Server-authoritative · virtual credits
Jackpot draw: totals become tickets. The biggest haul holds the most tickets and is most likely to win, but one roll — taken at the nonce right after the last pull, inside the same commitment — picks the winner. Every side can win; none is safe.
Expected return 0 cr · house edge 0% · browse the cases
Committed seed hash
Committed odds hash
Expected return 0 cr · house edge 0% ·
The server generates the seed, publishes only sha256(seed), resolves the whole battle at start, streams one round at a time, and reveals the seed at settlement. This page holds no seed and computes no outcome — the reels are playback.
The seed hash proves the roll was not tampered with. The config hash proves the odds, rake and format were fixed before play — without it, a site can publish honest rolls against a weight table it quietly edited. Both are shown in the lobby before anyone pays.
The client seed is sha256(lobbyId | seat0seed | seat1seed | …), so no single participant controls it. Bot seat seeds are sha256(serverSeed:bot:N) — derived from the seed the house already committed to, so the house cannot pick favourable bot seeds after the fact.
House bots pay entry from the house float, so a bot-filled lobby makes the house your counterparty rather than a neutral rake-taker. A winning bot seat's share returns to the float. The house's net on each battle is shown after settlement — it is frequently negative, and only the rake is positive in expectation.
Filling your own side with bots does not change your expected value: payout per winning seat is always the pot minus rake divided by the winning seats, which for symmetric formats is 1.9× your entry regardless of team size. It does change who your winnings are split with.
In jackpot mode the winner is not the biggest total — the biggest total is only the favourite. Each side's total becomes its ticket count, and one extra roll at the nonce straight after the last pull selects the holder. Because that roll sits inside the same commitment, it is reproducible by verify.py like every other number here.
Spins are solo: pick up to six lines, each its own case, and they all resolve against one seed. The commitment is published first and your seed is sent afterwards, so a seed chosen after the hash was shown cannot have been anticipated. There is no rake on a spin — the edge is whatever the case odds already carry.
One server seed covers many bets, with the nonce carried across them. Its hash is published before it is used and the seed itself is withheld until you rotate — at which moment the next seed's hash is already published. That ordering is what makes the commitment mean something: the house is locked into a seed before it knows what will be staked against it. Nothing is verifiable until you rotate, and everything is verifiable afterwards.
State now survives a restart, but there is still no auth, no rate limiting, no reconnect recovery, and no age or identity checks. Balances are made-up credits.