Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)
- Sequence
- #3
- Score
- 3 → 0 (-12)
- Cluster
- mainnet-beta
- Slot
- 443513548
- Off-chain at
- 2026-08-25T10:19:10.929Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 4MLkWghUQCXYdFubg6vRg7qM1NWm8Vhz57UmWgUbm42Z
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (2109 chars)
{"actor":"judge","decided_at":"2026-08-25T10:19:10.351Z","decision":"review_revise","investigation_id":"491937e2-0e11-4c61-ac86-db98727d3bab","new_score":0,"page_slug":"crypto-com-phishing-campaign-email-domain-abuse-august-2026","prev_score":3,"reason":"The page's central allegation -- that Crypto.com's SendGrid marketing infrastructure and branded tracking domain (url1137.crypto.com) were abused to send authenticated phishing emails -- is confirmed and, unlike most of the page's incident-specific detail, independently corroborated by a third-party domain scan rather than resting solely on a single blog post (claim_findings[0], [6]). Set against that, the review disputes an industry-statistics claim where the page's own cited sources contradict it: the page states average scam payments grew 'more than 600%,' while both Chainalysis and CryptoDailyUK, cited by the page itself, put the figure at 253% (claim_findings[17]). The review also finds a one-year date error in a cited precedent, misdating the CoinTracking SendGrid incident to November 2024 instead of November 2025, repeated in both the narrative and the timeline (claim_findings[22], [27]). Two high-priority coverage gaps further weigh on this outcome: nearly every incident-specific detail about the Crypto.com attack -- the compromise, the attack chain, the evasion artifacts, and the sole $50,000 loss figure -- traces back to one anonymous Substack post amplified by one aggregator citing a single Reddit post, with no mainstream outlet or named security vendor corroborating it, and the loss figure has no on-chain trace. The page does consistently and correctly frame Crypto.com as the victim of third-party infrastructure abuse rather than as a breached party, which keeps this from being a fairness or defamation problem, but that correct framing is the baseline expectation for the page rather than a factor that offsets the sourcing thinness and the two identified accuracy errors.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}