
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@fairseal/verify
Advanced tools
Independent verification for FairSeal anchor receipts and VEO-2 objects — structure, integrity, Ed25519 signatures, and on-chain Merkle anchors. ESM + CJS, Node >= 18.
Independent, fail-closed verification for FairSeal receipts (VEO objects).
Every check runs from public inputs. You do not need to trust FairSeal — or this package's authors — to re-verify a receipt: signatures verify against the keys embedded or supplied, and anchors verify against Base mainnet through any RPC you choose.
npm install @fairseal/verify
Requires Node >= 18. Both ESM (
import) and CJS (require) are supported on all Node versions from 18 onward.@noblev2 cryptography is bundled into the dist so CJS consumers do not need--experimental-require-module.
import { verifyVEO } from '@fairseal/verify';
const result = await verifyVEO(receipt); // receipt = a VEO-2 object
if (result.valid) {
// ALL applicable checks passed AND (if an anchor is present)
// the anchor was verified on-chain.
} else {
console.log(result.checks); // structure / integrity / signature / anchor
console.log(result.errors); // machine-readable failure reasons
}
| Field | Meaning |
|---|---|
valid | true only when all applicable checks pass and, if an anchor is present, it verified on-chain. Never true for an anchored object whose chain check was skipped or failed. |
structural | Structure + integrity + signature only. Can be true while valid is false (anchor pending/failed). |
anchored | true (verified on-chain) / false (check ran and failed) / "unknown" (chain unreachable) / "not_present" (no anchor on this object) / "not_checked" (structuralOnly mode) |
checks.* | Each check is pass, fail, or skipped with a detail string. |
"We could not verify" and "we verified it is wrong" are different states — this package never collapses them.
const result = await verifyVEO(receipt, { structuralOnly: true });
// result.anchored === 'not_checked'
// result.valid will be false when an anchor is present:
// structurally-valid-but-not-chain-verified is NOT called "valid".
FairSeal API receipts (VEO-1) are signed with personal_sign (EIP-191) over a
canonical serialization:
import { verifyEIP191Signature, canonicalizeVEO1 } from '@fairseal/verify';
const check = verifyEIP191Signature(veo1Object);
// recovers the secp256k1 signer address and compares to the declared signer
import { verifyMerklePath, verifyAnchor, DEFAULT_CONTRACT_ADDRESSES } from '@fairseal/verify';
// Pure sha256 fold — no network needed:
const ok = verifyMerklePath(leafHash, merklePath, expectedRoot);
// Confirm the batch root on Base mainnet via any RPC you trust:
const anchor = await verifyAnchor(anchorInfo, { rpcUrl: 'https://mainnet.base.org' });
verifyMerklePath alone proves inclusion against a root offline; it does
not prove the root is on-chain. Use verifyAnchor (or call
MerkleAnchor.getBatchRoot on any Base RPC yourself) for chain confirmation.
Proves:
Does not prove:
A fully receipted agent can still be wrong. Audit reasoning separately.
verifyVEO(veo, options) / verifyVEOSync(veo, options) — top-level VEO-2 verificationverifyStructure, verifyIntegrity, verifySignature, isSigned — individual VEO-2 checksverifyEIP191Signature, canonicalizeVEO1, eip191Hash, pubKeyToAddress — VEO-1computeMerkleRoot, verifyMerklePath, normalizeHex, toBytes32Hex — MerkleverifyAnchor, DEFAULT_CONTRACT_ADDRESSES, DEFAULT_RPC_URLS — on-chain anchorTOPIC_BATCH_ANCHORED, SELECTOR_GET_BATCH_ROOT, SELECTOR_BATCH_EXISTSMIT
FAQs
Independent verification for FairSeal anchor receipts and VEO-2 objects — structure, integrity, Ed25519 signatures, and on-chain Merkle anchors. ESM + CJS, Node >= 18.
The npm package @fairseal/verify receives a total of 14 weekly downloads. As such, @fairseal/verify popularity was classified as not popular.
We found that @fairseal/verify demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.