Skip to main content
AVOID.NET

Audit log

Every state-changing event for WaterPlum / Contagious Interview: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-21 23:10:55Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 449,199,426
    sig
    5QNKVXqsh9ry…iqFjBJKfexplorer ↗
    hash
    HJDBUt8XWu7g…11voL7L6sha256 → base58
    verifying row…full verify ↗
    canonical bytes (25275 B) ▸
    {"actor":"system:backfill","investigation_id":"3ff27a94-3426-4ecf-8cd4-fa6a1e524dcb","kind":"publish","page_slug":"waterplum-contagious-interview","published_at":"2026-09-21T23:10:55.678Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"WaterPlum / Contagious Interview","sections":[{"content":"A joint cybersecurity advisory published September 18, 2026 by seven agencies — Japan's National Police Agency (NPA), Japan's National Cybersecurity Office (NCO), the U.S. Federal Bureau of Investigation (FBI), the U.S. Department of Defense Cyber Crime Center (DC3), the Australian Signals Directorate's Australian Cyber Security Centre (ASD ACSC), Germany's Bundesnachrichtendienst (BND), and Germany's Bundesamt für Verfassungsschutz (BfV) — formally attributed the WaterPlum campaign to a North Korean state-linked actor. The agencies assess that WaterPlum operators and associated North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, a body subordinate to the Central Committee of the Workers' Party of Korea that is responsible for North Korea's weapons research and production. Prior to the joint advisory, the broader security research community had tracked the same group under the name Contagious Interview since approximately 2023, and some researchers have also referred to the cluster as Deceptive Development or linked it to the Lazarus Group ecosystem. The advisory does not constitute a criminal conviction or judicial finding; it represents the official assessment of the seven signatory agencies.","heading":"Attribution and State Sponsorship","severity":"critical","sources":[{"credibility":2,"name":"North Korea-Linked WaterPlum Used Fake Jobs to Steal Crypto, NPA Says — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/north-korea-linked-waterplum-used-fake-jobs-to-steal-crypto-npa-says/"},{"credibility":2,"name":"Joint FBI and Japanese NPA Advisory Exposes North Korean WaterPlum Campaign — BrinzTech","type":"news_article","url":"https://www.brinztech.com/breach-alerts/brinztech-alert-joint-fbi-and-japanese-npa-advisory-exposes-north-korean-waterplum-campaign-infecting-30000-devices-and-7000-crypto-wallets"},{"credibility":2,"name":"North Korea WaterPlum Crypto Thefts Attribution — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/24f4f-north-korea-waterplum-crypto-thefts-attribution"},{"credibility":1,"name":"WaterPlum / Contagious Interview Advisory — Australian Cyber Security Centre (cyber.gov.au)","type":"regulatory","url":"https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals"},{"credibility":2,"name":"North Korean WaterPlum — The Cyber Express","type":"news_article","url":"https://thecyberexpress.com/waterplum-contagious-interview-north-korea/"}]},{"content":"According to the September 18, 2026 joint government advisory, WaterPlum infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026. Credentials or funds were obtained from more than 7,000 cryptocurrency wallets. The agencies reported that at least 1.7 billion Japanese yen — equivalent to approximately $10.71 million USD at the time of reporting — was transferred to wallets controlled by WaterPlum actors and ultimately to the DPRK. Japan's NPA separately disclosed that a laptop farm on Japanese soil was dismantled for the first time, and that several hundred million yen had been transferred abroad through North Korean IT-worker employment operations operating within Japan. A documented case involved a 2025 recruitment attempt targeting Japanese cryptocurrency exchange bitFlyer, in which an applicant claiming Malaysian nationality used multiple VPN services and requested cryptocurrency payment before ultimately declining the position. Researchers note that the campaign has been active in some form since at least 2022, making the December 2025–July 2026 figures a partial window of a longer-running operation.","heading":"Campaign Scale and Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"North Korean Fake Recruiters Infect 30K Devices, Steal $10.7M in Crypto — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto"},{"credibility":2,"name":"North Korea-Linked WaterPlum Used Fake Jobs to Steal Crypto, NPA Says — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/north-korea-linked-waterplum-used-fake-jobs-to-steal-crypto-npa-says/"},{"credibility":2,"name":"North Korean Hackers Infect 30,000 PCs, Steal $10,700,000 in Crypto Through Fake IT Jobs — Daily Hodl","type":"news_article","url":"https://dailyhodl.com/2026/09/21/north-korean-hackers-infect-30000-pcs-steal-10700000-in-crypto-through-fake-it-jobs-fbi/"},{"credibility":1,"name":"FBI: North Korean Fake Job Interviews Hit 30,000 Devices — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/09/19/north-korea-shock-fake-job-interviews-drain-107m-from-7000-wallets/"}]},{"content":"The WaterPlum campaign relies on social engineering rather than technical vulnerability exploitation as its primary entry vector. Operators create fake recruiter personas and approach software developers, web engineers, blockchain specialists, and designers on social media platforms, job boards, and freelance marketplaces. Targets are offered attractive employment positions at companies purportedly operating in AI, cryptocurrency, or NFT sectors. Once contact is established, the operator schedules a fake technical interview and instructs the candidate to either run a malicious npm package provided as a coding assignment, troubleshoot a supposed video-conferencing problem by executing attacker-supplied code, or open a poisoned Visual Studio Code project from a shared repository. The advisory specifically warns that attackers have used AI-driven face-swapping software during video calls to disguise operators as believable candidates or recruiters, and that 'laptop farms' operated by local facilitators in the target country supply domestic IP addresses that defeat basic geolocation checks. North Korean IT workers have also reportedly obtained genuine remote employment positions at foreign companies to generate salary income for the regime while simultaneously serving as access vectors. Employers have been warned to treat refusal to appear on camera, frequent audio or video freezes, and requests for cryptocurrency-only compensation as red flags. The advisory identifies commands containing curl, base64, -enc, mshta, or Invoke-WebRequest as indicators of malicious interview code.","heading":"Attack Methods and Social Engineering","severity":"critical","sources":[{"credibility":2,"name":"North Korean WaterPlum — The Cyber Express","type":"news_article","url":"https://thecyberexpress.com/waterplum-contagious-interview-north-korea/"},{"credibility":3,"name":"WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks — DEV Community","type":"news_article","url":"https://dev.to/anoymask/waterplum-north-korean-campaign-infects-30000-devices-via-fake-interview-tasks-4528"},{"credibility":2,"name":"North Korean WaterPlum Hackers Target IT Professionals — GBHackers","type":"news_article","url":"https://gbhackers.com/north-korean-waterplum-hackers-target-it-professionals/"},{"credibility":2,"name":"North Korean WaterPlum Hackers Infect 30,000 PCs — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/north-korean-waterplum-hackers/"}]},{"content":"The joint advisory and associated security research identify five distinct malware families deployed by WaterPlum. BeaverTail is a JavaScript-based infostealer typically delivered concealed inside malicious npm packages; it harvests browser-stored credentials, clipboard contents, and cryptocurrency wallet data. InvisibleFerret is a Python-based backdoor that establishes persistent remote access and exfiltrates data to attacker-controlled infrastructure. OtterCookie is a JavaScript remote-access trojan with integrated information-stealing functions including screenshot capture and keystroke logging. OtterCandy is described by researchers as a hybrid combining OtterCookie capabilities with additional RAT functionality. StoatWaffle is a modular Node.js loader delivered through malicious Visual Studio Code projects; it exploits VS Code workspace configuration files (specifically .vscode/tasks.json) to execute automatically when a target opens and trusts the project folder. Collectively these payloads are designed to harvest browser credentials, clipboard data, keystrokes, screenshots, cryptocurrency private keys and seed phrases, identity documents, and source code. The advisory also notes that once backdoor access is established, attackers may attempt to pivot into the networks of companies or organizations where the compromised developer works. Researchers tracking the broader Contagious Interview campaign across package registries have linked over 1,700 malicious packages on npm, PyPI, Go Modules, crates.io, and Packagist to the same threat cluster.","heading":"Malware Arsenal: Five Named Families","severity":"critical","sources":[{"credibility":2,"name":"North Korean WaterPlum — The Cyber Express","type":"news_article","url":"https://thecyberexpress.com/waterplum-contagious-interview-north-korea/"},{"credibility":2,"name":"Illicit VS Code Projects Tapped to Deploy StoatWaffle Malware — SC