Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#2
Score
0 → 0 (0)
Cluster
mainnet-beta
Slot
443510608
Off-chain at
2026-08-25T02:59:32.217Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
77G75keGADtLuYoEdiTXQD1mY7eCBwV1VVki7cns8uGY
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1318 chars)
{"actor":"reviewer","decided_at":"2026-08-25T02:59:32.097Z","decision":"review","investigation_id":"26dc07e2-5780-4704-aa90-143adfe70acb","new_score":0,"page_slug":"solidity-pro-vscode-extension-malicious","prev_score":0,"reason":"The page's core narrative — two malicious 'Solidity Pro' VS Code extensions published by helper-beeps and web3devtoolsx, exfiltrating crypto and cloud credentials via Telegram/Cloudflare Workers, removed from Open VSX on August 6-7, 2026, and tentatively attributed to the WhiteCobra threat cluster — is well corroborated across independent primary (Yeeth Security, SlowMist) and secondary (The Hacker News, Bleeping Computer, Malpedia, CryptoTimes) sources, with exact IOC and date matches in most cases checked. A small number of granular technical details (a specific SHA-256 hash, an AES-GCM/static-passphrase claim, some of the more obscure harvested-credential types) and remediation-guidance citations to two sources (CyberPress, CyberSecurityNews) could not be independently confirmed, largely due to fetch access limitations rather than found contradictions; no claim was found to be actively disputed by a more credible current source.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}