Verify a round

Every outcome is fixed by three values before the round is played: a server seed we commit to by publishing its hash, a client seed you control, and a nonce that counts your rounds. This page recomputes the result in your browser. Nothing here is sent back to us.

Load a round

The three values

How it works

  1. Before your first round, we show sha256(server seed). We cannot change the seed after that without the hash changing.
  2. Each round reads bytes from HMAC-SHA256(server seed, "client seed:nonce:cursor").
  3. Plinko takes one byte per row; its low bit is the direction. The slot is the number of rights.
  4. Mines shuffles the 25 tiles with Fisher-Yates, taking four bytes per swap; the first tiles of the shuffle are the mines. Which tiles you clicked is your choice, so it is recorded with the round rather than derived.
  5. The path is a fair 50/50 walk. Risk changes only the multiplier table, never the ball.
  6. Rotate your seed pair and we reveal the old server seed — then every round you played under it can be recomputed here.