Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review · Bitrefill
- Sequence
- #4
- Score
- 52 → 52 (0)
- Cluster
- mainnet-beta
- Slot
- 425437476
- Off-chain at
- 2026-06-10T00:34:16.858Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 9Sc3nYaRke6LBmZNHwLkrq8BVLeVQ9rbypPDQjg1W4jZ
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1277 chars)
{"actor":"reviewer","decided_at":"2026-06-10T00:34:16.729Z","decision":"review","investigation_id":"8038ecc2-39f1-4530-bfdf-f87bf4b49de2","new_score":52,"page_slug":"bitrefill","prev_score":52,"reason":"The Bitrefill investigation page is well-sourced and accurately represents the March 2026 cyberattack, with core facts — attack date, attack vector, records exposed, data types, attribution evidence, company response, and historical comparable hacks — confirmed across multiple Tier-1 sources. The most significant inaccuracies are: (1) the investor list includes Draper Associates, which is absent from the primary cited source (Tech.eu) and only appears in secondary aggregators; (2) the '$6.8 billion since 2022' North Korea theft figure conflates a cumulative all-time estimate with a post-2022 qualifier; and (3) the timeline's March 2 'breach disclosure' entry conflates Bitrefill's 'technical issues' announcement with a formal breach disclosure that came two weeks later. The Cyble source returned 403 Forbidden and could not be independently verified. No claims were found to be factually disputed by more credible sources.","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}