Skip to main content
AVOID.NET

Audit log

Every state-changing event for IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-01 17:18:23Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 443,503,417
    sig
    2iiAiB1T6UR6…ZGQ9ZNVVexplorer ↗
    hash
    BG9LrTKhTQVn…QQnTwdtSsha256 → base58
    verifying row…full verify ↗
    canonical bytes (16951 B) ▸
    {"actor":"system:backfill","investigation_id":"ce124313-4762-44fc-8303-caef158070b8","kind":"publish","page_slug":"irs-fake-digital-asset-compliance-portal-phishing-campaign-2026","published_at":"2026-08-01T17:18:23.510Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026","sections":[{"content":"Beginning in late July 2026, U.S. cryptocurrency holders began receiving physical letters purporting to be official IRS correspondence. The letters referenced tax years 2017 through 2026, claimed recipients were required to enroll in a 'Digital Asset Compliance Portal' (DACP) before an August 10, 2026 deadline, and included a QR code directing recipients to the fraudulent domain 'irs.digitalcomplianceportal.com'. The campaign was identified by Coinbase and threat intelligence firm DarkTower, who issued a consumer alert on July 28, 2026. IRS Criminal Investigation formally warned the public on July 30, 2026. IRS-CI Chief Jarod Koopman stated: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.' The IRS confirmed it operates no Digital Asset Compliance Portal and does not request digital asset transfers or sensitive credentials through mailed notices.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":2,"name":"IRS warns crypto holders fraudster sending fake letters in attempt to steal digital assets or data — The Block","type":"news_article","url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders with fake compliance portal — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"}]},{"content":"The campaign used physical mail — an uncommon vector in cryptocurrency fraud — to bypass email spam filters and exploit the familiarity of crypto holders with genuine IRS digital asset letters the agency has sent since 2019. Letters arrived in plain envelopes formatted to mimic official IRS correspondence. Upon scanning the embedded QR code, recipients were taken to a convincing spoofed IRS enrollment page. The phishing site prompted victims to select which platform held their crypto assets — listing major exchanges including Coinbase, Kraken, and Binance — reportedly to identify which platform to subsequently impersonate. The site then requested personal identification details, cryptocurrency wallet information, recovery phrases, exchange account credentials, and phone numbers. According to Coinbase's consumer alert, after initial data entry a scammer posing as 'support' would attempt vishing (voice phishing) contact to further manipulate victims into transferring assets or surrendering account access. The IRS confirmed that legitimate IRS letters do not contain QR codes.","heading":"Attack Methodology","severity":"critical","sources":[{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders with fake compliance portal — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"Did You Get an IRS Crypto Compliance Letter? It Probably Isn't Real — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/did-irs-crypto-compliance-letter-082951104.html"},{"credibility":2,"name":"IRS Warns Crypto Holders About Fake Tax Letter Scam — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/irs-warns-crypto-holders-about-fake-tax-letter-scam/"}]},{"content":"The fraudulent domain 'irs.digitalcomplianceportal.com' was registered through a Hong Kong-based domain registrar only days before the physical letters were distributed. The website was hosted on servers in Romania that were already known to security researchers for hosting phishing pages impersonating FedEx and financial institutions. Reporting by The Star (citing Bloomberg) characterized the operation as a 'professional, international fraud operation' based on the rapid infrastructure setup and prior track record of the hosting network. The identity of the operators has not been publicly confirmed. No arrests or indictments directly related to this campaign had been announced as of August 1, 2026.","heading":"Technical Infrastructure","severity":"high","sources":[{"credibility":2,"name":"Scam artists are posing as IRS agents to drain crypto wallets — The Star (citing Bloomberg)","type":"news_article","url":"https://www.thestar.com.my/tech/tech-news/2026/07/31/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"Crypto Scam Surge: Fraudsters Use Fake IRS Letters to Steal Investor Information — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/crypto-scam-surge-fraudsters-use-fake-irs-letters-to-steal-investor-information/"},{"credibility":2,"name":"IRS Warns 'Digital