This draw checks out. Every stage was recomputed here.
Nothing on this page is read from a stored "result" column. The winner list was recomputed from the published inputs in front of you, and it agrees with what is stored.
9 stages evaluated · algorithm tgrgb-v1
· proof b3dc69ba73ae→1dc8370f9b16 · 24 entries · tgrgb-v1
Demo raffle — no money, no operator, just the maths
a group that does not exist · closed — · status Completed
| # | Prize | Ticket | Winner | Entry id | Claim |
|---|---|---|---|---|---|
| 1 | First prize | 11 | entrant 11 of 24 | 1010 | Claimed |
| 2 | Second prize | 5 | entrant 5 of 24 | 1004 | Claimed |
| 3 | Third prize | 7 | entrant 7 of 24 | 1006 | Claimed |
| 4 | Fourth prize | 6 | entrant 6 of 24 | 1005 | Claimed |
| Alt # | Would receive | Ticket | Entry id |
|---|---|---|---|
| 1 | First alternate | 17 | 1016 |
| 2 | Second alternate | 15 | 1014 |
Every stage, recomputed
Each one is a check a third party can repeat. A pass here means our own numbers agree with each other, not that you have to trust us.
-
Commitment preimage matches the published parameters
Result: pass. expected 'tgrgb-v1|DEMO|1760000000|0|24|1c1a0e5b6d7f8091a2b3c4d5e6f708192a3b4c5d6e7f8091a2b3c4d5e6f70819'
The seed, closing time, price and seat count shown here are the ones hashed into the commitment that was published before entries opened.
-
Commitment is SHA-256 of that preimage
Result: pass. got b3dc69ba73ae8505… vs published b3dc69ba73ae8505…
The hash on the raffle post reproduces from the revealed preimage.
-
Canonical entry list rebuilt from the rows we can read
Result: pass. 24 entries, 1432 bytes
This is the exact string hashed in the next stage. It is what we can read from the entry rows now — the published copy is at the snapshot URI when one was stored.
-
Entry list hashes to the published snapshot hash
Result: pass. got 29a063f400daf729… vs published 29a063f400daf729…
Adding, removing or editing an entry — including a single per-entry contribution — changes this digest, so the pool the draw used is fixed in public before the seed is revealed.
-
Draw seed reproduces from the revealed server seed
Result: pass. got 1dc8370f9b16f664… vs published 1dc8370f9b16f664…
The seed used to pick winners is the HMAC of the published inputs, keyed by the revealed server seed.
-
Winner list recomputes from the draw seed
Result: pass. recomputed ['1010', '1004', '1006']… (4 winners)
This is the stage that catches a stored winner row being edited after the draw: the list below is computed here, then compared with what is stored.
-
Entrant contributions produce the published client seed
Result: pass. recomputed 8f7bbd009dfd4b62… vs published 8f7bbd009dfd4b62…
Each entrant's contribution is assigned when they enter, so the pool could not be re-rolled by rewriting one row after the fact.
-
Published pick log replays against the entry pool
Result: pass. 4 published picks replay to 4 winners
Each pick states the raw 32-bit word and the pool size, so index = word % pool_size is checkable, and the entry claimed must really sit at that index of the shrinking pool.
-
Entry count matches the published snapshot
Result: pass. published 24, read 24
A silently shortened or padded pool shows up here as well as in the hash.
The published inputs
Everything needed to repeat the computation is below, including the full canonical entry list. Entry identifiers are opaque; names are never part of the hash.
