Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review_approve · BTCPay Server — LND Macaroon Credential Exploit (August 2026)
- Sequence
- #3
- Score
- 52 → 52 (0)
- Cluster
- mainnet-beta
- Slot
- 443511328
- Off-chain at
- 2026-08-25T03:27:38.805Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 6AUSQqLDZiQNDjQHb2uTFNkz4JEnGvLgbpoKD3xoopL4
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1657 chars)
{"actor":"judge","decided_at":"2026-08-25T03:27:38.533Z","decision":"review_approve","investigation_id":"81428e11-1d41-4a04-9369-d9826a55dfe9","new_score":52,"page_slug":"btcpay-server-lnd-macaroon-credential-exploit-august-2026","prev_score":52,"reason":"The review found no disputed, stale, or unverifiable claims across all 24 checked items (disputed_pct 0%). The core factual record -- the pre-authentication macaroon-theft mechanism, the affected version range, the correct absence of a CVE, the identities of the two named victims, the patch details, and the 3 BTC recovery bounty -- was independently corroborated against BTCPay Server's own advisory and multiple independent outlets (claim_findings[1], [7], [8], [9], [11], [12], [17]). Only two minor items were rated partially_supported: an approximate 'thousands of merchants' figure and the exact day of an August 2017 founding date (claim_findings[19], [22]) -- both directionally correct with only the precise wording unsourced, not materially misleading. The reviewer flagged one high-priority coverage gap around on-chain forensic tracing of the stolen funds, but noted this likely reflects that no such analysis has been publicly published yet rather than an omission of available facts (coverage_gaps[1]) -- it points to a future expansion opportunity, not a defect in what the page currently asserts. Given zero disputed claims, no link rot, and reasonably high reviewer confidence (0.82), this page holds up and does not warrant a score penalty.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}