Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#2
Score
00 (0)
Cluster
mainnet-beta
Slot
443505845
Off-chain at
2026-08-08T03:44:28.573Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
B7ViGuMAu8Wc299sjZnWU146pTyS8o3cec9Znrwu5YJC
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1224 chars)
{"actor":"reviewer","decided_at":"2026-08-08T03:44:28.446Z","decision":"review","investigation_id":"1bdf6812-5d0c-4de6-a57f-980e0fe05984","new_score":0,"page_slug":"chaindrop-shai-hulud-npm-worm-august-2026-crypto-credential-harvester","prev_score":0,"reason":"The investigation accurately documents a real and serious supply-chain attack with strong corroboration from Tier 1 and Tier 2 sources for the core facts: attack date, entry vector, propagation mechanism, Ethereum C2 infrastructure, IOC hashes and strings, and attribution uncertainty. Two material inaccuracies were found: the loader file byte sizes (Loader A and Loader B) are overstated by roughly 25x and 67x compared to values in StepSecurity and Semgrep, and the ServiceTitan affected-package count ('approximately 300') is overstated relative to primary-source figures of 141–200+. The CSA advisory date in the timeline is off by one day (page says August 5; advisory was issued August 6). These errors are concentrated in the IOC and Scale sections and do not undermine the overall characterization of the attack.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}