Skip to main content
Sign in
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Decision
publish · Hedgey
View on Solana ↗
Sequence
#1
Score
Cluster
mainnet-beta
Slot
421012580
Off-chain at
2026-05-20T15:26:58.088Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
C5tV7vA4UUsdVjbPiJ4ptjWbox71x1LJLhKnsGdi3hsf
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (5701 chars)
{"actor":"system:backfill","investigation_id":"04a3c621-dea2-4bc7-9c9c-5934edeaab4e","kind":"publish","page_slug":"hedgey","published_at":"2026-05-20T15:26:57.985Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Hedgey","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d"},{"credibility":3,"name":"","type":"other","url":"https://olympix.ai/blog/the-44m-hedgey-finance-exploit-what-went-wrong-and-how-olympix-could-have-prevented-it"},{"credibility":3,"name":"","type":"other","url":"https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth"},{"credibility":3,"name":"","type":"other","url":"https://hacken.io/audits/hedgey-finance/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d"},{"credibility":3,"name":"","type":"other","url":"https://rekt.news/hedgey-finance-rekt"},{"credibility":3,"name":"","type":"other","url":"https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024"},{"credibility":3,"name":"","type":"other","url":"https://cointelegraph.com/news/hedgey-protocol-44-million-exploit"},{"credibility":3,"name":"","type":"other","url":"https://thedefiant.io/news/defi/defi-protocol-hedgey-finance-suffers-usd44m-hack"},{"credibility":3,"name":"","type":"other","url":"https://immunebytes.com/blog/hedgey-finance-exploit-april-19-2024-detailed-analysis/"},{"credibility":3,"name":"","type":"other","url":"https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://www.certik.com/resources/blog/hedgey-finance-incident-analysis"},{"credibility":3,"name":"","type":"other","url":"https://rekt.news/hedgey-finance-rekt"},{"credibility":3,"name":"","type":"other","url":"https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/"},{"credibility":3,"name":"","type":"other","url":"https://beincrypto.com/hedgey-incurs-loss-in-crypto-hack/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d"},{"credibility":3,"name":"","type":"other","url":"https://crypto.news/hedgey-finance-hacked-for-44-7m-on-arbitrum-ethereum/"},{"credibility":3,"name":"","type":"other","url":"https://cryptobriefing.com/hedgey-finance-flash-loan-exploit/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024"},{"credibility":3,"name":"","type":"other","url":"https://www.certik.com/resources/blog/hedgey-finance-incident-analysis"},{"credibility":3,"name":"","type":"other","url":"https://olympix.ai/blog/the-44m-hedgey-finance-exploit-what-went-wrong-and-how-olympix-could-have-prevented-it"},{"credibility":3,"name":"","type":"other","url":"https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth"},{"credibility":3,"name":"","type":"other","url":"https://tracxn.com/d/insights/merger-acquisition-deals-brief/anchorage-digital-acquires-hedgey/__4KzVvRDuMqoyMDEVEi4vHYqWxSLLQwKCBLHGXoHoelE"}]}],"sources_used":[],"summary":"Hedgey is a token vesting, lockup, and claims protocol that served over 100 on-chain projects before suffering a critical smart contract exploit on April 19, 2024, resulting in the theft of approximately $44.7 million across Ethereum and Arbitrum. The vulnerability — a missing input validation check in the ClaimCampaigns.sol contract — was present despite two prior audits by ConsenSys Diligence. No confirmed recovery of stolen funds has been reported; Hedgey was subsequently acquired by Anchorage Digital in late 2025.","timeline":[{"date":"2023-06-01","event":"ConsenSys Diligence completes second audit of Hedgey contracts, including the re-audit commissioned for Arbitrum DAO onboarding; vulnerable ClaimCampaigns.sol flaw goes undetected.","source":""},{"date":"2024-04-19","event":"Exploit begins at ~07:06 UTC. Attacker uses $1.3M Balancer flash loan to abuse createLockedCampaign input validation gap in ClaimCampaigns.sol. $2.1M drained on Ethereum; $42.6M in BONUS tokens drained on Arbitrum. Secondary copycat attacker linked to Unizen exploit also strikes on Ethereum. Total loss: ~$44.7M.","source":""},{"date":"2024-04-19","event":"Hedgey team disables new claims creation, engages SEAL 911, contacts Gate.io and Bybit to freeze attacker-linked deposits, and sends on-chain message to attacker requesting return of funds.","source":""},{"date":"2024-04-19","event":"CUBE3.AI publishes postmortem confirming real-time detection of the malicious transaction; CertiK and Halborn publish independent on-chain analyses identifying attacker addresses and laundering behavior.","source":""},{"date":"2024-04-20","event":"Official post-mortem published by Hedgey team via Medium, confirming 23 of 60 active campaigns were impacted, vesting/lockup contracts were unaffected, and law enforcement coordination was underway.","source":""},{"date":"2025-12-16","event":"Anchorage Digital announces acquisition of Hedgey, integrating the token vesting tooling into a full-stack institutional token lifecycle management product. Deal terms undisclosed.","source":""}]},"v":1}