Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Lodestar V0
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 422743546
- Off-chain at
- 2026-05-28T15:02:22.764Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 9r5bueA5tFfRpMPo2j2jeFWhhCXKzcNdaHEbXNaqYEjR
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (6998 chars)
{"actor":"system:backfill","investigation_id":"7a6a9a8c-cef4-4d72-89a6-e56479ac9e6f","kind":"publish","page_slug":"lodestar-v0","published_at":"2026-05-28T15:02:22.655Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lodestar V0","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://iq.wiki/wiki/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://docs.lodestarfinance.io/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5","type":"other","url":""},{"credibility":3,"name":"https://web3isgoinggreat.com/single/lodestar-finance-attacked","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://x.com/LodestarFinance/status/1601687317604839424","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://iq.wiki/wiki/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://claim.lodestarfinance.io/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/LodestarFinance/status/1684418629297930240","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/lodestar-v1","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","type":"other","url":""}]}],"sources_used":[{"credibility":2,"name":"CertiK — Lodestar Finance Incident Analysis","type":"research","url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis"},{"credibility":2,"name":"CoinTelegraph — Lodestar Finance exploited in flash loan attack","type":"news_article","url":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack"},{"credibility":2,"name":"CoinTelegraph — Hackers copied Mango Markets attacker's methods to exploit Lodestar","type":"news_article","url":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik"},{"credibility":2,"name":"Halborn — Explained: The Lodestar Finance Hack (November 2022)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022"},{"credibility":2,"name":"Web3 Is Going Great — Lodestar Finance attacked and drained","type":"community_report","url":"https://web3isgoinggreat.com/single/lodestar-finance-attacked"},{"credibility":2,"name":"PlutusDAO — Official Statement on the Lodestar Finance Exploit","type":"official","url":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5"},{"credibility":2,"name":"IQ.wiki — Lodestar Finance","type":"research","url":"https://iq.wiki/wiki/lodestar-finance"},{"credibility":2,"name":"DeFiLlama — Lodestar Finance TVL","type":"on_chain","url":"https://defillama.com/protocol/lodestar-finance"},{"credibility":2,"name":"DeFiLlama — Lodestar V1 TVL","type":"on_chain","url":"https://defillama.com/protocol/lodestar-v1"},{"credibility":3,"name":"Lodestar Finance Twitter — Exploit acknowledgment and hacker outreach","type":"social_media","url":"https://x.com/LodestarFinance/status/1601687317604839424"},{"credibility":3,"name":"Lodestar Finance Twitter — V1 launch announcement","type":"social_media","url":"https://x.com/LodestarFinance/status/1684418629297930240"},{"credibility":2,"name":"Unchained Crypto — DeFi Lending Platform Lodestar Finance Loses $6.9M in Oracle Exploit","type":"news_article","url":"https://unchainedcrypto.com/defi-lending-platform-lodestar-finance-loses-6-9m-in-oracle-exploit/"},{"credibility":2,"name":"EigenPhi — $6.9M Lodestar Exploit: Oracle Manipulations","type":"research","url":"https://eigenphi.substack.com/p/69m-lodestar-exploit-oracle-manipulations"}],"summary":"Lodestar V0 is the original deployment of Lodestar Finance, an algorithmic money market lending protocol on Arbitrum. On December 10, 2022, the protocol suffered a critical flash loan exploit in which an attacker manipulated the plvGLP price oracle to drain approximately $6.9 million in user funds. The protocol was subsequently relaunched as Lodestar V1 in July 2023; V0 remains abandoned with negligible TVL (~$95K) and the attacker was never publicly identified.","timeline":[{"date":"2022-12-08","event":"Attacker wallet funded with approximately 1,500 ETH in preparation for the exploit.","source":""},{"date":"2022-12-10","event":"Flash loan oracle manipulation exploit executed against Lodestar V0 on Arbitrum; approximately $6.5–6.9 million drained from the protocol.","source":""},{"date":"2022-12-10","event":"Lodestar Finance team publicly acknowledged the exploit and appealed to the attacker for a white-hat agreement via Twitter.","source":""},{"date":"2022-12-10","event":"PlutusDAO published official statement clarifying the vulnerability was in Lodestar's oracle implementation, not the plvGLP contract.","source":""},{"date":"2022-12-11","event":"CertiK published incident analysis identifying attacker wallet 0xb50f...5db13 and detailing the on-chain attack flow.","source":""},{"date":"2022-12-12","event":"Halborn published post-mortem analysis classifying the exploit as a preventable oracle vulnerability.","source":""},{"date":"2023-04-08","event":"Lodestar Finance relaunched on Arbitrum, attracting over $30 million in TVL.","source":""},{"date":"2023-07-27","event":"Lodestar V1 launched; team announced migration of incentives from V0 to V1.","source":""},{"date":"2023-10-01","event":"Lodestar team reported approximately one-third of hack losses repaid to affected depositors; 750,000 esLODE tokens allocated for further compensation.","source":""}]},"v":1}