redirecting visitors to a newly registered phishing domain, compound-finance[.]app, which hosted a wallet drainer application. Compound Finance's security adviser Michael Lewellen confirmed the breach and urged all users to cease interacting with the website immediately. The attack was part of a broader wave of DNS hijacks affecting DeFi protocols whose domains had been migrated from Google Domains to Squarespace in 2023 as part of Google's asset sale. The migration process disabled multi-factor authentication on affected accounts, a condition that threat actors exploited to gain unauthorized control of DNS records. Other affected protocols in the same attack wave included Celer Network, Pendle Finance, and Unstoppable Domains. The Compound protocol's underlying smart contracts and user funds held on-chain were not directly at risk from this attack, but users who connected wallets to or entered credentials on the phishing site were exposed to complete fund loss. Squarespace had not publicly commented on the vulnerability as of initial reporting.","heading":"July 2024 Squarespace DNS Hijack (ZachXBT Alert)","severity":"critical","sources":[{"credibility":2,"name":"Compound Finance site potentially breached — ZachXBT via CoinTelegraph","type":"news","url":"https://cointelegraph.com/news/compound-finance-website-hijacked-security-warning"},{"credibility":1,"name":"Compound Finance, Celer Site Compromised in Phishing Attack — CoinDesk","type":"news","url":"https://www.coindesk.com/tech/2024/07/11/compound-finance-site-compromised-in-phishing-attack"},{"credibility":2,"name":"DNS hijacks target crypto platforms registered with Squarespace — BleepingComputer","type":"news","url":"https://www.bleepingcomputer.com/news/security/dns-hijacks-target-crypto-platforms-registered-with-squarespace/"},{"credibility":2,"name":"DeFi apps targeted in apparent Squarespace DNS registry attack — CoinTelegraph","type":"news","url":"https://cointelegraph.com/news/defi-apps-targeted-squarespace-dns-registry-attack-blockaid"},{"credibility":2,"name":"Compound Finance and Celer Network websites compromised in front-end attacks — Protos","type":"news","url":"https://protos.com/compound-finance-and-celer-network-websites-compromised-in-front-end-attacks/"},{"credibility":1,"name":"Researchers: Weak Security Defaults Enabled Squarespace Domain Hijacks — Krebs on Security","type":"news","url":"https://krebsonsecurity.com/2024/07/researchers-weak-security-defaults-enabled-squarespace-domains-hijacks/"}]},{"content":"In July 2024, Compound Finance's DAO governance process was the subject of an alleged governance attack orchestrated by a pseudonymous whale identified as 'Humpy,' leading a delegate coalition called the 'Golden Boys.' After two earlier failed attempts in May and July 2024, the group accumulated sufficient COMP voting power to pass Governance Proposal 289 on July 28, 2024. The proposal allocated 499,000 COMP tokens — approximately $24 million, or roughly 5% of the protocol's total treasury — to a yield-bearing protocol controlled by the Golden Boys, for a one-year term. The proposal passed by a margin of 682,191 to 633,636 votes. Community members and delegates, including Michael Lewellen of OpenZeppelin and members of Compound's broader delegate community, characterized the vote as a governance attack, arguing that a small group with accumulated token holdings had overridden the expressed preferences of the broader DAO. Humpy had allegedly engaged in similar governance maneuvers at Balancer and SushiSwap in prior periods. Following significant community backlash, the Golden Boys agreed to rescind Proposal 289 in exchange for the creation of a new COMP staking product that would distribute 30% of annual protocol token reserves proportionally to staked COMP holders. The incident highlighted structural vulnerabilities in token-weighted governance models where sufficiently capitalized actors can unilaterally direct treasury allocations.","heading":"July 2024 Alleged Governance Attack — Humpy / Golden Boys Proposal 289","severity":"high","sources":[{"credibility":2,"name":"$24 million Compound Finance proposal passed by whale over DAO objections — The Block","type":"news","url":"https://www.theblock.co/post/307943/24-million-compound-finance-proposal-passed-by-whale-over-dao-objections"},{"credibility":2,"name":"Compound Finance Proposal Passes Sparking Concerns Over Governance Attack — Decrypt","type":"news","url":"https://decrypt.co/242095/compound-finance-proposal-passes-concerns-over-governance-attack"},{"credibility":2,"name":"Compound Finance proposals elicit governance attack allegations — CoinTelegraph","type":"news","url":"https://cointelegraph.com/news/compound-finance-proposals-elicit-governance-attack-allegations-dao"},{"credibility":2,"name":"Compound reaches truce with crypto whale Humpy after controversial vote — The Block","type":"news","url":"https://www.theblock.co/post/308215/compound-reaches-truce-with-crypto-whale-humpy-after-controversial-vote-to-move-24-million-in-tokens"},{"credibility":1,"name":"COMP