Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · Crypto DAO (BNB Chain Access-Control Exploit, July 2026)
- Sequence
- #3
- Score
- 4 → 0 (-10)
- Cluster
- mainnet-beta
- Slot
- 443505857
- Off-chain at
- 2026-08-08T03:51:14.201Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- HfyrWGQnWsxw3yzKyfCrXghqhTPHEg3n7GG1TSJFQEzg
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1510 chars)
{"actor":"judge","decided_at":"2026-08-08T03:51:13.793Z","decision":"review_revise","investigation_id":"f5182354-8f85-4c17-893e-eead4d4d56d2","new_score":0,"page_slug":"crypto-dao-bnb-chain-access-control-exploit-july-2026","prev_score":4,"reason":"The page's core technical narrative is well-supported: the exploit date, blockchain, root cause (missing access-control modifier), attacker wallet, Blockaid detection, and team silence are all confirmed by Tier 1–2 sources. However, the headline loss figure of $8.2 million is materially contested by one of the page's own cited sources — the SlowMist Hacked database records actual attacker profit at approximately $52,000, noting the $8.2M represents assets in related monitored addresses rather than confirmed stolen proceeds (claim_findings[1] and claim_findings[21]). This discrepancy is a factor of roughly 157x and involves the single most prominent claim on the page. The five unverifiable findings (claim_findings[10], [11], [18], [20]) are inherent absence-of-evidence claims consistent with the source record but not independently cross-checked. The page should be revised to acknowledge the $8.2M vs. $52K discrepancy and clarify whether the figure represents vault exposure or confirmed attacker profit; on-chain BscScan verification would close the high-priority coverage gap identified by the reviewer.","score_delta":-10,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}