Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review · debank.auction
- Sequence
- #2
- Score
- 2 → 2 (0)
- Cluster
- mainnet-beta
- Slot
- 443514627
- Off-chain at
- 2026-08-25T13:41:22.570Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- FWrCSZiwohQDeMfvR13XQTM1UPbfUwBxuJZEQ7okG8qf
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1167 chars)
{"actor":"reviewer","decided_at":"2026-08-25T13:41:22.070Z","decision":"review","investigation_id":"027efe27-8bb6-4acc-8596-12b3ac306d6a","new_score":2,"page_slug":"debank-auction","prev_score":2,"reason":"The page's core technical account of the debank.auction indirect-prompt-injection campaign — the hidden CSS/JSON-LD payload, the 26-model test, the GPT-5.4/Claude Sonnet 4.5 misclassification, and the companion Python-library payment campaign with its wallet address — is well supported by the primary Zscaler ThreatLabz research and corroborating trade press. Weaker points include an unsupported 'updated August 5, 2026' date that appears to conflate an archive.org capture with an actual revision, a Hacker News citation that predates and does not concern this campaign, a Group-IB citation that does not mention DeBank despite being used to support a DeBank-specific claim, and a PhishDestroy-sourced phishing domain described as presently 'active' though the source's own data shows it went offline months earlier.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}