TARGET

Verify a round.

Every witnessed round publishes a seed commitment to immutable storage before its chosen future public-randomness round exists. This page independently recalculates the draw and result in your browser.

Completed rounds

Round details

Select a completed round. No completed rounds will appear until the first game ends.

How the witnessed result is calculated

The commitment binds the hidden server seed, client seed, nonce, pinned drand chain and a future drand round. After that round exists, SHA-256 expansion plus rejection sampling produces an exactly uniform integer K in the reference space. The same integer/rational 97% contract then determines the result.

commit = SHA256(version | serverSeed | clientSeed | nonce | chainHash | drandRound)
candidate = SHA256-expand(commit, drandRandomness, counter)
reject candidate while candidate ≥ M; K = candidate + 1
raw crash = 97M / (50(2K - 1))

The verifier also downloads the exact immutable witness version and the selected drand transcript. Independent review status is shown with every proof; an unreviewed build is not presented as externally certified.