World","type":"news_article","url":"https://www.scworld.com/brief/illicit-vs-code-projects-tapped-to-deploy-stoatwaffle-malware"},{"credibility":2,"name":"North Korea's Contagious Interview Campaign Escalates: 338 Malicious npm Packages — Socket.dev","type":"research","url":"https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages"},{"credibility":2,"name":"Contagious Interview: North Korean Hackers Target Crypto Devs with Fake Job NPM Malware — VPN Central","type":"news_article","url":"https://vpncentral.com/contagious-interview-north-korean-hackers-target-crypto-devs-with-fake-job-npm-malware/"},{"credibility":3,"name":"WaterPlum Compromises 30,000 PCs via Fake Coding Tests — Windows Forum","type":"news_article","url":"https://windowsforum.com/news/waterplum-compromises-30-000-pcs-via-fake-coding-tests.444984/"}]},{"content":"All government advisories issued as of September 2026 describe the campaign as ongoing. The crypto and Web3 developer community represents a primary and continuing target: operators specifically impersonate recruiters from legitimate cryptocurrency exchanges, NFT projects, DeFi protocols, and blockchain infrastructure companies. The risk is not limited to individual financial loss; once a developer's device is compromised, the attackers may attempt to exfiltrate source code, private keys used in production deployments, and organizational credentials, potentially enabling downstream attacks on protocols and platforms. The advisory notes that unknowingly hiring a North Korean IT worker as a contractor also exposes firms to U.S. sanctions liability under OFAC regulations governing transactions with the DPRK. Researchers tracked the broader Contagious Interview cluster as early as 2022, and new malicious packages continue to appear across multiple package registries. The December 2025–July 2026 figures represent a defined reporting window, not the full historical scope of losses attributable to the campaign.","heading":"Ongoing Threat and Current Risk to Crypto Industry","severity":"critical","sources":[{"credibility":2,"name":"North Korean WaterPlum Supply Chain Attack — Aviatrix AI Threat Research","type":"research","url":"https://aviatrix.ai/threat-research-center/north-korean-waterplum-hackers-infected-30000-devices-worldwide/"},{"credibility":2,"name":"Famous Chollima / WaterPlum Cyber Actor Group — RH-ISAC","type":"research","url":"https://rhisac.org/general-blog/famous-chollima-waterplum-cyber-actor-group-continue-targeting-it-professionals/"},{"credibility":2,"name":"North Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/north-korean-waterplum-hackers/"},{"credibility":2,"name":"North Korean Fake Recruiters Infect 30K Devices, Steal $10.7M in Crypto — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto"}]},{"content":"The joint advisory and security researchers identify the following protective measures for developers and organizations. Individuals should run any code received during a recruitment or interview process exclusively inside an isolated virtual machine with no access to personal wallets or credentials. Unfamiliar Visual Studio Code projects should be opened in Restricted Mode, with .vscode/tasks.json inspected before the project is trusted. Commands presented during interviews that include curl, base64, -enc, mshta, or Invoke-WebRequest should be treated as strongly indicative of malicious intent. After a potential compromise, victims should assume all credentials stored on the affected device are stolen, rotate all cryptocurrency wallets from a clean device, and fully reinstall the operating system before further use. Organizations should verify that applicant IP addresses are consistent with their claimed locations, and should treat consistent refusal to appear on live video, repeated audio or video degradation, requests for cryptocurrency-only compensation, and high-quality AI-generated profile photographs as potential indicators of a North Korean IT-worker candidate. For npm or other package-registry consumers, the presence of unexpected child processes spawned by Node.js or Python, unusual access to browser profile directories, and outbound traffic to unfamiliar hosts after running a new package are behavioral indicators. The advisory recommends limiting contractor access to production systems and requiring multi-party approval for any code merged from contractor accounts.","heading":"Protective Measures and Indicators of Compromise","severity":"high","sources":[{"credibility":2,"name":"North Korean WaterPlum — The Cyber Express","type":"news_article","url":"https://thecyberexpress.com/waterplum-contagious-interview-north-korea/"},{"credibility":3,"name":"WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks — DEV