Token Rises as Whale Backs Down on Supposed Governance Attack — CoinDesk","type":"news","url":"https://www.coindesk.com/business/2024/07/30/comp-token-rises-as-whale-backs-down-on-supposed-governance-attack-on-compound"},{"credibility":2,"name":"Compound Governance Attack Reveals Inherent Vulnerabilities Of DAOs — The Defiant","type":"news","url":"https://thedefiant.io/news/defi/compound-governance-attack-reveals-inherent-vulnerabilities-of-daos"},{"credibility":2,"name":"DAO Delegate Group Accused of Governance Attack on Compound Finance — Unchained","type":"news","url":"https://unchainedcrypto.com/humpy-accused-of-governance-attack-on-compound-finance-dao/"}]},{"content":"Key verified Ethereum contract addresses associated with Compound Finance include the COMP governance token at 0xc00e94Cb662C3520282E6f5717214004A7f26888 (Etherscan verified), the Compound Comptroller (risk management) contract at 0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b (Etherscan verified), and the Compound Ether (cETH) token at 0x4ddc2d193948926d02f9b1fe9e1daa0718270ed5. The 2021 COMP distribution bug was specifically located in the Comptroller contract logic. These contracts remain active and have processed hundreds of thousands of transactions. Compound's protocol code is open source and available at the compound-finance/compound-protocol GitHub repository.","heading":"On-Chain Contract Addresses","severity":"low","sources":[{"credibility":1,"name":"COMP Token Contract — Etherscan","type":"onchain","url":"https://etherscan.io/token/0xc00e94cb662c3520282e6f5717214004a7f26888"},{"credibility":1,"name":"Compound Comptroller Contract — Etherscan","type":"onchain","url":"https://etherscan.io/address/0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b"},{"credibility":1,"name":"Compound Ether (cETH) Token — Etherscan","type":"onchain","url":"https://etherscan.io/token/0x4ddc2d193948926d02f9b1fe9e1daa0718270ed5"}]},{"content":"As of the research date, no direct enforcement action by the U.S. Securities and Exchange Commission (SEC), Commodity Futures Trading Commission (CFTC), or Department of Justice (DOJ) specifically targeting Compound Finance or Compound Labs has been identified in public records. Compound Finance operates as a decentralized autonomous protocol with governance performed by COMP token holders, which places it in a regulatory gray area typical of DeFi lending platforms. The broader DeFi sector remains subject to evolving regulatory scrutiny in the United States, though the 2024-2025 period has seen several SEC enforcement actions against crypto businesses withdrawn or closed. No specific Compound Finance regulatory filing or enforcement docket was identified in this investigation.","heading":"Regulatory Standing","severity":"low","sources":[{"credibility":3,"name":"DeFi Regulatory Compliance 2025 — Calibraint","type":"news","url":"https://www.calibraint.com/blog/defi-regulatory-compliance-sec-cftc-2025"}]},{"content":"Compound Finance has experienced at least three distinct front-end or operational security failures across a roughly two-year window: the December 2023 X account compromise (resulting in alleged theft of $4.4 million in LINK tokens via Pink Drainer), the July 2024 Squarespace DNS hijack (redirecting compound.finance to a wallet drainer), and historical reports of domain-level phishing infrastructure mimicking Compound's interface. In each case, the underlying smart contracts were not exploited, but users interacting with compromised interfaces faced material financial risk. The pattern suggests that Compound's operational security posture around web infrastructure, social media accounts, and domain registrar practices has been a persistent weak point. ZachXBT's role in publicly alerting the community to the July 2024 DNS hijack was credited with enabling rapid user response before larger-scale losses occurred.","heading":"Pattern of Front-End and Operational Security Failures","severity":"high","sources":[{"credibility":2,"name":"Compound Finance Website Appears Hijacked, ZachXBT Warns — CryptoNews","type":"news","url":"https://cryptonews.com/news/compound-finance-website-appears-hijacked-zachxbt-warns/"},{"credibility":2,"name":"Compound Finance confirms hack, warns users of phishing from website — Crypto Briefing","type":"news","url":"https://cryptobriefing.com/compound-finance-phishing-hack-alert/"},{"credibility":3,"name":"Security Breach: Compound Finance Website Compromised in Phishing Scam — Crypto Daily","type":"news","url":"https://cryptodaily.co.uk/2024/07/security-breach-compound-finance-website-compromised-in-phishing-scam"},{"credibility":2,"name":"ZachXBT Warns Compound Finance Users of Possible Hack on Website — TechReport","type":"news","url":"https://techreport.com/crypto-news/zachxbt-warns-compound-finance-users-of-possible-hack-on-website/"}]}],"sources_used":[],"summary":"Compound Finance is one of the earliest