Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#3
Score
2 → 0 (-12)
Cluster
mainnet-beta
Slot
443513364
Off-chain at
2026-08-25T10:17:37.254Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
5rFukw1osWeLZD5FczAcsqDdw3njTNfjyo9DjxqaGGQS
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1729 chars)
{"actor":"judge","decided_at":"2026-08-25T10:17:36.690Z","decision":"review_revise","investigation_id":"d9de73f6-b05b-4329-858b-caf586a1203b","new_score":0,"page_slug":"vanta-stealer-python-infostealer-targeting-crypto-wallets","prev_score":2,"reason":"The reviewer confirmed 19 of 28 claims outright, including the malware's core technical profile — 20 published SHA256 hashes matching exactly, file counts, CArchive size, Python version, antivirus detection names, and data-harvesting scope were all verified directly against the primary Point Wild report and corroborated independently by PCRisk. Against that, the review found two disputed claims: a deobfuscation tool is misnamed as 'PyArmor Shot' when no source uses that name (claim_findings[10]), and the timeline's stated publication date for a CyberSecurityNews article conflicts with the page's own archive metadata for that same source (claim_findings[26]). It also found an evaluative judgment about 'experienced operators' attributed to unnamed researchers that traces to no cited source (claim_findings[20]), and an overstatement of PyArmor's obfuscation layering (claim_findings[2]). At 17.9% disputed-or-unverifiable, and with none of the disputed items touching the page's central allegation that this malware targets crypto wallets and related credentials, the page does not warrant denial. But two high-priority coverage gaps — the untraceable researcher attribution and a missing disambiguation from the unrelated legitimate company Vanta (vanta.com) — mean the page needs correction before it stands as published.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}