Community","type":"news_article","url":"https://dev.to/anoymask/waterplum-north-korean-campaign-infects-30000-devices-via-fake-interview-tasks-4528"},{"credibility":2,"name":"North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/north-korea-hackers-crypto-wallets-job-offers/"}]},{"content":"Before the September 2026 joint advisory standardized the name WaterPlum, security researchers had tracked this threat cluster under the Contagious Interview label since at least 2023. The group's tactics — targeting developers via fake job offers and malicious npm packages — were documented by multiple threat-intelligence firms as early as 2022. Socket.dev tracked the publication of over 338 malicious npm packages across a single escalation period and reported more than 1,700 packages linked to the broader campaign across multiple package ecosystems including npm, PyPI, Go Modules, crates.io, and Packagist. The Contagious Interview campaign has been described by some researchers as Lazarus-adjacent, though the joint government advisory attributes it specifically to the 313 General Bureau rather than to Lazarus Group directly. Some vendors and information-sharing groups have also used the aliases Famous Chollima and Deceptive Development for overlapping or related clusters. The advisory does not explicitly adjudicate the boundaries between these cluster names; AVOID.NET uses WaterPlum as the primary identifier consistent with the formal government designation while noting that prior research published under Contagious Interview remains substantively relevant.","heading":"Historical Background: Contagious Interview Prior to the WaterPlum Designation","severity":"medium","sources":[{"credibility":2,"name":"North Korea's Contagious Interview Campaign Escalates: 338 Malicious npm Packages — Socket.dev","type":"research","url":"https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages"},{"credibility":2,"name":"DPRK Attackers Spawn Malicious Npm Package Factory — Dark Reading","type":"news_article","url":"https://www.darkreading.com/application-security/contagious-interview-malicious-npm-package-factory"},{"credibility":2,"name":"A Comprehensive Analysis of DPRK's Contagious Interview — OpenSourceMalware","type":"research","url":"https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026"},{"credibility":2,"name":"Famous Chollima / WaterPlum Cyber Actor Group — RH-ISAC","type":"research","url":"https://rhisac.org/general-blog/famous-chollima-waterplum-cyber-actor-group-continue-targeting-it-professionals/"}]}],"sources_used":[{"credibility":2,"name":"North Korean Fake Recruiters Infect 30K Devices, Steal $10.7M in Crypto — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto"},{"credibility":2,"name":"North Korea-Linked WaterPlum Used Fake Jobs to Steal Crypto, NPA Says — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/north-korea-linked-waterplum-used-fake-jobs-to-steal-crypto-npa-says/"},{"credibility":1,"name":"FBI: North Korean Fake Job Interviews Hit 30,000 Devices — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/09/19/north-korea-shock-fake-job-interviews-drain-107m-from-7000-wallets/"},{"credibility":2,"name":"North Korean Hackers Infect 30,000 PCs, Steal $10,700,000 in Crypto Through Fake IT Jobs — Daily Hodl","type":"news_article","url":"https://dailyhodl.com/2026/09/21/north-korean-hackers-infect-30000-pcs-steal-10700000-in-crypto-through-fake-it-jobs-fbi/"},{"credibility":2,"name":"North Korean WaterPlum — The Cyber Express","type":"news_article","url":"https://thecyberexpress.com/waterplum-contagious-interview-north-korea/"},{"credibility":2,"name":"North Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/north-korean-waterplum-hackers/"},{"credibility":1,"name":"WaterPlum / Contagious Interview Advisory — Australian Cyber Security Centre (cyber.gov.au)","type":"regulatory","url":"https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals"},{"credibility":2,"name":"Joint FBI and Japanese NPA Advisory Exposes North Korean WaterPlum Campaign — BrinzTech","type":"news_article","url":"https://www.brinztech.com/breach-alerts/brinztech-alert-joint-fbi-and-japanese-npa-advisory-exposes-north-korean-waterplum-campaign-infecting-30000-devices-and-7000-crypto-wallets"},{"credibility":2,"name":"North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide — Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/"},{"credibility":2,"name":"North Korea's Contagious Interview Campaign Escalates: 338 Malicious npm Packages — Socket.dev","type":"research","url":"https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages"},{"credibility":2,"name":"DPRK Attackers Spawn Malicious Npm Package Factory — Dark Reading","type":"news_article","url":"https://www.darkreading.com/application-security/contagious-interview-malicious-npm-package-factory"},{"credibility":2,"name":"Famous