Crash, dice, mines and plinko on crypto casinos often carry a provably fair badge. This guide shows what the badge proves, what it leaves out, and how to check a real bet yourself in about three minutes.
- Provably fair locks a game result before you bet. The casino shows a hash of its secret seed first and reveals the seed later.
- You add your own seed, so the casino cannot pick the result on its own.
- A passing check proves one round followed the published formula. It does not prove the payout table or the RTP.
- Most tricks found in the wild sit in the part a basic check does not cover.
Why provably fair exists
In an online game the result comes from the casino’s server. For most of the history of online gambling a player had two options. Trust the operator, or trust a lab certificate that the player could not check.
Early Bitcoin dice sites tried a different idea. The casino commits to its random value before the bet and proves it later. Anyone can then rebuild the result with the same math. That idea is called provably fair. Today most crypto casinos use it for their in-house games.
The four inputs
| Input | Who sets it | What it does |
|---|---|---|
| Server seed | Casino | A long secret random string. You do not see it while you play. |
| Hashed server seed | Casino | A SHA-256 fingerprint of the server seed. You see it before your first bet. It locks the casino to that seed. |
| Client seed | You | Your own string. You can change it at any time. It stops the casino from choosing results alone. |
| Nonce | Counter | Goes up by one with every bet, so each bet on the same seed pair gets a new result. |
A hash works one way. The same seed always gives the same hash. You cannot rebuild the seed from the hash, and you cannot find a second seed with the same hash. So the casino cannot swap its seed after you bet without the fingerprint changing.
One dice roll, worked by hand
Here is a full example with made up seeds. You can repeat every step on your own computer. Many casinos use this exact scheme for dice. Your casino may use a slightly different message format, so always read its fairness page first.
| Value | Example |
|---|---|
| Server seed (revealed later) | 9f1c2e7a4b8d06f35e21c9a7d4b0e8f16a3c5d7e9b2f4a6c8e0d1b3f5a7c9e2d |
| Hash shown before the bet | e32e8bee1acb29cfba2fece7a196e08e75266d25af7ea93fb9a863e1f08b8cc8 |
| Client seed | ccr-example-2026 |
| Nonce | 1 |
- Hash the server seed with SHA-256. You get
e32e8bee...8cc8. It matches the hash shown before the bet, so the seed was not swapped. - Run HMAC-SHA256 with the server seed as the key and
ccr-example-2026:1:0as the message. The last 0 is a round counter that some games use when one hash is not enough. - The output starts with the bytes
f5 0a 4c 20. In decimal that is 245, 10, 76 and 32. - Turn the four bytes into a number between 0 and 1: 245/256 + 10/256² + 76/256³ + 32/256⁴ = 0.95719.
- Dice has 10,001 outcomes from 0.00 to 100.00. Multiply by 10,001, divide by 100 and round down. The roll is 95.72.
Change the nonce to 2 and the same seeds give 25.66. Nonce 3 gives 51.08. Nothing else changes, yet each bet gets a fresh result that was fixed before you clicked.
import hmac, hashlib
server = "9f1c2e7a4b8d06f35e21c9a7d4b0e8f16a3c5d7e9b2f4a6c8e0d1b3f5a7c9e2d"
print(hashlib.sha256(server.encode()).hexdigest())
h = hmac.new(server.encode(), b"ccr-example-2026:1:0", hashlib.sha256).digest()
f = sum(b / 256 ** (i + 1) for i, b in enumerate(h[:4]))
print(int(f * 10001) / 100) # 95.72
Other games use the same random number in a different way. Roulette multiplies it by 37 pockets. A card game multiplies it by 52 cards. Plinko uses one number per row to pick left or right. The fairness page of each game should publish that step.
How to check a real bet
- Before you play, open the fairness panel. Copy the hashed server seed and save it somewhere outside the casino.
- Replace the default client seed with your own string. The browser makes one for you at sign up, but your own is better.
- Play. Open the bet details for the round you want to check and note the nonce.
- Rotate the seed pair. On many casinos this is the moment the old server seed is shown in plain text. Some reveal it right after each round.
- Hash the revealed seed. It must match the hash you saved in step 1.
- Put the revealed seed, your client seed and the nonce into a verifier. Compare the result with the bet history.

If the result does not match, check your inputs first. The usual causes are a wrong nonce, a changed client seed, or pasting the hashed seed where the plain seed belongs.
Duel
12 Originals at 100% RTP, 50% slot rakeback paid at once, sports on the same wallet. Duel Blackjack Live is offline.
- Rakeback50% slots
- Originals12 games
- Wallet16 coins
- 12 Originals
- 50% rakeback
- Sportsbook
What a passing check does not prove
A game has two layers. The first makes a random number from the seeds. The second turns that number into a win or a loss through a payout table, a probability table or game rules. A standard check covers the first layer. The second layer is often not published, and the casino’s own verifier usually shares code with the live game.