Asset Compliance Portal' Is A Scam Targeting Crypto Taxpayers — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/irs-warns-digital-asset-compliance-portal-scam/"}]},{"content":"IRS Criminal Investigation issued a public alert on July 30, 2026, warning U.S. taxpayers of the campaign. IRS-CI Chief Jarod Koopman confirmed the agency operates no Digital Asset Compliance Portal and does not request personal or financial information via mailed QR codes. The IRS directed recipients of suspicious letters to verify correspondence through IRS.gov and report incidents via www.IRS.gov/SubmitATip. The Accounting Today report of the same date reproduced key IRS-CI guidance: cease communication with the sender, change any compromised passwords, contact financial institutions, preserve evidence, and report to IRS-CI. Coinbase published a consumer warning on July 28, 2026, crediting DarkTower as the threat intelligence source that identified the campaign. As of August 1, 2026, the IRS had not disclosed the volume of letters distributed nor any confirmed financial losses attributable to the campaign.","heading":"Official Warnings and Regulatory Response","severity":"high","sources":[{"credibility":1,"name":"IRS-CI issues alert about potential cryptocurrency phishing scam — IRS.gov","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/irs-ci-issues-alert-about-potential-cryptocurrency-phishing-scam"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]},{"content":"The DACP campaign emerged against a documented backdrop of escalating crypto-related fraud. According to the FBI Internet Crime Complaint Center (IC3), Americans lost over $11 billion to crypto-related scams in 2025, a reported 22% increase year-over-year, with an average loss of $62,604 per victim and over 18,000 cases exceeding $100,000 in losses. Chainalysis data cited in reporting noted impersonation scams surged 1,400% in 2025, with total scam losses reaching $17 billion that year. TRM Labs recorded more than 207 hacks in the first half of 2026 — more than double the prior-year period — suggesting a broader industry shift from technical protocol exploits toward social engineering targeting individual holders. The DACP campaign exploited a specific credibility vector: since 2019, the IRS has legitimately mailed educational letters to taxpayers regarding unreported digital assets, creating a population of recipients already conditioned to expect IRS correspondence about crypto. In parallel, the FBI's IC3 warned in July 2026 of criminals impersonating IC3 itself using AI-generated videos and spoofed websites to re-victimize prior fraud victims.","heading":"Broader Context: Crypto Impersonation Scam Trends","severity":"medium","sources":[{"credibility":2,"name":"Scam artists are posing as IRS agents to drain crypto wallets — The Star","type":"news_article","url":"https://www.thestar.com.my/tech/tech-news/2026/07/31/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"Crypto Scam Surge: Fraudsters Use Fake IRS Letters to Steal Investor Information — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/crypto-scam-surge-fraudsters-use-fake-irs-letters-to-steal-investor-information/"},{"credibility":2,"name":"IRS Fake Crypto Tax Letters: How to Spot the Scam — Crypto Daily","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/irs-fake-crypto-tax-letters-scam"}]},{"content":"IRS-CI and security researchers identified the following indicators of the fraudulent letters: (1) letters arriving in plain unmarked envelopes rather than official IRS envelopes; (2) inclusion of a QR code — the IRS states it does not include QR codes in official correspondence; (3) references to an 'August 10' enrollment deadline creating artificial urgency; (4) direction to a domain other than IRS.gov; (5) requests for cryptocurrency wallet credentials, recovery phrases, or exchange login details. Recommended protective actions include: do not scan the QR code; do not call any phone numbers listed in the letter; do not enter any personal or financial information on linked websites; verify unexpected IRS correspondence directly at IRS.gov; report the letter to IRS-CI at www.IRS.gov/SubmitATip; and file a complaint with the FBI IC3 at IC3.gov, including any wallet addresses, domains, or phone numbers found in the letter.","heading":"Identification and Protection Guidance","severity":"medium","sources":[{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders with fake compliance portal — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"}]}],"sources_used":[{"credibility":1,"name":"IRS-CI issues alert about potential cryptocurrency phishing scam — IRS.gov","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/irs-ci-issues-alert-about-potential-cryptocurrency-phishing-scam"},{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"IRS warns