Skip to content

Provably fair explained: how to check a casino bet yourself

What the provably fair badge proves, what it leaves out, and how to check a real bet in three minutes. With a worked dice example and five checks before you play.

Alex Jovanovic Crypto casino analyst

Published
Updated
Provably Fair in neon letters with lock, dice and check mark icons above a casino chip and a die on a dark grid

Crash, dice, mines and plinko on crypto casinos often carry a provably fair badge. This guide shows what the badge proves, what it leaves out, and how to check a real bet yourself in about three minutes.

  • Provably fair locks a game result before you bet. The casino shows a hash of its secret seed first and reveals the seed later.
  • You add your own seed, so the casino cannot pick the result on its own.
  • A passing check proves one round followed the published formula. It does not prove the payout table or the RTP.
  • Most tricks found in the wild sit in the part a basic check does not cover.

Why provably fair exists

In an online game the result comes from the casino’s server. For most of the history of online gambling a player had two options. Trust the operator, or trust a lab certificate that the player could not check.

Early Bitcoin dice sites tried a different idea. The casino commits to its random value before the bet and proves it later. Anyone can then rebuild the result with the same math. That idea is called provably fair. Today most crypto casinos use it for their in-house games.

The four inputs

InputWho sets itWhat it does
Server seedCasinoA long secret random string. You do not see it while you play.
Hashed server seedCasinoA SHA-256 fingerprint of the server seed. You see it before your first bet. It locks the casino to that seed.
Client seedYouYour own string. You can change it at any time. It stops the casino from choosing results alone.
NonceCounterGoes up by one with every bet, so each bet on the same seed pair gets a new result.

A hash works one way. The same seed always gives the same hash. You cannot rebuild the seed from the hash, and you cannot find a second seed with the same hash. So the casino cannot swap its seed after you bet without the fingerprint changing.

How provably fair locks a resultFour steps. The casino shows the hash of its server seed. You set a client seed and bet. The game computes the result from server seed, client seed and nonce. After you rotate the seed, the casino reveals it and you check it against the hash.1Casino commitsIt makes a secret server seed andshows you only its SHA-256 hash.2You add your partSet your own client seed. Each betraises the nonce by one.3The game computesserver seed + client seed + noncego through HMAC-SHA256 to a result.4Reveal and checkThe casino reveals the seed. Its hashmust match the one from step 1.COMMIT . PLAY . REVEAL . VERIFY
The commit and reveal cycle behind every provably fair game.

One dice roll, worked by hand

Here is a full example with made up seeds. You can repeat every step on your own computer. Many casinos use this exact scheme for dice. Your casino may use a slightly different message format, so always read its fairness page first.

ValueExample
Server seed (revealed later)9f1c2e7a4b8d06f35e21c9a7d4b0e8f16a3c5d7e9b2f4a6c8e0d1b3f5a7c9e2d
Hash shown before the bete32e8bee1acb29cfba2fece7a196e08e75266d25af7ea93fb9a863e1f08b8cc8
Client seedccr-example-2026
Nonce1
  1. Hash the server seed with SHA-256. You get e32e8bee...8cc8. It matches the hash shown before the bet, so the seed was not swapped.
  2. Run HMAC-SHA256 with the server seed as the key and ccr-example-2026:1:0 as the message. The last 0 is a round counter that some games use when one hash is not enough.
  3. The output starts with the bytes f5 0a 4c 20. In decimal that is 245, 10, 76 and 32.
  4. Turn the four bytes into a number between 0 and 1: 245/256 + 10/256² + 76/256³ + 32/256⁴ = 0.95719.
  5. Dice has 10,001 outcomes from 0.00 to 100.00. Multiply by 10,001, divide by 100 and round down. The roll is 95.72.

