Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
- Sequence
- #3
- Score
- 0 → 0 (-12)
- Cluster
- mainnet-beta
- Slot
- 443505849
- Off-chain at
- 2026-08-08T03:44:28.682Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 4ptjDzZrTTcSfmi4vFRXogzwJe8bCLv5Gui9M6mwnU9F
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1405 chars)
{"actor":"judge","decided_at":"2026-08-08T03:44:28.446Z","decision":"review_revise","investigation_id":"1bdf6812-5d0c-4de6-a57f-980e0fe05984","new_score":0,"page_slug":"chaindrop-shai-hulud-npm-worm-august-2026-crypto-credential-harvester","prev_score":0,"reason":"The review confirmed 15 of 24 claims outright, with strong corroboration from Tier 1 and Tier 2 sources for all core facts: attack date and entry vector, propagation mechanism, Ethereum C2 infrastructure, and attribution uncertainty. However, three claims were disputed and three were unverifiable, yielding a 25% disputed rate. Two material inaccuracies drive the penalty: claim_findings[4] shows the IOC loader byte sizes (757,598 and 738,697 bytes) are contradicted by StepSecurity and Semgrep, which report 29,918 and 11,017 bytes respectively — a 25x–67x overstatement that could mislead incident responders relying on these indicators; and claim_findings[10] overstates the ServiceTitan affected-package count ('approximately 300') against primary-source figures of 141–200+. The CSA advisory date in the timeline (claim_findings[16]) is off by one day. Two high-priority coverage gaps — on-chain tracing of the C2 contract and confirmed downstream wallet theft — are recommended additions.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}