crypto holders fraudster sending fake letters in attempt to steal digital assets or data — The Block","type":"news_article","url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders with fake compliance portal — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"IRS Warns Crypto Holders About Fake Tax Letter Scam — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/irs-warns-crypto-holders-about-fake-tax-letter-scam/"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":1,"name":"IRS Warns Crypto Users of Fake Letters in Data-Stealing Scam — Bloomberg Tax","type":"news_article","url":"https://news.bloombergtax.com/daily-tax-report/irs-warns-crypto-users-of-fake-letters-in-data-stealing-scam"},{"credibility":2,"name":"Did You Get an IRS Crypto Compliance Letter? It Probably Isn't Real — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/did-irs-crypto-compliance-letter-082951104.html"},{"credibility":2,"name":"IRS Warns 'Digital Asset Compliance Portal' Is A Scam Targeting Crypto Taxpayers — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/irs-warns-digital-asset-compliance-portal-scam/"},{"credibility":2,"name":"Scam artists are posing as IRS agents to drain crypto wallets — The Star","type":"news_article","url":"https://www.thestar.com.my/tech/tech-news/2026/07/31/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"Crypto Scam Surge: Fraudsters Use Fake IRS Letters to Steal Investor Information — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/crypto-scam-surge-fraudsters-use-fake-irs-letters-to-steal-investor-information/"},{"credibility":2,"name":"IRS Fake Crypto Tax Letters: How to Spot the Scam — Crypto Daily","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/irs-fake-crypto-tax-letters-scam"},{"credibility":3,"name":"Coinbase Support warning on X — @CoinbaseSupport","type":"social_media","url":"https://x.com/CoinbaseSupport/status/2082145747277881537"}],"summary":"In late July 2026, an unidentified threat actor mailed counterfeit IRS letters to U.S. cryptocurrency holders directing them to a fictitious 'Digital Asset Compliance Portal' (DACP) at a lookalike domain. IRS Criminal Investigation (IRS-CI) issued a public warning on July 30, 2026, confirming no such portal exists and that the campaign was designed to harvest personal information, exchange credentials, and digital asset holdings. The phishing infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior history of financial phishing activity.","timeline":[{"date":"2026-07-28","event":"Coinbase and threat intelligence firm DarkTower issued a consumer alert identifying the fake DACP letter campaign.","source":"Coinbase Blog","source_url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"date":"2026-07-30","event":"IRS Criminal Investigation (IRS-CI) issued a formal public warning confirming the campaign. IRS-CI Chief Jarod Koopman stated criminals were creating convincing fake websites and official-looking correspondence. The IRS confirmed it operates no Digital Asset Compliance Portal.","source":"Bloomberg / Accounting Today","source_url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"date":"2026-07-31","event":"Multiple crypto and mainstream news outlets including The Block, Crypto Briefing, Crypto Times, and Gate News published coverage of the IRS warning. Coinbase Support posted a public advisory on X (Twitter).","source":"The Block","source_url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"},{"date":"2026-08-01","event":"As of this date, no confirmed victim counts, financial losses, arrests, or indictments related to the DACP campaign had been publicly disclosed. The August 10 enrollment deadline cited in the fraudulent letters had not yet passed.","source":"IRS / Multiple outlets","source_url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 81370692-d14b-406f-9e64-0ff33907b532
  2. #2reviewby reviewerreviewer
    2026-08-25 22:58:25Z
    Score: 00 (no score change)
    The page's core factual claims about the DACP phishing campaign — letter methodology, indicators, dates, Hong Kong/Romania infrastructure, official response, and the industry-scale statistics it cites — are well corroborated by independent reporting and by the IRS's own current fraud alert page. The IRS is consistently and unambiguously framed as the impersonated party rather than an actor, and the reader-facing safety guidance is accurate and non-inverted throughout. Two issues were found: the page's primary IRS.gov regulatory citation resolves to an unrelated 2022 alert rather than the 2026 campaign it is cited to support (the correct IRS.gov page exists at a different URL and does corroborate the claims), and a TRM Labs hack-count statistic is stretched to support an inference about an industry-wide shift toward social engineering that the underlying data does not itself demonstrate.
