Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#2
Score
18 → 18 (0)
Cluster
mainnet-beta
Slot
443516216
Off-chain at
2026-08-25T19:08:36.670Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
5dRmhv6qJp8V6WPS69Xt2YYHttKmLsW9fxuVxDfN3eSm
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1354 chars)
{"actor":"reviewer","decided_at":"2026-08-25T19:08:36.557Z","decision":"review","investigation_id":"a9cdc7b5-15a1-4e71-857b-15faed45731b","new_score":18,"page_slug":"coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-2026","prev_score":18,"reason":"The page's core technical, financial, and timeline claims about the Coldcard/Coinkite entropy exploit were independently verified against Coinkite's own advisory and disclosure history, TRM Labs' research report, and multiple independent news outlets, and were found to be accurately and conservatively characterized, including the crucial point that exploitation required no physical device access but also did not involve remote compromise of shipped devices. The 'multi-actor' framing is directly supported by an on-record Galaxy Research statement rather than inferred, and no facts appear to have been imported from the separate Blockstream Jade phishing incident. The most notable defect found is an internal inconsistency between the summary's Aug 10 loss figure (2,055 BTC) and the body text's Aug 10 figure (2,000+ BTC per Coinkite's own tracking), plus a small number of quotes not traceable to a specific cited URL within their section.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}