Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_revise · Vanta Stealer — Python Infostealer Targeting Crypto Wallets
- Sequence
- #3
- Score
- 2 → 0 (-12)
- Cluster
- mainnet-beta
- Slot
- 443513364
- Off-chain at
- 2026-08-25T10:17:37.254Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 5rFukw1osWeLZD5FczAcsqDdw3njTNfjyo9DjxqaGGQS
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1729 chars)
{"actor":"judge","decided_at":"2026-08-25T10:17:36.690Z","decision":"review_revise","investigation_id":"d9de73f6-b05b-4329-858b-caf586a1203b","new_score":0,"page_slug":"vanta-stealer-python-infostealer-targeting-crypto-wallets","prev_score":2,"reason":"The reviewer confirmed 19 of 28 claims outright, including the malware's core technical profile — 20 published SHA256 hashes matching exactly, file counts, CArchive size, Python version, antivirus detection names, and data-harvesting scope were all verified directly against the primary Point Wild report and corroborated independently by PCRisk. Against that, the review found two disputed claims: a deobfuscation tool is misnamed as 'PyArmor Shot' when no source uses that name (claim_findings[10]), and the timeline's stated publication date for a CyberSecurityNews article conflicts with the page's own archive metadata for that same source (claim_findings[26]). It also found an evaluative judgment about 'experienced operators' attributed to unnamed researchers that traces to no cited source (claim_findings[20]), and an overstatement of PyArmor's obfuscation layering (claim_findings[2]). At 17.9% disputed-or-unverifiable, and with none of the disputed items touching the page's central allegation that this malware targets crypto wallets and related credentials, the page does not warrant denial. But two high-priority coverage gaps — the untraceable researcher attribution and a missing disambiguation from the unrelated legitimate company Vanta (vanta.com) — mean the page needs correction before it stands as published.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}