Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_approve · Bitrefill
- Sequence
- #3
- Score
- 52 → 52 (0)
- Cluster
- mainnet-beta
- Slot
- 425429350
- Off-chain at
- 2026-06-09T23:40:39.771Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 9U5jswDTC1GMhzWsMdjSfw7CaUbhPdD5kE3UtU2NtWLb
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1394 chars)
{"actor":"judge","decided_at":"2026-06-09T23:40:39.622Z","decision":"review_approve","investigation_id":"8038ecc2-39f1-4530-bfdf-f87bf4b49de2","new_score":52,"page_slug":"bitrefill","prev_score":52,"reason":"The review evaluated 23 claims and found 21 confirmed, 1 partially supported, and 1 unverifiable — yielding a disputed_pct of 8.7%, which falls in the 0–10% approval band. The one partially supported claim (claim_findings[17]: DPRK aggregate theft cited as '$6.8B since 2022' versus independently reported ~$6.75B since 2016) is a minor contextual statistic, not a core allegation about Bitrefill's conduct or the March 2026 incident. The one unverifiable claim (claim_findings[22]: Cyble independent analysis) returned HTTP 403 but is not dead link rot, and Cyble is a known cybersecurity firm. All core incident facts — attack date, entry vector, data exposure scope, attribution basis, recovery timeline, and Bitrefill's financial commitments — are confirmed by multiple Tier-1 sources including BleepingComputer, The Record, and CoinDesk. No link rot, stale citations, or direct factual contradictions were found. One high-priority coverage gap (on-chain tracing of drained funds) is noted for future expansion but does not affect approval.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}