- Algorithm
- tgrgb-v1
- Code
- DEMO
- Closes at (unix)
- 1760000000
- Price (minor units)
- 0
- Seat count
- 24
- Commitment
- b3dc69ba73ae85051491610e6946a9965a1d837b78b60491f5c17b6d8082fb7e
- Preimage
- tgrgb-v1|DEMO|1760000000|0|24|1c1a0e5b6d7f8091a2b3c4d5e6f708192a3b4c5d6e7f8091a2b3c4d5e6f70819
- Snapshot hash
- 29a063f400daf729e2e638b4457e414c3620d3ee0f5bb183d35ad0f7cfd5a2a9
- Client seed
- 8f7bbd009dfd4b6242ab88e96098ebc29ecd93a51655eb6cf9dbac4296abfec6
- Draw seed
- 1dc8370f9b16f66416d9d35cea3c283f4e95fb34b79f920b34a5d5ef0f99fd18
- Server seed (revealed)
- 1c1a0e5b6d7f8091a2b3c4d5e6f708192a3b4c5d6e7f8091a2b3c4d5e6f70819
- Entries
- 24 eligible · published count
Canonical entry list (24 rows) — the exact string that hashes to the snapshot
[{"e":"1000","n":1,"s":"000000005eed0000","u":700000,"w":1},{"e":"1001","n":2,"s":"000000005eed1eef","u":700001,"w":1},{"e":"1002","n":3,"s":"000000005eed3dde","u":700002,"w":1},{"e":"1003","n":4,"s":"000000005eed5ccd","u":700003,"w":1},{"e":"1004","n":5,"s":"000000005eed7bbc","u":700004,"w":3},{"e":"1005","n":6,"s":"000000005eed9aab","u":700005,"w":1},{"e":"1006","n":7,"s":"000000005eedb99a","u":700006,"w":1},{"e":"1007","n":8,"s":"000000005eedd889","u":700007,"w":1},{"e":"1008","n":9,"s":"000000005eedf778","u":700008,"w":1},{"e":"1009","n":10,"s":"000000005eee1667","u":700009,"w":1},{"e":"1010","n":11,"s":"000000005eee3556","u":700010,"w":1},{"e":"1011","n":12,"s":"000000005eee5445","u":700011,"w":1},{"e":"1012","n":13,"s":"000000005eee7334","u":700012,"w":1},{"e":"1013","n":14,"s":"000000005eee9223","u":700013,"w":1},{"e":"1014","n":15,"s":"000000005eeeb112","u":700014,"w":1},{"e":"1015","n":16,"s":"000000005eeed001","u":700015,"w":1},{"e":"1016","n":17,"s":"000000005eeeeef0","u":700016,"w":1},{"e":"1017","n":18,"s":"000000005eef0ddf","u":700017,"w":1},{"e":"1018","n":19,"s":"000000005eef2cce","u":700018,"w":1},{"e":"1019","n":20,"s":"000000005eef4bbd","u":700019,"w":1},{"e":"1020","n":21,"s":"000000005eef6aac","u":700020,"w":1},{"e":"1021","n":22,"s":"000000005eef899b","u":700021,"w":1},{"e":"1022","n":23,"s":"000000005eefa88a","u":700022,"w":1},{"e":"1023","n":24,"s":"000000005eefc779","u":700023,"w":1}]
Pick log (4 picks) — word, pool size, index, entry
| Nonce | Pool | Accepted word | Index | Entry | Ticket | Tier |
|---|---|---|---|---|---|---|
| 0 | 26 | 749877192 | 12 | 1010 | 11 | 0 |
| 1 | 25 | 189564355 | 5 | 1004 | 5 | 1 |
| 2 | 24 | 2100203287 | 7 | 1006 | 7 | 2 |
| 3 | 23 | 1673657037 | 6 | 1005 | 6 | 2 |
Do it yourself, without our software
These commands use only printf and openssl. If the output matches the
published values above, the draw is what it claims to be. If it does not, we are wrong and you should
say so publicly.