    anchoranchored
    chain
    mainnet-betaslot 443,518,306
    sig
    33ig9xjoD2H4…UKPNTiU6explorer ↗
    hash
    4x8FPz3VM1gF…GWoDpRh1sha256 → base58
    verifying row…full verify ↗
    canonical bytes (1296 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-25T22:58:25.205Z","decision":"review","investigation_id":"ce124313-4762-44fc-8303-caef158070b8","new_score":0,"page_slug":"irs-fake-digital-asset-compliance-portal-phishing-campaign-2026","prev_score":0,"reason":"The page's core factual claims about the DACP phishing campaign — letter methodology, indicators, dates, Hong Kong/Romania infrastructure, official response, and the industry-scale statistics it cites — are well corroborated by independent reporting and by the IRS's own current fraud alert page. The IRS is consistently and unambiguously framed as the impersonated party rather than an actor, and the reader-facing safety guidance is accurate and non-inverted throughout. Two issues were found: the page's primary IRS.gov regulatory citation resolves to an unrelated 2022 alert rather than the 2026 campaign it is cited to support (the correct IRS.gov page exists at a different URL and does corroborate the claims), and a TRM Labs hack-count statistic is stretched to support an inference about an industry-wide shift toward social engineering that the underlying data does not itself demonstrate.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision cfaab078-bbc3-42e1-9854-e42171aa5d15
  3. #3review approveby judgejudge
    2026-08-25 22:58:25Z
    Score: 00 (-4)
    Of 30 checked claims, 27 were confirmed outright, 0 were disputed, and 0 were unverifiable, so disputed_pct is 0.0% by the reviewer's own formula (disputed + unverifiable / total) — squarely in the approve band, and reviewer confidence (0.85) is high enough not to soften that further. The page's central claims (the fake letters, the fraudulent portal, the IRS's official denial, the infrastructure details, the statistics, and the safety guidance) are corroborated by independent reporting and by the IRS's own current alert page, and the reviewer explicitly confirms the IRS is consistently framed as the victim/impersonated party with no inverted safety advice (the single most consequential thing to get right on a phishing writeup). Two sub-threshold issues keep this from a clean pass, both correctly excluded from the numerator as 'partially_supported' rather than disputed: claim_findings[14] misattributes a 'professional, international fraud operation' characterization to the outlet's own editorial judgment when it was actually a reproduced quote from Coinbase, and claim_findings[22] uses an accurate TRM Labs hack-count statistic to support an inference (a shift toward social engineering) that the same TRM Labs dataset does not bear out, since smart-contract exploits remained the majority category. Separately, claim_findings[18] is a real citation-integrity defect, not merely a dead link: the page's primary IRS.gov regulatory citation resolves to a genuine but unrelated 2022 IRS-CI alert about a different scam, and the source's own recorded archive timestamp (2026-02-09) predates the July 2026 campaign it is cited to document, meaning the citation could never have supported the claim as published. The correct IRS.gov alert exists at a different URL and does support the page's substance, so no factual claim is actually wrong — but a reader clicking through would land on a real government page describing something else entirely and might not notice the mismatch. This is a mismatched citation, not link rot in the ordinary sense, and it sits on the page's single most load-bearing government source. The disputed_pct formula has no mechanism to weight that distinction — it treats this identically to a citation going 404 — so I am applying a modest downward adjustment within the approve band to reflect it, rather than either ignoring it or manufacturing a verdict change the data doesn't support. No coverage gap was flagged high priority, so gaps do not independently justify escalation.