and largest decentralized lending protocols on Ethereum, founded in 2018 by Robert Leshner and Geoffrey Hayes. The protocol has accumulated a documented history of security incidents including a $90 million token distribution bug in 2021, a phishing attack via its compromised X account in December 2023, a Squarespace DNS hijack in July 2024 flagged by ZachXBT, and an alleged governance attack in July 2024 in which a whale actor narrowly passed a $24 million treasury allocation proposal over community objections. The underlying smart contracts have never been directly exploited, but repeated front-end and governance-layer incidents represent a sustained pattern of institutional fragility.","timeline":[{"date":"2018-09","event":"Compound Finance launches on Ethereum mainnet, founded by Robert Leshner and Geoffrey Hayes.","source":"OKX Learn","source_url":"https://www.okx.com/en-us/learn/compound-finance-defi-lending-platform"},{"date":"2019-05","event":"Compound v2 launches with support for additional assets and updated interest rate models.","source":"OKX Learn","source_url":"https://www.okx.com/en-us/learn/compound-finance-defi-lending-platform"},{"date":"2020-03","event":"COMP governance token deployed on Ethereum (contract: 0xc00e94Cb662C3520282E6f5717214004A7f26888).","source":"Etherscan","source_url":"https://etherscan.io/token/0xc00e94cb662c3520282e6f5717214004a7f26888"},{"date":"2020-06","event":"Community governance formally activated; Compound Labs transfers protocol control to COMP token holders.","source":"IQ.wiki — Robert Leshner","source_url":"https://iq.wiki/wiki/robert-leshner"},{"date":"2021-09","event":"Governance Proposal 62 activates, introducing a single-character (> vs >=) bug in the Comptroller contract, erroneously distributing up to $90 million in COMP to certain depositors.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2021/09/30/defi-money-market-compound-overpays-15m-in-comp-rewards-in-possible-exploit"},{"date":"2021-10","event":"Proposal 63 disables COMP distributions as emergency measure. Robert Leshner publicly threatens to report non-returners to the IRS. Approximately $36 million in COMP returned voluntarily. Fix deployed October 9.","source":"CNBC / The Register","source_url":"https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html"},{"date":"2023-12","event":"Compound Finance's X (Twitter) account is compromised for approximately four hours. A Pink Drainer phishing site linked from the account allegedly steals over $4.4 million in LINK tokens from users, as documented by ZachXBT.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/compound-finance-x-twitter-account-hacked-posted-scam-link"},{"date":"2024-07","event":"ZachXBT alerts that compound.finance has been hijacked via Squarespace DNS compromise, redirecting to phishing site compound-finance[.]app. Part of a broader attack on DeFi protocols migrated from Google Domains to Squarespace. Compound security adviser confirms breach and advises users to stop interacting with site.","source":"CoinDesk / BleepingComputer","source_url":"https://www.coindesk.com/tech/2024/07/11/compound-finance-site-compromised-in-phishing-attack"},{"date":"2024-07","event":"Governance Proposal 289, pushed by whale 'Humpy' and the Golden Boys coalition, passes 682,191 to 633,636 to allocate 499,000 COMP (~$24 million) to a Golden Boys-controlled protocol. Community and delegates allege governance attack.","source":"The Block / CoinDesk","source_url":"https://www.theblock.co/post/307943/24-million-compound-finance-proposal-passed-by-whale-over-dao-objections"},{"date":"2024-07","event":"Golden Boys agree to rescind Proposal 289 following community backlash, in exchange for creation of a COMP staking product distributing 30% of annual reserves to stakers.","source":"The Block / Unchained","source_url":"https://www.theblock.co/post/308215/compound-reaches-truce-with-crypto-whale-humpy-after-controversial-vote-to-move-24-million-in-tokens"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision d9723b55-271f-4602-bd47-e6f7eae79379 - #2reviewby reviewerreviewer2026-06-09 02:24:24ZScore: 72 → 72 (no score change)The Compound Finance investigation page is largely well-sourced and factually accurate across its major claims. The core incidents — the 2021 COMP distribution bug, the December 2023 X account hack, the July 2024 Squarespace DNS hijack, and the Humpy/Golden Boys governance attack — are all confirmed by multiple credible sources. The primary factual weakness is the TVL figure ($2-3.15B) which is materially overstated relative to current DeFiLlama data (~$1.4B as of early 2026). The Inferno Drainer victim count ($180M/189,000 victims) is partially supported but draws from a data point that conflicts with some primary security firm reports. Three claims were unverifiable due to dependence on secondary research-level on-chain analysis that could not be confirmed via direct primary sources.anchoranchored
- chain
- ●mainnet-betaslot 425,236,707
