Provably fair
Every random outcome on Lottra is fixed before you choose and published afterwards, so you can check it yourself rather than taking our word for it.
Last updated
The problem it solves
Any site that generates its own random numbers could, in principle, generate them after seeing what you picked. Nothing in the interface would look different. You would lose slightly more often than you should, and you would have no way to tell.
A promise not to do that is worth nothing, because a site that would do it would also promise not to. The fix is not a stronger promise; it is removing the opportunity.
Commit, then reveal
It works in three steps:
- Before play begins, the server generates a secret random seed and publishes its SHA-256 hash — a fingerprint. The fingerprint reveals nothing about the seed, but a given fingerprint can only have come from that exact seed.
- You choose — your numbers, your corner, your entry. The fingerprint is already published and cannot be changed.
- After the result, the server publishes the seed. Hash it yourself. If it matches the fingerprint from step one, the outcome was decided before you moved.
The result itself is derived from that seed by HMAC-SHA256, using rejection sampling so that every outcome is exactly as likely as it should be. (Taking a hash modulo the number of outcomes — the obvious approach — makes low numbers very slightly more likely. Over enough rounds that is a real edge, so we do not do it.)
Checking a result yourself
After a round or a draw, the app shows both the fingerprint published beforehand and the revealed seed. To confirm they match, hash the seed on your own machine — and note the game's name on the end, separated by a colon:
echo -n "PASTE_THE_SEED_HERE:slots" | shasum -a 256That suffix is not decoration and the check fails without it. Use slots, keno or ludo to match the game you played. It exists so that one game's revealed seed can never be replayed as a valid commitment in another — the seeds are separate values in separate games, and the hash has to say so.
A worked example you can run right now, from a real spin on 2026-09-24:
seed 0ded52cd3ce4c4fe3e5ce29854a1f2a9794c342763f9cd933442d47889eb0c0b
seal 0cc729c4df2d2bddaded1becd5e28afbcc3dbfffa55d4674f0ed8c03b283dfeaThe output must equal the fingerprint shown before you played. If it ever does not, that is a bug or worse, and we want to hear about it at info@lottra.app.
What this does not prove
Being straight about the limits, because a page that claims a cryptographic scheme solves everything is a page to distrust:
- It does not set the odds. Commit-reveal proves the result was not changed after you chose. It says nothing about how generous the paytable is. That is a separate, published setting.
- It proves nothing you do not check. The guarantee is only worth what verification is worth. If nobody ever hashes a seed, the scheme is decoration.
- It covers randomness, not the rest of the system. Account balances, payouts and eligibility are ordinary software with ordinary safeguards, and are governed by the Official Rules.
Raffle draws
The same scheme picks raffle winners. Each raffle's seed is committed when the draw opens and revealed when it closes, so the winning entry was determined by a value fixed before entries were counted.
If a draw fails to reach its minimum number of distinct players it is cancelled and every entrant is refunded in full — see how the draws work.