Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
- Sequence
- #3
- Score
- 0 → 0 (-12)
- Cluster
- mainnet-beta
- Slot
- 443519544
- Off-chain at
- 2026-08-26T06:07:49.742Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- Dx3CUs993u5sSH51vgnwBPYtBvUH453W47thcJKEvaNP
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (2165 chars)
{"actor":"judge","decided_at":"2026-08-26T06:07:49.295Z","decision":"review_revise","investigation_id":"dd0db8d8-86d7-4988-95a1-b35ea4d655cf","new_score":0,"page_slug":"north-korea-lazarus-group-h1-2026-systematic-crypto-theft-campaign","prev_score":0,"reason":"Recomputing from the reviewer's own claim_findings array (41 entries, not the 42 stated in the summary block) gives 28 confirmed, 2 partially supported, 4 disputed, and 7 unverifiable claims. Using the disputed-plus-unverifiable formula, that is 11/41 = 26.8%, which falls in the 10-30% band. The core allegations of the page -- DPRK/Lazarus responsibility for the Drift and KelpDAO exploits, the OFAC sanctions details, and the H1 2026 aggregate loss figures -- are all confirmed against primary or well-corroborated sources (claim_findings[0], [10], [11], [17], [18]). The disputed items sit in supporting and historical sections: the page mislabels the TraderTraitor cluster as 'UNC4736' when Mandiant tracks it as UNC4899 (claim_findings[1] and [7], both stemming from the same underlying labeling error, confirmed wrong by a Tier 1 MITRE ATT&CK source and by the page's own cited LayerZero report); the page's 2024 historical figures ($975M/62 incidents/39% share) conflict with widely corroborated reporting of $1.34B/47 incidents/61% share, materially changing the escalation narrative the page tells (claim_findings[28]); and the page's DeFi TVL passage fails its own arithmetic ($120B minus $70B does not equal the stated $55B outflow) while also diverging from independently reported figures (claim_findings[34]). A high-priority coverage gap independently flags that the page presents historical data from multiple research firms as a single consistent trend without disclosing that firms materially disagree, reinforcing the 2024-figures problem. These are real defects that warrant correction, but they are concentrated in contextual/historical material rather than the central factual claims of the investigation, which remain solidly supported.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}