- sig
22eEdmFGW19t…cKgksMZPexplorer ↗- hash
3iciuVvnY8QH…hp7gK6Pesha256 → base58
verifying row…full verify ↗canonical bytes (1148 B) ▸
{"actor":"reviewer","decided_at":"2026-06-09T02:24:24.727Z","decision":"review","investigation_id":"3f4dd138-18e5-404a-a014-3a75ddc91a6d","new_score":72,"page_slug":"compound-finance","prev_score":72,"reason":"The Compound Finance investigation page is largely well-sourced and factually accurate across its major claims. The core incidents — the 2021 COMP distribution bug, the December 2023 X account hack, the July 2024 Squarespace DNS hijack, and the Humpy/Golden Boys governance attack — are all confirmed by multiple credible sources. The primary factual weakness is the TVL figure ($2-3.15B) which is materially overstated relative to current DeFiLlama data (~$1.4B as of early 2026). The Inferno Drainer victim count ($180M/189,000 victims) is partially supported but draws from a data point that conflicts with some primary security firm reports. Three claims were unverifiable due to dependence on secondary research-level on-chain analysis that could not be confirmed via direct primary sources.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 99a81193-680d-4b5a-9a6a-3b0c34b3a6b3 - #3review reviseby judgejudge2026-06-09 02:24:25ZScore: 72 → 62 (-10)The review confirmed 27 of 35 claims via credible sources, with all four major incidents (2021 COMP distribution bug, December 2023 X account compromise, July 2024 DNS hijack, and the Humpy/Golden Boys governance attack) verified by multiple Tier-1 outlets. The page requires revision primarily because claim_findings[8] — the stated TVL range of $2–3.15 billion — is directly contradicted by the page's own cited source, DeFiLlama, which shows approximately $1.4 billion as of early 2026, a material overstatement. Three additional claims are partially supported with minor discrepancies (a one-day date error in claim_findings[11], a conflicting Inferno Drainer victim count in claim_findings[28], and an uncertain veBAL percentage in claim_findings[32]), and three on-chain analytics claims are unverifiable from primary sources. No link rot or high-priority coverage gaps were identified. The page is fundamentally sound and does not warrant denial or investigation status, but the TVL figure must be corrected before the page accurately reflects current protocol standing.anchoranchored
- chain
- ●mainnet-betaslot 425,236,710
- sig
3CK9orJwx4sW…56ASRFXQexplorer ↗- hash
6y3kSWBMP7RB…5ZQ4V6BTsha256 → base58
verifying row…full verify ↗canonical bytes (1435 B) ▸
{"actor":"judge","decided_at":"2026-06-09T02:24:24.727Z","decision":"review_revise","investigation_id":"3f4dd138-18e5-404a-a014-3a75ddc91a6d","new_score":62,"page_slug":"compound-finance","prev_score":72,"reason":"The review confirmed 27 of 35 claims via credible sources, with all four major incidents (2021 COMP distribution bug, December 2023 X account compromise, July 2024 DNS hijack, and the Humpy/Golden Boys governance attack) verified by multiple Tier-1 outlets. The page requires revision primarily because claim_findings[8] — the stated TVL range of $2–3.15 billion — is directly contradicted by the page's own cited source, DeFiLlama, which shows approximately $1.4 billion as of early 2026, a material overstatement. Three additional claims are partially supported with minor discrepancies (a one-day date error in claim_findings[11], a conflicting Inferno Drainer victim count in claim_findings[28], and an uncertain veBAL percentage in claim_findings[32]), and three on-chain analytics claims are unverifiable from primary sources. No link rot or high-priority coverage gaps were identified. The page is fundamentally sound and does not warrant denial or investigation status, but the TVL figure must be corrected before the page accurately reflects current protocol standing.","score_delta":-10,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 54dbb958-7a67-497f-a573-545f1fcb8b3f - #4reviewby reviewerreviewer2026-09-09 03:05:04ZScore: 55 → 55 (no score change)Findings-only fact-check (retroactive anchor of stored findings)anchoranchored
- chain
- ●mainnet-betaslot 445,505,658
- sig
3M5iu5ee5EdU…GXrAdWrHexplorer ↗- hash
FsxarntS3ffM…MoDEMpWksha256 → base58
verifying row…full verify ↗canonical bytes (709 B) ▸
{"actor":"reviewer","artifact_identity":"4f0baf8858cab0ceb789dde3dd06b32f","decided_at":"2026-09-07T10:52:37.865797+00:00","decision":"review","findings_count":35,"findings_rows_hash":"080ab90175f8fa2588ca53d57ea138edbb5082acd38532963e878a4e26b0cdc2","investigation_id":"3f4dd138-18e5-404a-a014-3a75ddc91a6d","mode":"findings_only_retroactive","new_score":55,"page_content_hash":"0a09fd578148f2e6ceeab2c9e7531a8505f7eeb92d411396448ce9d2a32eba6c","page_slug":"compound-finance","prev_score":55,"reason":"Findings-only fact-check (retroactive anchor of stored findings)","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 6745902f-73c4-422d-870e-3d3ba09128d7
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.