Server-authoritative · virtual credits

Case Battle lobby

Your balance — not signed in

Open a lobby

Your seed is sent to the server and mixed with every other seat's.

Potential drops

Chance of hitting, and what it pays. Weights are fixed by the committed odds hash.

Open lobbies

Open a second browser tab to join as another player.

Who decides what

The server generates the seed, publishes only sha256(seed), resolves the whole battle at start, streams one round at a time, and reveals the seed at settlement. This page holds no seed and computes no outcome — the reels are playback.

Two commitments, not one

The seed hash proves the roll was not tampered with. The config hash proves the odds, rake and format were fixed before play — without it, a site can publish honest rolls against a weight table it quietly edited. Both are shown in the lobby before anyone pays.

Seat seeds

The client seed is sha256(lobbyId | seat0seed | seat1seed | …), so no single participant controls it. Bot seat seeds are sha256(serverSeed:bot:N) — derived from the seed the house already committed to, so the house cannot pick favourable bot seeds after the fact.

Bots and the house position

House bots pay entry from the house float, so a bot-filled lobby makes the house your counterparty rather than a neutral rake-taker. A winning bot seat's share returns to the float. The house's net on each battle is shown after settlement — it is frequently negative, and only the rake is positive in expectation.

Filling your own side with bots does not change your expected value: payout per winning seat is always the pot minus rake divided by the winning seats, which for symmetric formats is 1.9× your entry regardless of team size. It does change who your winnings are split with.

Jackpot draws

In jackpot mode the winner is not the biggest total — the biggest total is only the favourite. Each side's total becomes its ticket count, and one extra roll at the nonce straight after the last pull selects the holder. Because that roll sits inside the same commitment, it is reproducible by verify.py like every other number here.

Spins

Spins are solo: pick up to six lines, each its own case, and they all resolve against one seed. The commitment is published first and your seed is sent afterwards, so a seed chosen after the hash was shown cannot have been anticipated. There is no rake on a spin — the edge is whatever the case odds already carry.

Seeds and rotation

One server seed covers many bets, with the nonce carried across them. Its hash is published before it is used and the seed itself is withheld until you rotate — at which moment the next seed's hash is already published. That ordering is what makes the commitment mean something: the house is locked into a seed before it knows what will be staked against it. Nothing is verifiable until you rotate, and everything is verifiable afterwards.

Still missing for anything real

State now survives a restart, but there is still no auth, no rate limiting, no reconnect recovery, and no age or identity checks. Balances are made-up credits.