Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #2
- Score
- 0 → 0 (0)
- Cluster
- mainnet-beta
- Slot
- 443505845
- Off-chain at
- 2026-08-08T03:44:28.573Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- B7ViGuMAu8Wc299sjZnWU146pTyS8o3cec9Znrwu5YJC
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1224 chars)
{"actor":"reviewer","decided_at":"2026-08-08T03:44:28.446Z","decision":"review","investigation_id":"1bdf6812-5d0c-4de6-a57f-980e0fe05984","new_score":0,"page_slug":"chaindrop-shai-hulud-npm-worm-august-2026-crypto-credential-harvester","prev_score":0,"reason":"The investigation accurately documents a real and serious supply-chain attack with strong corroboration from Tier 1 and Tier 2 sources for the core facts: attack date, entry vector, propagation mechanism, Ethereum C2 infrastructure, IOC hashes and strings, and attribution uncertainty. Two material inaccuracies were found: the loader file byte sizes (Loader A and Loader B) are overstated by roughly 25x and 67x compared to values in StepSecurity and Semgrep, and the ServiceTitan affected-package count ('approximately 300') is overstated relative to primary-source figures of 141–200+. The CSA advisory date in the timeline is off by one day (page says August 5; advisory was issued August 6). These errors are concentrated in the IOC and Scale sections and do not undermine the overall characterization of the attack.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}