    anchoranchored
    chain
    mainnet-betaslot 443,518,309
    sig
    rtYK1mJviamh…q8WbA69Mexplorer ↗
    hash
    H7fkYve4ZpPQ…TW1eXFg1sha256 → base58
    verifying row…full verify ↗
    canonical bytes (2923 B) ▸
    {"actor":"judge","decided_at":"2026-08-25T22:58:25.205Z","decision":"review_approve","investigation_id":"ce124313-4762-44fc-8303-caef158070b8","new_score":0,"page_slug":"irs-fake-digital-asset-compliance-portal-phishing-campaign-2026","prev_score":0,"reason":"Of 30 checked claims, 27 were confirmed outright, 0 were disputed, and 0 were unverifiable, so disputed_pct is 0.0% by the reviewer's own formula (disputed + unverifiable / total) — squarely in the approve band, and reviewer confidence (0.85) is high enough not to soften that further. The page's central claims (the fake letters, the fraudulent portal, the IRS's official denial, the infrastructure details, the statistics, and the safety guidance) are corroborated by independent reporting and by the IRS's own current alert page, and the reviewer explicitly confirms the IRS is consistently framed as the victim/impersonated party with no inverted safety advice (the single most consequential thing to get right on a phishing writeup). Two sub-threshold issues keep this from a clean pass, both correctly excluded from the numerator as 'partially_supported' rather than disputed: claim_findings[14] misattributes a 'professional, international fraud operation' characterization to the outlet's own editorial judgment when it was actually a reproduced quote from Coinbase, and claim_findings[22] uses an accurate TRM Labs hack-count statistic to support an inference (a shift toward social engineering) that the same TRM Labs dataset does not bear out, since smart-contract exploits remained the majority category. Separately, claim_findings[18] is a real citation-integrity defect, not merely a dead link: the page's primary IRS.gov regulatory citation resolves to a genuine but unrelated 2022 IRS-CI alert about a different scam, and the source's own recorded archive timestamp (2026-02-09) predates the July 2026 campaign it is cited to document, meaning the citation could never have supported the claim as published. The correct IRS.gov alert exists at a different URL and does support the page's substance, so no factual claim is actually wrong — but a reader clicking through would land on a real government page describing something else entirely and might not notice the mismatch. This is a mismatched citation, not link rot in the ordinary sense, and it sits on the page's single most load-bearing government source. The disputed_pct formula has no mechanism to weight that distinction — it treats this identically to a citation going 404 — so I am applying a modest downward adjustment within the approve band to reflect it, rather than either ignoring it or manufacturing a verdict change the data doesn't support. No coverage gap was flagged high priority, so gaps do not independently justify escalation.","score_delta":-4,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision f727e5c7-13b8-4731-a73c-da5e8df939c1
  4. #4reviewby reviewerreviewer
    2026-09-09 03:05:36Z
    Score: 00 (no score change)
    Findings-only fact-check (retroactive anchor of stored findings)
    anchoranchored
    chain
    mainnet-betaslot 445,508,877
    sig
    3YAFrjynfpYB…w7hKoXEGexplorer ↗
    hash
    FccbwQEbG9Uj…yb1WhMm2sha256 → base58
    verifying row…full verify ↗
    canonical bytes (754 B) ▸
    {"actor":"reviewer","artifact_identity":"fc620d1ab137f9eac03dc19e39421bd4","decided_at":"2026-09-07T15:27:58.759813+00:00","decision":"review","findings_count":31,"findings_rows_hash":"463414b1453f3f22dff0af2596a955848ce0d01d5ee60a5d382bbff92d799ae7","investigation_id":"ce124313-4762-44fc-8303-caef158070b8","mode":"findings_only_retroactive","new_score":0,"page_content_hash":"6ab868d1f3bb1f2bb21cd95acb4325b61e8fd82d836d96485e920839d256cb02","page_slug":"irs-fake-digital-asset-compliance-portal-phishing-campaign-2026","prev_score":0,"reason":"Findings-only fact-check (retroactive anchor of stored findings)","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision db7bca65-dd0f-4a6f-9281-3a7ca7cf7d2a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.