Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#3
Score
2 → 0 (-13)
Cluster
mainnet-beta
Slot
443517164
Off-chain at
2026-08-25T19:47:48.528Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
8VZohbw4Q3AH3tuBbSNuihvs76vYMhXDkSfVbywJ6ADV
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (1815 chars)
{"actor":"judge","decided_at":"2026-08-25T19:47:48.340Z","decision":"review_revise","investigation_id":"7638801f-7416-48e4-9f83-f287e3cb78d9","new_score":0,"page_slug":"wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026","prev_score":2,"reason":"Most of this page's technical claims about the WEL1DROPPER npm campaign held up under review — package counts, delivery mechanism, Windows/Linux payload behavior, and the link to the earlier Moika campaign are all corroborated by primary sources such as Sonatype, The Hacker News, and SafeDep. But of 23 claims checked, 5 (21.7%) came back disputed or unverifiable, and they cluster around the page's most consequential risk assertions rather than minor details. The summary states as fact that WEL1DROPPER's infrastructure is linked to the sanctioned Aeza Group hosting provider and that the malware can drain cryptocurrency wallets, but the review found both claims traceable only to a single lower-tier news aggregator, not the primary research also cited alongside them (claim_findings[2], claim_findings[3]); the page's body text already hedges this as 'medium confidence,' a caveat missing from the summary. Separately, the timeline misdates the start of the related Moika campaign by about two months, contradicting its own cited source (claim_findings[16]), and a SecurityWeek citation in the North Korean campaign section actually describes an unrelated incident (claim_findings[19]). These are sourcing and calibration problems that call for correction, not evidence the page's core narrative is false, so it is being sent back for revision rather than approved as-is or removed.","score_delta":-13,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}