Reproduce this draw with nothing but openssl (no account, no software from us):
1) Commitment was published before entries opened:
printf '%s' 'tgrgb-v1|DEMO|1760000000|0|24|1c1a0e5b6d7f8091a2b3c4d5e6f708192a3b4c5d6e7f8091a2b3c4d5e6f70819' | openssl dgst -sha256
-> must equal the published commitment
2) Entry list hash:
printf '%s' '[{"e":"1000","n":1,"s":"000000005eed0000","u":700000,"w":1},{"e":"1001","n":2,"s":"000000005eed1eef","u":700001,"w":1},{"e":"1002","n":3,"s":"000000005eed3dde","u":700002,"w":1},{"e":"1003","n":4,"s":"000000005eed5ccd","u":700003,"w":1},{"e":"1004","n":5,"s":"000000005eed7bbc","u":700004,"w":3},{"e":"1005","n":6,"s":"000000005eed9aab","u":700005,"w":1},{"e":"1006","n":7,"s":"000000005eedb99a","u":700006,"w":1},{"e":"1007","n":8,"s":"000000005eedd889","u":700007,"w":1},{"e":"1008","n":9,"s":"000000005eedf778","u":700008,"w":1},{"e":"1009","n":10,"s":"000000005eee1667","u":700009,"w":1},{"e":"1010","n":11,"s":"000000005eee3556","u":700010,"w":1},{"e":"1011","n":12,"s":"000000005eee5445","u":700011,"w":1},{"e":"1012","n":13,"s":"000000005eee7334","u":700012,"w":1},{"e":"1013","n":14,"s":"000000005eee9223","u":700013,"w":1},{"e":"1014","n":15,"s":"000000005eeeb112","u":700014,"w":1},{"e":"1015","n":16,"s":"000000005eeed001","u":700015,"w":1},{"e":"1016","n":17,"s":"000000005eeeeef0","u":700016,"w":1},{"e":"1017","n":18,"s":"000000005eef0ddf","u":700017,"w":1},{"e":"1018","n":19,"s":"000000005eef2cce","u":700018,"w":1},{"e":"1019","n":20,"s":"000000005eef4bbd","u":700019,"w":1},{"e":"1020","n":21,"s":"000000005eef6aac","u":700020,"w":1},{"e":"1021","n":22,"s":"000000005eef899b","u":700021,"w":1},{"e":"1022","n":23,"s":"000000005eefa88a","u":700022,"w":1},{"e":"1023","n":24,"s":"000000005eefc779","u":700023,"w":1}]' | openssl dgst -sha256
-> must equal the published snapshot hash
3) Draw seed is an HMAC-SHA256 keyed by the revealed server seed:
printf '%s' 'tgrgb-v1|DEMO|<snapshot_hash>|<client_seed>|1760000000' \
| openssl dgst -sha256 -mac HMAC -macopt hexkey:1c1a0e5b6d7f8091a2b3c4d5e6f708192a3b4c5d6e7f8091a2b3c4d5e6f70819
-> must equal the published draw seed
(client_seed = sha256 of concatenated per-entry contributions, see snapshot 's' fields)
4) Winner indices: for nonce 0,1,2… take
printf '%s' '<nonce>:0' | openssl dgst -sha256 -mac HMAC -macopt hexkey:<draw_seed>
read the digest as four-byte big-endian words, discard any word >= floor(2**32/n)*n,
the first surviving word modulo n is the 0-based index into the sorted entry list.
Remove that slot and repeat with the next nonce.
What this does not prove
- The commitment binds the seed and the deadline printed on the post. The moment the pool is frozen is a separate published hash, not part of the commitment.
- A commitment cannot stop a host from closing early or cancelling before the reveal. What constrains that is automatic closing at the published time, the visible snapshot hash, an early close that demands a recorded reason, and a re-draw that is always a new record.
- Entrant contributions are assigned by the bot at entry time, not typed by the entrant.
- Re-running a draw creates a second draw row. The old winner list is never edited, so “why was my number taken” has an answer with a timestamp.
- Payment review on Venmo, Cash App, PayPal and Zelle is a human decision, because those rails expose no API to check a payment against. We do not call that automated.
The whole scheme ·
Machine-readable version
(?format=json)