Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · Bankr / BankrBot (AI Agent Prompt Injection Exploit)
- Sequence
- #3
- Score
- 18 → 6 (-12)
- Cluster
- mainnet-beta
- Slot
- 443522964
- Off-chain at
- 2026-08-27T03:05:58.167Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 6CrwxLTuFBDKCV1wpvwhLX9mcSdtubNgMjBLY9hnR3wW
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1542 chars)
{"actor":"judge","decided_at":"2026-08-27T03:05:57.904Z","decision":"review_revise","investigation_id":"cbe21877-b631-47a7-a344-fe90e23b96f0","new_score":6,"page_slug":"bankr-bankrbot-ai-agent-prompt-injection-exploit","prev_score":18,"reason":"This page's core narrative about the May 4 prompt-injection exploit -- the Morse-code trigger, the NFT-based permission escalation, the stolen amount, and Bankr's remediation -- is solidly corroborated (16 of 25 checked claims fully confirmed, including the remediation steps in claim_findings[17] and [18]). The main problem is claim_findings[14]: the page states the second, May 19-20 breach of 14 wallets used 'the same underlying permission-chain vulnerability' as the first incident, but a directly-fetched contemporaneous source describes that breach as distinct and likely caused by private-key or session compromise, not a repeat of the NFT/Morse-code mechanism. That same issue is independently flagged as a high-priority coverage gap, reinforcing that it's a real interpretive overreach rather than a minor slip. Two smaller defects -- an inflated 15-20% price-decline figure versus a more commonly reported ~40% (claim_findings[6]) and a real quote misattributed to the wrong citations (claim_findings[13]) -- round out the issues, while two link-rot findings were correctly excluded from the disputed count and don't affect factual accuracy.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}