Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #2
- Score
- 0 → 0 (0)
- Cluster
- mainnet-beta
- Slot
- 443518680
- Off-chain at
- 2026-08-25T23:08:42.010Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- BkqciycvuoUCqyf39hPneLNa7HctohgSB3aMNSCjKMbg
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1530 chars)
{"actor":"reviewer","decided_at":"2026-08-25T23:08:41.930Z","decision":"review","investigation_id":"1432a256-9098-4bcb-8698-a7e4ea73c243","new_score":0,"page_slug":"coldcard-coinkite-august-2026-multi-actor-attacker-cluster","prev_score":0,"reason":"The page's core factual scaffolding (attacker count, BTC/dollar totals, wave breakdown, technical root cause, law-enforcement cooperation, and dormancy statistics) is well supported by cited and independently found sources, and it correctly frames the vulnerability as an engineering defect rather than alleging wrongdoing by Coinkite. However, the page has a genuine date/time discrepancy for Wave 1 (stated as July 31 UTC when Galaxy Research's own primary data and multiple outlets place it on July 30 UTC), several granular on-chain figures and quotes that could not be independently verified, one claim (Security Alliance/SEAL involvement) unverifiable in any source checked, and one section (AI-rediscovery/Tokenomist dispute) whose underlying facts are accurate but not supported by the specific sources cited for that section. No evidence of cross-contamination with Blockstream Jade or other hardware-wallet vendors was found in any of this page's citations; sources consistently and correctly describe the Coldcard/Coinkite-specific vulnerability, and one search explicitly confirmed Blockstream Jade was reported as unaffected.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}