Chollima / WaterPlum Cyber Actor Group — RH-ISAC","type":"research","url":"https://rhisac.org/general-blog/famous-chollima-waterplum-cyber-actor-group-continue-targeting-it-professionals/"},{"credibility":2,"name":"North Korea WaterPlum Crypto Thefts Attribution — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/24f4f-north-korea-waterplum-crypto-thefts-attribution"},{"credibility":2,"name":"Illicit VS Code Projects Tapped to Deploy StoatWaffle Malware — SC World","type":"news_article","url":"https://www.scworld.com/brief/illicit-vs-code-projects-tapped-to-deploy-stoatwaffle-malware"},{"credibility":2,"name":"Contagious Interview: North Korean Hackers Target Crypto Devs with Fake Job NPM Malware — VPN Central","type":"news_article","url":"https://vpncentral.com/contagious-interview-north-korean-hackers-target-crypto-devs-with-fake-job-npm-malware/"},{"credibility":2,"name":"North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/north-korea-hackers-crypto-wallets-job-offers/"},{"credibility":2,"name":"A Comprehensive Analysis of DPRK's Contagious Interview — OpenSourceMalware","type":"research","url":"https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026"}],"summary":"WaterPlum, the name given by a seven-agency international joint advisory to the threat group the security industry had previously tracked as Contagious Interview, is a North Korean state-linked cyber-espionage and theft operation assessed to operate under the 313 General Bureau of North Korea's Munitions Industry Department. Between December 2025 and July 2026 the group infected more than 30,000 devices in over 100 countries by posing as recruiters for AI, cryptocurrency, and NFT companies, tricking developers into executing malicious code during fake technical interviews and transferring at least $10.71 million USD (approximately 1.7 billion JPY) in stolen cryptocurrency to North Korea. The campaign is attributed by the FBI, Japan's National Police Agency, Australia's ASD ACSC, and German intelligence agencies; it remains ongoing and actively targets software developers and crypto/Web3 job seekers.","timeline":[{"date":"2022-01-01","event":"Security researchers first document Contagious Interview campaign targeting developers via fake job offers and malicious npm packages; exact start date is approximate.","source":"Socket.dev / multiple threat-intelligence firms","source_url":"https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages"},{"date":"2025-01-01","event":"A North Korean IT-worker posing as a Malaysian national attempts to gain employment at Japanese cryptocurrency exchange bitFlyer; the applicant uses multiple VPNs, requests cryptocurrency payment, and ultimately declines the position. Date is approximate based on NPA disclosure.","source":"Japan NPA via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/18/north-korea-linked-waterplum-used-fake-jobs-to-steal-crypto-npa-says/"},{"date":"2025-12-01","event":"Start of the campaign window documented in the joint government advisory: WaterPlum begins systematically infecting devices at scale across 100+ countries.","source":"Joint advisory per CoinTelegraph","source_url":"https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto"},{"date":"2026-07-31","event":"End of the advisory's documented campaign window. By this date: 30,000+ devices infected, 7,000+ crypto wallets compromised, $10.71 million USD transferred to North Korea.","source":"Joint advisory per CoinTelegraph / CryptoTimes","source_url":"https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto"},{"date":"2026-09-18","event":"Seven agencies — Japan NPA, Japan NCO, FBI, DC3, ASD ACSC, Germany BND, Germany BfV — publish joint advisory formally attributing WaterPlum to North Korea's 313 General Bureau and disclosing scale and financial figures.","source":"Joint advisory per CryptoTimes / cyber.gov.au","source_url":"https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals"},{"date":"2026-09-18","event":"Japan's NPA separately discloses that authorities identified and dismantled a North Korean IT-worker laptop farm on Japanese soil for the first time.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/18/north-korea-linked-waterplum-used-fake-jobs-to-steal-crypto-npa-says/"},{"date":"2026-09-21","event":"Continued reporting on the advisory; FBI and international partners publicly confirm the campaign is ongoing and actively targeting developers as of this date.","source":"Daily Hodl / CoinTelegraph","source_url":"https://dailyhodl.com/2026/09/21/north-korean-hackers-infect-30000-pcs-steal-10700000-in-crypto-through-fake-it-jobs-fbi/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 7cc586e1-33aa-4d85-ad08-cc5888ad259e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.