Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review · JADEPUFFER
- Sequence
- #2
- Score
- 0 → 0 (0)
- Cluster
- mainnet-beta
- Slot
- 443518710
- Off-chain at
- 2026-08-25T23:10:52.914Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- Bj8JkGs2N6xh8LxJyYEfRcL4pSTZ6C5irheo9GTYK1Tw
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1440 chars)
{"actor":"reviewer","decided_at":"2026-08-25T23:10:52.810Z","decision":"review","investigation_id":"5ff2d8a2-70bd-433c-84c9-c3bbd2752ac5","new_score":0,"page_slug":"jadepuffer","prev_score":0,"reason":"The page's core technical narrative (CVE-2025-3248/CVE-2026-9198 in Langflow, the Nacos/MinIO pivot, ENCFORGE's design, IOCs, and hashes) is well supported by Sysdig's original research and closely corroborated by independent security journalism, with several exact figures (hashes, config-item counts, timing) matching independent write-ups precisely. However, the page contains a repeated, internally inconsistent, and externally contradicted superlative claim -- that a given KEV catalog addition (variously dated July 8 or August 4, 2026) was 'the first' time CISA listed an AI agent platform vulnerability -- when CISA's own KEV catalog shows an earlier Langflow listing in March 2026, and the page itself documents an even earlier Langflow KEV listing in May 2025. A secondary, minor factual error was found in the CVE-2021-29441 disclosure date (page: March 1, 2021; primary disclosing source: April 14, 2021), and the Sysdig disclosure date is imprecise by one to two days in two locations. These are date/superlative errors layered on an otherwise well-verified technical body of claims.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}