Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · requests-secure-v2
- Sequence
- #3
- Score
- 0 → 0 (-8)
- Cluster
- mainnet-beta
- Slot
- 443514531
- Off-chain at
- 2026-08-25T13:35:05.197Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 8s7LGH5zDjc93nuSU2RudkaxDE2NYdPygzDP64mxMADK
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1742 chars)
{"actor":"judge","decided_at":"2026-08-25T13:35:04.679Z","decision":"review_revise","investigation_id":"05607536-644a-4a27-874b-e8189103aed1","new_score":0,"page_slug":"requests-secure-v2","prev_score":0,"reason":"The review found the page's core claim -- that no verifiable public record documents a package called requests-secure-v2 -- to be accurate and independently corroborated, and confirmed the page carefully avoids any suggestion that the real, widely-used requests library or its maintainers were compromised (claim_findings[0], claim_findings[1]). At 12.5% of claims disputed or unverifiable, the page sits in the low end of the minor-issues range: a citation misattributes six named wallet brands (Atomic, Exodus, MetaMask, Trust Wallet, Ronin, TronLink) to a ReversingLabs report that never mentions them, when the correct source is a separately-cited Checkmarx report in the same paragraph (claim_findings[11]); a typosquat count is overstated (\"more than 50\" versus the cited source's figure of 36) (claim_findings[5]); and a campaign detection date is off by three to five days from its own citation (claim_findings[23]). These are attribution and precision errors, not fabrications or problems with the page's central allegation, and no citations were found to be dead or stale. Whether an entry about an unconfirmed package should exist in this form at all is a publication-policy question this decision framework does not adjudicate; on the facts reviewed, the page is transparent about that uncertainty throughout rather than asserting the package's existence as settled fact.","score_delta":-8,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}