Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Decision
review · ShipMonk
View on Solana ↗
Sequence
#2
Score
28 → 28 (0)
Cluster
mainnet-beta
Slot
443515069
Off-chain at
2026-08-25T14:05:38.367Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
8QGMHRQD6ProZ6jLwgiDJsuJXwsXymha7dHLvv4rMijD
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1336 chars)
{"actor":"reviewer","decided_at":"2026-08-25T14:05:37.763Z","decision":"review","investigation_id":"930d9ec3-3b01-456d-b86e-c788baabbe19","new_score":28,"page_slug":"shipmonk","prev_score":28,"reason":"The page's factual core — the Metabase CVE-2026-72898 zero-day, the ShipMonk/Trezor breach scope (13,689 customers, 11,742 full/1,947 partial records), the related Framework/Tally/n8n/Kilo Code disclosures, and the mitigating 90-day retention policy — is well supported by primary and independent secondary sources, including Trezor's own blog. The most significant defect is an internal contradiction: the summary states ShipMonk 'disclosed' the breach, while the page's own body sections correctly note ShipMonk never issued any public statement and all disclosure came from Trezor. One cited source (CBInsights) also contradicts the page's stated 2014 founding year. The larger structural concern is that ShipMonk, an uninvolved logistics company with no independent crypto business, is included in a crypto risk index based solely on being one of several victims of a broad, non-crypto-specific supply-chain attack, with no source establishing negligence or misconduct on ShipMonk's part.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}