Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · AI Agent Prompt Injection Crypto Attack Class (2026)
- Sequence
- #3
- Score
- 0 → 0 (-12)
- Cluster
- mainnet-beta
- Slot
- 443505319
- Off-chain at
- 2026-08-08T01:56:19.703Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 2JEqMcCXvmjWgNPAchb436LhuW13dtkVfyYTo1jszXT8
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1409 chars)
{"actor":"judge","decided_at":"2026-08-08T01:56:19.512Z","decision":"review_revise","investigation_id":"d833d196-5311-4b1f-8661-fcb59faee33f","new_score":0,"page_slug":"ai-agent-prompt-injection-crypto-attack-class-2026","prev_score":0,"reason":"14 of 21 claims are confirmed from credible independent sources, and the core incidents (Bankr/Grok on-chain details, Zscaler SEO poisoning research, OpenClaw/Lobstar Wilde, OWASP 2026 rankings) are well-evidenced. However, claim_findings[10] — the characterization of Step Finance as an 'overpermissioned AI trading agent' incident — is disputed by three Tier 1 sources (The Record, Halborn, BleepingComputer), all of which describe it solely as a device compromise with no AI agent involvement. The AI agent framing traces exclusively to KuCoin's editorial blog, yet the page presents it as documented fact. This is a classification error affecting a core allegation and propagates into the $45M aggregate figure in claim_findings[15]. Three additional claims are unverifiable or only partially supported (claim_findings[17], [18], [21]), and a high-priority coverage gap calls for either a primary source confirming the AI agent role in Step Finance or explicit re-framing of that section as KuCoin's interpretation.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}