Change the nonce to 2 and the same seeds give 25.66. Nonce 3 gives 51.08. Nothing else changes, yet each bet gets a fresh result that was fixed before you clicked.

import hmac, hashlib
server = "9f1c2e7a4b8d06f35e21c9a7d4b0e8f16a3c5d7e9b2f4a6c8e0d1b3f5a7c9e2d"
print(hashlib.sha256(server.encode()).hexdigest())
h = hmac.new(server.encode(), b"ccr-example-2026:1:0", hashlib.sha256).digest()
f = sum(b / 256 ** (i + 1) for i, b in enumerate(h[:4]))
print(int(f * 10001) / 100)   # 95.72

Other games use the same random number in a different way. Roulette multiplies it by 37 pockets. A card game multiplies it by 52 cards. Plinko uses one number per row to pick left or right. The fairness page of each game should publish that step.

How to check a real bet

  1. Before you play, open the fairness panel. Copy the hashed server seed and save it somewhere outside the casino.
  2. Replace the default client seed with your own string. The browser makes one for you at sign up, but your own is better.
  3. Play. Open the bet details for the round you want to check and note the nonce.
  4. Rotate the seed pair. On many casinos this is the moment the old server seed is shown in plain text. Some reveal it right after each round.
  5. Hash the revealed seed. It must match the hash you saved in step 1.
  6. Put the revealed seed, your client seed and the nonce into a verifier. Compare the result with the bet history.
The Duel provably fair Verify tab for Dice with a client seed, a revealed server seed and nonce 9802. The rebuilt roll is 72.94.
A real check on Duel Dice. The client seed, the revealed server seed and the nonce go in on the left. The verifier rebuilds the roll, 72.94, and shows the JavaScript it used.

If the result does not match, check your inputs first. The usual causes are a wrong nonce, a changed client seed, or pasting the hashed seed where the plain seed belongs.

Duel

12 Originals at 100% RTP, 50% slot rakeback paid at once, sports on the same wallet. Duel Blackjack Live is offline.

  • Rakeback50% slots
  • Originals12 games
  • Wallet16 coins
  • 12 Originals
  • 50% rakeback
  • Sportsbook
8.8 CCR / 10
Play at Duel Read review 18+ · Partner link

What a passing check does not prove

A game has two layers. The first makes a random number from the seeds. The second turns that number into a win or a loss through a payout table, a probability table or game rules. A standard check covers the first layer. The second layer is often not published, and the casino’s own verifier usually shares code with the live game.

What the check coversLayer one, seeds to random number, is covered by a provably fair check. Layer two, random number to payout through tables and rules, is not covered. RTP, withdrawals and licence are outside the check.LAYER 1 . CHECKEDSeeds to random numberSeed fixed before the betYour seed used in the mathSame inputs, same numberLAYER 2 . OFTEN HIDDENRandom number to payoutPayout and probability tablesGame rules and multipliersThe real RTP you getOUTSIDE THE CHECKWithdrawals . licence . third party slots
A provably fair check covers the first layer. Tricks tend to sit in the second.
  • It proves one round was fixed before your bet and follows the published formula.
  • It does not prove the payout table matches the one the casino advertises.
  • It does not prove the long run RTP. One matching bet says nothing about millions of bets.
  • It does not cover withdrawals, limits, account reviews or the licence.
  • It does not apply to third party slots or live dealer tables. Those use their own studio RNG.

Six patterns behind fake fairness

Independent researchers have published technical reviews of several crypto casinos in 2025 and 2026. Every game below carried a provably fair label. In most of them the casino’s own checker still passed.

