Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_approve · Allbridge Core — CCTP Base Chain Exploit (August 2026)
- Sequence
- #3
- Score
- 8 → 8 (0)
- Cluster
- mainnet-beta
- Slot
- 443511065
- Off-chain at
- 2026-08-25T03:21:17.909Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 6XPLDTdqhBSKsSzMPZViVi7ZLCa7uo2Ab41cR2KBnL6M
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1799 chars)
{"actor":"judge","decided_at":"2026-08-25T03:21:17.616Z","decision":"review_approve","investigation_id":"7be2e44e-2114-4940-85f3-54a8b6b1cd26","new_score":8,"page_slug":"allbridge-core-cctp-base-chain-exploit-august-2026","prev_score":8,"reason":"Of 40 claims checked, none were disputed, 33 were confirmed outright, and the remaining 7 involved only minor imprecision or interpretive framing rather than substantive errors. The page's central allegation — the August 19, 2026 CCTP exploit that drained 191,156 USDC from Allbridge's Base router — is confirmed and, per claim_findings[1], independently corroborated in its key figures and mechanism by a SlowMist analysis the page itself does not cite; this is a sourcing gap (also flagged in coverage_gaps) rather than a factual problem, since the uncited source agrees with what the page says. The page's 'novel attack class' framing (claim_findings[3]) is reasonably flagged as the page's own interpretive characterization rather than a directly sourced fact, and the cited precedent (Noble mint bug) is thematically similar but not mechanistically identical — a soft overstatement, not a misrepresentation, and not weighty enough to affect the verdict. The remaining partially-supported items (claim_findings[25, 28, 34, 38]) are small numerical rounding differences (a $650,000 vs. confirmed ~$570,000 loss estimate, '39 months' vs. ~40, '30 minutes' vs. ~25) or a slightly overstated summary of L2BEAT's contract-verification language, none touching the core narrative. No coverage gap was rated high priority, and reviewer confidence (0.8) was solid, supporting a clean approval with no score penalty.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}