Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#2
Score
0 → 0 (0)
Cluster
mainnet-beta
Slot
443514527
Off-chain at
2026-08-25T13:35:05.049Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
6KPmVMumBTpUSg4XUn6kRZiVDF2S9SuEsoLcmuWxSvpt
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1228 chars)
{"actor":"reviewer","decided_at":"2026-08-25T13:35:04.679Z","decision":"review","investigation_id":"05607536-644a-4a27-874b-e8189103aed1","new_score":0,"page_slug":"requests-secure-v2","prev_score":0,"reason":"The page's central and most consequential claim -- that no verifiable public record documents a package named requests-secure-v2 -- is well-supported and independently corroborated, and the page correctly and consistently distinguishes the alleged fake package from the genuine, widely-used requests library without ever misattributing wrongdoing to its real maintainers. However, several supporting claims about the broader threat archetype contain citation-precision errors: a wallet-name list is misattributed to the ReversingLabs BIPClip source when it actually belongs to a separately-cited Checkmarx campaign, the TrapDoor timeline entry states a detection date (May 19, 2026) not found in its cited source (which gives May 22-24, 2026), and a claim that security changes were made to 'both registries' (RubyGems and PyPI) is only supported for PyPI in the cited source.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}