PatternWhat happenedCan you spot it?
Changed probability tableA plinko update cut the odds of the edge buckets. The RTP fell from about 99% to about 98% for close to three months. The checker kept passing.Hard. Only a large sample or an audit shows it.
Checker with its own RTPThe on-site checker used a different formula and a lower RTP than the live game. It could not rebuild a single real bet.Yes. Your real bet will not reproduce.
Client seed ignoredThe seed field was there, but the value never reached the math.Yes. Change the seed and nothing in the formula changes.
Nonce stuck at 0A new server seed for every bet and the nonce always 0. The house could make many seeds and keep a good one.Yes. Watch the nonce in bet details.
No hash before the betA seed was shown after the round with nothing to compare it to.Yes. Look for the hash before you bet.
Result inside the proofThe revealed “seed” already contained the finished result, such as the multiplier. The hash only proved the answer was stored.Yes. There is no formula to run.
Five checks before you playHash of the server seed shown before the bet. Client seed you can change. Nonce that goes up every bet. A published formula. A revealed seed that matches the hash.FIVE CHECKS BEFORE YOU PLAYServer seed hash shown before the betClient seed you can changeNonce goes up with every betFormula published, seed to resultRevealed seed matches the hash
If any of the five is missing, the provably fair label has nothing behind it.

Crash and other shared games

In crash every player sees the same round, so there is no personal client seed. A fair setup uses two locks instead. The casino makes a long chain of seeds up front, where each seed is the hash of the next one, and publishes the end of the chain before the game starts. The other input comes from an event that has not happened yet, such as the hash of a future Bitcoin block or a public randomness beacon.

You can check any round by hashing its seed forward until you reach the published end of the chain. If a seed was swapped, the chain breaks. If a crash game shows no published chain and no outside input, the casino picks the last input on its own.

A fair game can still take your bankroll

Take plinko with 16 rows. Each row is a 50/50 bounce, so the odds of every bucket are fixed math. On a common high risk board the five middle buckets pay 0.2x. The ball lands there about 79% of the time. The two corners together come up once in 32,768 drops. Over 1,000 drops there is a 97% chance you never see a corner at all.

Long losing runs are part of that design. A fair game and a rigged one can feel the same inside one session. That is why the checks above matter more than your results.

Provably fair, lab tests and independent audits

QuestionLab certificateProvably fairIndependent audit
Who is it forThe regulatorThe playerPlayer and operator
Can you check one betNoYesYes
Checks the payout logicOften RNG onlyNoYes
Confirms the RTPAt test timeNoYes, over millions of rounds
Keeps working after launchNoEvery roundWhen re-run

An independent audit rebuilds the game from its published rules, replays thousands of real bets against that rebuild and simulates millions of rounds to measure the real RTP. Very few crypto casinos have one. If a casino has an audit, check that it names each game and that the results are public.

Questions players ask

Can a casino still cheat on a provably fair game?

It cannot change a round after you bet if the commit and reveal work. It can still set a worse payout table than it advertises, or ship a checker that does not match the live game. That is the part a single check does not cover.

Do I need to verify every bet?

No. Check a few bets after each seed rotation, and always check a big win or a streak that looks wrong. The point is that you can check any bet at any time.

Why does my result not match?

Most often the nonce is off by one, the client seed was changed between bets, or the hashed seed was pasted where the plain seed belongs. If every input is right and the result still differs, save the bet ID and contact support in writing.

Does provably fair mean there is no house edge?

No. The house edge is built into the payout table. A game can be fully provably fair and still return 99% or 97% over time. Read the RTP on each game review.

Why can I see the server seed only after I rotate it?

If you saw the plain seed early, you could compute your next results before betting. So the casino keeps it hidden while the seed is active. Some casinos reveal it after each round and start a new one. Others reveal it when you rotate.

Are slots provably fair?

Slots from outside studios use the studio’s own RNG and lab testing. Some casinos run in-house slots with seeds, but the reel logic sits in the second layer. Check whether the casino publishes how each spin is mapped.

A fair game still has a house edge. Over many rounds the casino keeps its share. Set a limit before you start and stop when you reach it.

Each original game file on this site notes the house edge and how the fairness panel works at that casino. Our method is on the How we review page.

Reader desk

Comments

Played at this casino, spotted a mistake or have a question? Write it here. Alex reads every comment before it goes live.

Be the first to comment

Your email is never shown. Comments are checked by hand before they appear. Links and promo codes are removed.

18+ only. By posting you agree to our terms and privacy policy.

All posts