Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #2
- Score
- 0 → 0 (0)
- Cluster
- mainnet-beta
- Slot
- 443523155
- Off-chain at
- 2026-08-27T03:24:20.073Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 14jjcJBChLRVaHdZCMFzpHZEZBm5csWHS8WDdgyeSojB
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1531 chars)
{"actor":"reviewer","decided_at":"2026-08-27T03:24:19.040Z","decision":"review","investigation_id":"49f04edf-4c80-4118-a494-f18aa91ae323","new_score":0,"page_slug":"keyv-cacheable-npm-supply-chain-attack-teampcp-mini-shai-hulud-august-2026","prev_score":0,"reason":"The page's technical description of the keyv/cacheable npm compromise itself — the maintainer account takeover, malware architecture, self-propagating worm mechanism, C2 infrastructure, affected-package specifics, and remediation timeline — is well corroborated by the cited vendor sources and by independent registry/web verification, with only minor timestamp and count discrepancies. However, the page's central and title-level claim — attribution of this specific incident to 'TeamPCP' — is materially overstated: only one of roughly seven relevant vendor sources makes an unhedged attribution, several others describe only a malware-lineage resemblance, and one cited source (The Hacker News) explicitly states that no actor has been established for this incident. Several supporting details in the TeamPCP 'operational history' narrative (SANDCLOCK/CanisterWorm package counts, a 'seventh phase' framing, an exact November 1, 2025 origin date) are not supported by the specific sources cited for them, even though the broader TeamPCP threat actor and its Mini Shai-Hulud toolkit are real and independently documented.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}