- It proves one round was fixed before your bet and follows the published formula.
- It does not prove the payout table matches the one the casino advertises.
- It does not prove the long run RTP. One matching bet says nothing about millions of bets.
- It does not cover withdrawals, limits, account reviews or the licence.
- It does not apply to third party slots or live dealer tables. Those use their own studio RNG.
Six patterns behind fake fairness
Independent researchers have published technical reviews of several crypto casinos in 2025 and 2026. Every game below carried a provably fair label. In most of them the casino’s own checker still passed.
| Pattern | What happened | Can you spot it? |
|---|---|---|
| Changed probability table | A plinko update cut the odds of the edge buckets. The RTP fell from about 99% to about 98% for close to three months. The checker kept passing. | Hard. Only a large sample or an audit shows it. |
| Checker with its own RTP | The on-site checker used a different formula and a lower RTP than the live game. It could not rebuild a single real bet. | Yes. Your real bet will not reproduce. |
| Client seed ignored | The seed field was there, but the value never reached the math. | Yes. Change the seed and nothing in the formula changes. |
| Nonce stuck at 0 | A new server seed for every bet and the nonce always 0. The house could make many seeds and keep a good one. | Yes. Watch the nonce in bet details. |
| No hash before the bet | A seed was shown after the round with nothing to compare it to. | Yes. Look for the hash before you bet. |
| Result inside the proof | The revealed “seed” already contained the finished result, such as the multiplier. The hash only proved the answer was stored. | Yes. There is no formula to run. |
Crash and other shared games
In crash every player sees the same round, so there is no personal client seed. A fair setup uses two locks instead. The casino makes a long chain of seeds up front, where each seed is the hash of the next one, and publishes the end of the chain before the game starts. The other input comes from an event that has not happened yet, such as the hash of a future Bitcoin block or a public randomness beacon.
You can check any round by hashing its seed forward until you reach the published end of the chain. If a seed was swapped, the chain breaks. If a crash game shows no published chain and no outside input, the casino picks the last input on its own.
A fair game can still take your bankroll
Take plinko with 16 rows. Each row is a 50/50 bounce, so the odds of every bucket are fixed math. On a common high risk board the five middle buckets pay 0.2x. The ball lands there about 79% of the time. The two corners together come up once in 32,768 drops. Over 1,000 drops there is a 97% chance you never see a corner at all.
Long losing runs are part of that design. A fair game and a rigged one can feel the same inside one session. That is why the checks above matter more than your results.
Provably fair, lab tests and independent audits
| Question | Lab certificate | Provably fair | Independent audit |
|---|---|---|---|
| Who is it for | The regulator | The player | Player and operator |
| Can you check one bet | No | Yes | Yes |
| Checks the payout logic | Often RNG only | No | Yes |
| Confirms the RTP | At test time | No | Yes, over millions of rounds |
| Keeps working after launch | No | Every round | When re-run |
An independent audit rebuilds the game from its published rules, replays thousands of real bets against that rebuild and simulates millions of rounds to measure the real RTP. Very few crypto casinos have one. If a casino has an audit, check that it names each game and that the results are public.
Questions players ask
Can a casino still cheat on a provably fair game?
It cannot change a round after you bet if the commit and reveal work. It can still set a worse payout table than it advertises, or ship a checker that does not match the live game. That is the part a single check does not cover.
Do I need to verify every bet?
No. Check a few bets after each seed rotation, and always check a big win or a streak that looks wrong. The point is that you can check any bet at any time.
Why does my result not match?
Most often the nonce is off by one, the client seed was changed between bets, or the hashed seed was pasted where the plain seed belongs. If every input is right and the result still differs, save the bet ID and contact support in writing.
Does provably fair mean there is no house edge?
No. The house edge is built into the payout table. A game can be fully provably fair and still return 99% or 97% over time. Read the RTP on each game review.
Why can I see the server seed only after I rotate it?
If you saw the plain seed early, you could compute your next results before betting. So the casino keeps it hidden while the seed is active. Some casinos reveal it after each round and start a new one. Others reveal it when you rotate.
Are slots provably fair?
Slots from outside studios use the studio’s own RNG and lab testing. Some casinos run in-house slots with seeds, but the reel logic sits in the second layer. Check whether the casino publishes how each spin is mapped.
A fair game still has a house edge. Over many rounds the casino keeps its share. Set a limit before you start and stop when you reach it.
Each original game file on this site notes the house edge and how the fairness panel works at that casino. Our method is on the How we review page.
Reader desk
Comments
Played at this casino, spotted a mistake or have a question? Write it here. Alex reads every comment before it goes live.