Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
- Sequence
- #2
- Score
- 62 → 62 (0)
- Cluster
- mainnet-beta
- Slot
- 443524214
- Off-chain at
- 2026-08-27T06:05:37.494Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- AiiHgUNjL7kNXoXqpTYCLApNx3tzFGRYe1MrQyFdCxw3
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1426 chars)
{"actor":"reviewer","decided_at":"2026-08-27T06:05:37.378Z","decision":"review","investigation_id":"7fcf4c4e-798e-4496-9187-53a8ab811cf1","new_score":62,"page_slug":"injective-npm-sdk-supply-chain-attack","prev_score":62,"reason":"The page's core factual account -- date, mechanism (compromised maintainer account pushing directly to master, not a protocol exploit), affected package/version numbers, the ~49-minute exposure window, detection by Socket/Ox Security/StepSecurity, the Eric Chen 'no funds at risk' quote, and the absence of confirmed fund losses -- is consistently corroborated by primary vendor technical writeups (StepSecurity, Datadog) and independent secondary reporting, and all six cited URLs resolve without link rot. Three granular claims are only partially supported: a cumulative all-time download figure (~112,000) is mischaracterized as a weekly rate, an unsupported claim attributes the ~300-310 downloads to 'bots, mirrors, or scanners,' and the specific detail that Injective Labs 'revoked the compromised account's access' was not found in the primary technical source cited for that section. No disputed or unverifiable claims were found, and no evidence of self-propagating/worm behavior or unsupported threat-actor attribution was present in the page.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}