Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
- Sequence
- #2
- Score
- 18 → 18 (0)
- Cluster
- mainnet-beta
- Slot
- 443521489
- Off-chain at
- 2026-08-26T15:26:41.357Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- B1Fp8UL3Dd7SxZRzD9izrnHDdziByqzYPiBRPgw2kw4N
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1559 chars)
{"actor":"reviewer","decided_at":"2026-08-26T15:26:41.043Z","decision":"review","investigation_id":"2166bf7d-c5c4-4a44-a9a8-fbed8b9d3827","new_score":18,"page_slug":"coldcard-coinkite-hardware-wallet-firmware-exploit","prev_score":18,"reason":"The page's core narrative — a March 2021 Coldcard firmware defect that silently weakened seed entropy, disclosed by Coinkite on July 30-31, 2026, and exploited to steal Bitcoin — is well-supported by primary and independent sources: 25 of 39 extracted claims are confirmed outright, and the great majority of named quotes (NVK, Valente, Swann, Neuman) and technical details (fee signature, affected models, competitor statements, entropy bit-counts) check out. The page's principal weaknesses are that it presents an early-stage on-chain tally (~$70M) under a 'Total Scope' heading that was superseded within days by materially larger figures (~$89M, then ~$116M) and a shift from single-attacker to multi-actor characterization documented by Galaxy Research and TRM Labs; that its specific technical explanation of the root-cause commit does not match the most detailed independent post-mortem, which instead describes a linker/build-toolchain failure; and that it does not acknowledge or cross-reference at least three other index pages covering substantially the same event with different figures, nor a related phishing campaign that piggybacked on the same disclosure.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}